AIF-C01 notes
Security, compliance, and governance

Approaches for Implementing Governance Strategies

Governance strategies

Approaches to governance strategies

When working with generative AI solutions, it's important to establish and follow governance strategies to ensure responsible development and deployment. The following are some key approaches to consider.

Policies

Develop clear and comprehensive policies that outline the organization's approach to generative AI, including principles, guidelines, and responsible AI considerations. Here are some common characteristics of policies:

  • Policies should address areas such as data management, model training, output validation, safety, and human oversight.
  • Policies should also cover aspects like intellectual property, bias mitigation, and privacy protection.
  • Ensure these policies are regularly reviewed and updated to keep pace with evolving technology and regulatory requirements.

Review cadence

Implement a regular review process to assess the performance, safety, and responsible AI implications of the generative AI solutions. Here are some common tasks to include in the review process:

  • The review process could involve a combination of technical, legal, and responsible AI reviews at different stages of the development and deployment lifecycle.
  • Establish a clear timeline for these reviews, such as monthly, quarterly, or bi-annually, depending on the complexity and risk profile of the solutions.
  • Ensure that the review process includes diverse perspectives from stakeholders, including subject matter experts, legal and compliance teams, and end-users.

Review strategies

Develop comprehensive review strategies that cover both technical and non-technical aspects of the generative AI solutions. Here is some suggested guidance for a review strategy:

  • Technical reviews should focus on model performance, data quality, and the robustness of the underlying algorithms.
  • Non-technical reviews should assess the solutions' alignment with organizational policies, responsible AI principles, and regulatory requirements.
  • Incorporate testing and validation procedures to validate the outputs of the generative AI solutions before deployment.
  • Establish clear decision-making frameworks to determine when and how to intervene or modify the solutions based on the review findings.

Transparency standards

Commit to maintaining high standards of transparency in the development and deployment of generative AI solutions by ensuring the following:

  • Include publishing information about the AI models, their training data, and the key decisions made during the development process.
  • Provide clear and accessible documentation on the capabilities, limitations, and intended use cases of the generative AI solutions.
  • Establish channels for stakeholders, including end-users, to provide feedback and raise concerns about the solutions.

Team training requirements

Ensure that all team members involved in the development and deployment of generative AI solutions are adequately trained on relevant policies, guidelines, and best practices. Some suggestions for team training include the following:

  • Provide comprehensive training on bias mitigation, and responsible AI practices.
  • Encourage cross-functional collaboration and knowledge-sharing to foster a culture of responsible AI development.
  • Consider implementing ongoing training and certification programs to keep team members up to date with the latest advancements and regulatory changes.

Monitoring an AI system

Monitoring

Monitoring an AI system is necessary to ensure its performance, reliability, and compliance with the intended use case. Effective monitoring can help identify issues, optimize system performance, and maintain overall system health.

The following are some key aspects to consider when monitoring an AI system.

Performance metrics

Monitor the performance of the AI system by tracking metrics, such as the following:

  • Model accuracy: The proportion of correct predictions made by the model
  • Precision: The ratio of true positive predictions to the total number of positive predictions made by the model
  • Recall: The ratio of true positive predictions to the total number of actual positive instances in the data
  • F1-score: The harmonic mean of precision and recall, which provides a balanced measure of model performance
  • Latency: The time taken by the model to make a prediction, which is an important measure of a model's practical performance

These metrics can help you assess the effectiveness of the AI model and identify areas for improvement.

Infrastructure monitoring

Monitor the underlying infrastructure that supports the AI system, including the following:

  • Compute resources (for example, CPU, memory, GPU)
  • Network performance
  • Storage
  • System logs

This can help you identify resource bottlenecks, capacity planning issues, and potential system failures.

Monitoring for bias and fairness

Regularly assess the AI system for potential biases and unfair outcomes, especially in sensitive domains such as healthcare, finance, and HR. This can help ensure the AI system is making fair and unbiased decisions.

Monitoring for compliance and responsible AI

Ensure the AI system's operations and outputs adhere to relevant regulations, industry standards, and responsible guidelines. Monitor for any potential violations or issues that could raise compliance or responsible AI concerns.

Generative AI Security Scoping Matrix

You can use the Generative AI Security Scoping Matrix to assist you with application security scoping efforts. This matrix summarizes the key security disciplines that you should consider based on your generative AI solution. Use the matrix to guide you in classifying your applications among the five defined generative AI scopes.

Each scope of the security matrix is described in the interactive numbered markers.

2: Scope 2: Enterprise app

2: Scope 2: Enterprise app

Your business uses a third-party enterprise application that has generative AI features embedded within, and a business relationship is established between your organization and the vendor.

Example: You use a third-party enterprise scheduling application that has a generative AI capability embedded within to help draft meeting agendas.

Security disciplines

The matrix provides guidance on how to apply the following security disciplines to each scope.

  • Governance and Compliance
  • Legal and Privacy
  • Risk Management
  • Controls and Resilience

Controls: The implementation of security controls that are used to mitigate risk

The following are some examples:

  • Control who can use specific foundation models.
  • Control access to inference endpoints.

Resilience: How to architect generative AI solutions to maintain availability and meet business Service Level Agreements (SLAs)

The following is an example:

  • Ensure each AWS service is available in your chosen AWS Region.

Additional resources

Securing Generative AI: An Introduction to the Generative AI Security Scoping Matrix

To learn more about the Generative AI Security Scoping Matrix and how to use it, choose the following link.

AWS Security Blog

Securing Generative AI: Applying Relevant Security Controls

This post discusses the considerations when implementing security controls to protect a generative AI application. To learn more, choose the following link.

AWS Security Blog

Next, you will answer some questions to check how much you have learned in this section.

On this page