Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document our roadmap #49

Open
ColinEberhardt opened this issue Sep 18, 2024 · 2 comments
Open

Document our roadmap #49

ColinEberhardt opened this issue Sep 18, 2024 · 2 comments

Comments

@ColinEberhardt
Copy link
Collaborator

During the in-person workshop (12 Sep 2024), one of the workstreams considering the overall value proposition of the governance framework, and the roadmap going forwards. This should be added to this repository as a markdown file.

@lucaborella89
Copy link
Contributor

A new working group (WG) on Ethical and Responsible AI (metrics and guidelines) @chamindra @vicenteherrera

@lucaborella89
Copy link
Contributor

Notes from 12th Sept Workshop (roadmap sub-group):

Value Proposition: The GF provides a starting point for banks who wish to understand and generate a Gen AI Risk Framework for developing their AI solutions.

  • From a financial services consortium, drawing best practices from across the industry

  • Builds on top of other risk frameworks (NIST, etc) with a focus on what’s different for GenAI

  • Including key threats and recommended controls, potentially including classification around controls which provide higher assurance

  • Maintained and current to new risks

  • Leveraged by an ecosystem: TraderX, CCC, CSP Examples, Banks…

Who should use it?

  • Financial Services CISOs: Risk management teams, Policy control office

  • Vendor solution teams (3rd party vendors)

  • Vendor purchasing teams

  • Model risk management – May not be in direct scope, roadmap potential

  • CTO/CIO Office: Architecture and development teams, Data/Model acquisition and management teams

  • Banking Legal teams

  • Regulators

  • CSPs and model providers

  • Other Open source providers (CCC, +++)

Roadmap

V0 – By OSFF

  1. Preview release of SGF

  2. V1 - Codified governance and feedback

  3. NIST and OWASP control mapping for current controls

V1 – Post OSFF / Spring 2025

  1. Integration with CCC & sample solution with Validators: Service list for reference workloads, Pilot Program: Common Cloud Controls for AI - Google Docs
    2.First adopters (Case studies)

  2. RAI controls (New)

  3. Feedback iteration on controls (Feedback in Github)

V2 - Beyond

  1. Assurance Levels

  2. Next workloads

  3. Open RegTech – Regulation as code

Open issue: Controls in AI SIG vs CCC – unifying strategy need here. Karl to solve for all of us 😊

Responsible AI

Strategy

  • We should create a working group dedicated to this

  • Creating Frameworks for evaluating responsible and conscientious use cases https://miro.com/app/board/uXjVKrmdIOo=/, § Password: reach out to [email protected], BXT from Microsoft, AI Alliance, Others….

  • Evaluating AI Ethics acts for applicability

  • Then… Potentially Identify RAI threats/risks as a component of the risk framework.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: In Progress
Development

No branches or pull requests

2 participants