@Weiyee In
Your observation about the complexities and challenges in AI Trust, Risk, and Security Management is indeed insightful, particularly in light of the varying international regulations and standards.
Introducing the concept of DORA (Digital Operational Resilience Act) into this conversation could provide a valuable perspective.
DORA, primarily focused within the EU, aims to ensure that all participants in the financial system have the necessary safeguards and resilience against cyber threats. It's especially relevant in this context because it illustrates a proactive and comprehensive approach to digital operational resilience, something that is crucial in managing AI-related risks.
The principles of DORA could serve as a template or inspiration for global financial institutions grappling with multi-jurisdictional security, data privacy, and governance requirements. Its emphasis on rigorous risk management, incident reporting, digital operational resilience testing, and third-party risk management aligns well with the goals of AI TRiSM. DORA's framework could potentially offer a more harmonized approach to AI governance and security, aiding in the reduction of the fragmentation of standards and regulations you've highlighted.
Moreover, DORA's approach could be instrumental in establishing a common taxonomy and risk classification system, addressing one of the critical issues you mentioned regarding the lack of such frameworks in current AI TRiSM implementations. This standardization would not only facilitate compliance but also enhance the overall security posture of institutions operating in the AI space.
This could be particularly beneficial in the financial sector, where cross-border operations are the norm, and the need for a consistent approach to AI governance and cybersecurity is increasingly paramount.
------------------------------
Jose Arias
Mainframe Security Specialist
Mainframe Blog in Spanish:
https://mainframeseguro.blogspot.com/------------------------------