Exploring Risk and Compliance
Risk and Compliance in AI Control Tower provides visibility into risk, compliance, and governance status across your AI portfolio.
Risk and Compliance overview
Risk and Compliance in AI Control Tower provides governance visibility for AI systems at both the portfolio level and the individual AI system level. These views provide governance visibility into risk, compliance, and governance status without requiring users to work directly in the underlying governance workflows.
The Risk and Compliance views show summarized governance signals across AI assets. These signals include action items, regulatory risk classification, compliance posture, compliance score, aggregated risk posture, and risk heat maps. The generated summaries help stakeholders identify trends, prioritize attention, and focus on higher-risk areas of the AI portfolio.
At the AI system level, Risk and Compliance views provide more specific context for a single asset. Users can review regulatory classification status, compliance score, and compliance posture for priority frameworks. Users can also review aggregated risk rating, risk heat maps, and related governance records such as assessments, risks, controls, issues, and policy exceptions.
AI Control Tower surfaces these governance outcomes for visibility and oversight. Risk assessments, control execution, remediation, and other governance activities are managed through related governance solutions and supporting workflows.
Risk and Compliance users
| User | Description |
|---|---|
| AI governance stakeholder | Uses portfolio-level summaries to understand overall governance posture, identify priority action items, and monitor how AI assets are classified and governed across the organization. |
| AI steward or asset stakeholder | Uses the asset-level Risk and Compliance view to understand the governance posture of an individual AI system, including its assessment status, compliance score, aggregated risk rating, and related governance records. |
| Governance reviewer | Uses framework-specific and risk-specific views to understand which areas require follow-up, such as unresolved issues, incomplete assessments, ineffective controls, or missing governance data. |
Risk and Compliance benefits
| Feature | Benefit | Users |
|---|---|---|
| Top action items | Identify high-priority governance work that requires immediate attention. | AI governance stakeholder, governance reviewer |
| Regulatory risk classification | Understand how AI assets are grouped by regulatory acceptability and identify assets that require closer review. | AI governance stakeholder, governance reviewer |
| Compliance score and compliance posture for priority frameworks | Understand compliance posture for configured frameworks and see where issues affect governance coverage. | AI governance stakeholder, AI steward or asset stakeholder |
| Aggregated risk rating and risk heat map | Understand how inherent risk and control effectiveness influence residual risk for an AI system. | AI steward or asset stakeholder, governance reviewer |
| Assessments, risks, controls, issues, and policy exceptions | Review governance records associated with a specific AI system without leaving the AI system context. | AI steward or asset stakeholder |
What to explore next
For information about configuring and using Risk and Compliance in AI Control Tower, see: