Aller au contenu
login
arrow_backRetour aux issues
finos/ai-governance-framework #187

Add References to the COBIT Framework in the Risk Catalog

ecoDébutant help wanted 💡 Idea good-first-issue

descriptionDescription

### Contact Details markjpaulsen@gmail.com ### What is the idea The Risk Catalog currently references OWASP, NIST, EA AI Act, and others - and it might be a good idea to include references to the [COBIT Framework ](https://www.isaca.org/resources/cobit)as well. Many Banks (especially Canadian Banks) leverage COBIT for their control environments, risk management, and internal audit scope. KPMG has done a similar exercise in their [AI Risk and Controls Matrix](https://assets.kpmg.com/content/dam/kpmgsites/uk/pdf/2018/09/ai-risk-and-controls-matrix.pdf), and I have done a similar exercise with the [Vector Institute for AI](https://vectorinstitute.ai). The Vector tool we created as part of the exercise is [here](https://res-ai.ca/#home-panel) and a risk and controls matrix can be downloaded [here](https://res-ai.ca/assets/MIT%20Risk%20Controls%20Matrix.xlsx) - which includes references to the MIT A Risk Repository as well as COBIT. ### Why is it a good idea The Banking industry would benefit from this because COBIT is used by many banks for their existing control frameworks and environments. Having a mapping between risk catalog items and their control frameworks would help highlight gaps, potential risks, and mitigation steps. As well as ensure Internal Audits are planned and executed wit the right scope and context. ### How does it work? The [3 Lines of Defence](https://www.isaca.org/resources/isaca-journal/issues/2018/volume-4/roles-of-three-lines-of-defense-for-information-security-and-governance) - including Risk Management groups, Control testers/managers/ and Internal Audit would probably be the main users. ### primer artificial intelligence ### Any other key information ```shell ``` ### Code of Conduct - [x] I agree to follow the FINOS Code of Conduct
codeOuvre sur GitHub