바로가기 메뉴 본문 바로가기 주메뉴 바로가기
  • 01-1Have you analyzed risk factors that may arise throughout the life cycle of the AI system?
    Determine applicability: Consider this question if the AI system is used internally within the institution for the public interest or as part of a public service, and determine if the requirement has been satisfied.

    • Risk management includes identifying, analyzing, evaluating, and treating risks. You must continuously and repetitively perform these four activities at each stage of the life cycle to remove and prevent risks and, ultimately, ensure trustworthiness. “ISO 31000:2018 — Risk management — Guidelines” introduces the idea, definition, and overall flow of risk management.

    • But the methodology of identification, analysis, and evaluation of risk factors that could interrupt the process of ensuring trustworthiness in AI may differ from existing software and hardware systems. ISO/IEC 24028:2020 and ISO/IEC 23894:2023 provide the classification of risk factors that must be examined from the perspective of trustworthy AI.

    • If you are implementing an AI system to be operated by a public institution, develop measures to remove risk factors using the institution’s risk management methodology and examine if ripple effects have been reduced. In the risk identification stage, you must particularly analyze the possibility of negative impact that could harm the public interest and fairness due to the implementation of the AI service in accordance with the objective and duties of each institution.