MAP — Context & Risk Identification
Description
The MAP function establishes the context for AI risk management by identifying the intended purpose, deployment context, capabilities, limitations, and potential impacts of each AI system. MAP produces the risk context that MEASURE and MANAGE operate on. Skipping MAP means measuring and managing risks you haven't properly identified — a recipe for blind spots.
Subcategories
| ID | Name | Description |
|---|---|---|
| MP-1 | Context establishment | Legal, regulatory, and societal contexts of AI system deployment are identified and documented, including norms and expe... |
| MP-2 | Categorization and risk tiering | AI systems are categorized based on their intended use, beneficiaries, and potential for harm, enabling risk-proportiona... |
| MP-3 | AI capabilities and limitations | AI system capabilities, intended purposes, context of use, and known limitations are documented. Every AI system has bou... |
| MP-4 | Risk identification and analysis | AI risks and benefits are identified, assessed, prioritized, and documented covering technical, societal, and ethical di... |
| MP-5 | Impact assessment | AI system impacts on individuals, groups, communities, organizations, and society are identified and assessed. Impact as... |
Implementation Guidance
Context and Purpose Documentation
Before building or deploying any AI system, document its purpose, intended users, expected benefits, and operational environment. This isn't paperwork — it's the foundation for risk identification. An AI system designed for internal use by trained analysts has fundamentally different risks than the same model exposed to public users.
Risk Identification Framework
MAP requires systematic identification of risks across multiple dimensions:
- Technical risks: Model accuracy degradation, adversarial vulnerability, data drift, infrastructure failures
- Societal risks: Bias and discrimination, privacy violations, job displacement, environmental impact
- Legal risks: Regulatory non-compliance, liability exposure, intellectual property infringement
- Ethical risks: Lack of transparency, erosion of human agency, concentrated power
System Classification and Risk Tiering
Categorize every AI system by risk level to determine proportionate controls:
- Minimal risk: Internal productivity tools, autocomplete, spell-check — standard security controls sufficient
- Limited risk: Customer-facing chatbots, content recommendation — transparency obligations, bias testing required
- High risk: Hiring, lending, medical diagnosis, criminal justice — full TEVV, human oversight, fairness audits, impact assessments mandatory
- Unacceptable risk: Social scoring, mass surveillance, manipulation — prohibited by policy
Model Cards and System Cards
Create standardized documentation for every AI system covering: intended use, training data description, performance metrics across demographic groups, known limitations, failure modes, and human oversight mechanisms. Model cards are living documents updated throughout the system lifecycle.
Evidence Requirements
- AI system inventory with risk tier classification for every system in scope
- Model cards or system cards for each AI system documenting purpose, capabilities, limitations, and performance metrics
- Risk identification worksheets covering technical, societal, legal, and ethical dimensions
- Impact assessments for high-risk AI systems with stakeholder input documentation
- AI system classification framework document defining risk tiers and corresponding control requirements
- Context analysis documentation identifying regulatory requirements, industry standards, and organizational constraints for each system
- Known limitations register documenting failure modes, edge cases, and out-of-scope uses for each system