Companies are rapidly accelerating their efforts to build or leverage AI systems and related technologies. Simultaneously, we are also seeing a wave of regulations and standards that specifies rules and requirements for developers and deployers of AI systems to comply with to enhance trust with stakeholders and promote the responsible use of AI. The session presents three case studies of how consumers were misled due to incorrect results by AI algorithms resulting in losses that further necessitates the need for strong controls and periodic oversight.
This session provides participants with information about the key risks considerations for an AI system and the associated controls that must be implemented to address these risks. A two-layer risk and impact assessment process for AI systems is explained. In line with the OECD AI system lifecycle, the key technical risks and control considerations at each phase are described – data-related risks; model development life cycle risks and model operations and monitoring risks. The session provides prescriptive controls that meet the requirements of the EU AI Act/ISO 42001 and helps not only build a robust AI governance program but also establish 'AI governance as a culture.'
The talk is geared towards both audit/compliance professionals (who will be exposed to important concepts to be aware of when auditing an AI system) and security/governance professionals (who are tasked with building a governance program around AI and will need to be aware of the critical risks and must-have controls).
SPEAKER
Varun is a Managing Director with BDO’s Third Party Attestation practice. In his current role, he works with tech companies to evaluate their cybersecurity posture and assess compliance with SOC 2 and various ISO standards to help them meet customer requirements and build trust with stakeholders. He focuses on complex and emerging requirements for security, privacy, cloud and AI assurance. Varun is an IT audit and risk management professional with 15+ years of progressive experience that he gained through various roles for Big4 firms and world leading corporations across various geographies. He has managed and executed a variety of IT audit-based projects from end-to-end. He has provided various types of IT audit and assurance services, such as, SOC 1/SOC 2 examinations, ISO 27001/42001/22301 audits, cybersecurity assessments, SOX testing, and privacy reviews. Varun is the Vice President of the ISACA SF chapter and has authored several articles around cloud security, AI audits and compliance.