Risk Management in the AI Era: Navigating the Opportunities and Challenges of AI Tools in the Public Sector

Artificial Intelligence (AI) has moved into the mainstream of businesses and government.

Business leaders are rushing to take advantages of the benefits that can be brought to a wide array of industries to help increase productivity. Government leaders are also moving forward, but with appropriate caution. When considering the use and application of AI related technologies, government leaders weigh different factors than their private sector counterparts. Whether it is deploying self-driving electric trolleys in a city or retrofitting city streetlights with sensors to make them “smarter,” these leaders must address issues of accountability, transparency, ethics, equity, common good, effectiveness, efficiency, managerial capacity, and political legitimacy.

The report authors put forth a threefold strategy to assist government leaders and public managers with how best to approach using AI, which includes:

  • reviews of prior federal government studies on the use and application of AI. These reports reflect a number of important issues for agencies and stakeholders to consider as they begin incorporating AI; the studies also highlight the government’s broad risk management approach to AI
  • a risk management framework for when and how government can and should consider using AI tools, how to use these tools, and which organizational tasks and decisions may benefit from the use of AI
  • case studies of two innovative uses of AI tools to help manage risks from local governments: the City of Syracuse, New York, and the City of Bryan, Texas.

The authors close with a list of practical guidelines for government action in using AI tools to improve the overall quality of governance, while incorporating similar tools into their overall risk management strategy.

ERM: Getting Everyone on Board without Sinking the Ship – 2018

In this 2018 Summit presentation… Successful ERM programs drive a cultural change that increases risk-awareness and transparency to inform risk-based decision making throughout the organization. Learn about the 10 building blocks of risk leader success, targeted risk communications, and other leading ERM practices from thought leaders in academia and non-profit sectors.

Speakers: Chris Mandel, Sedgwick Institute; Mahesh Joshi, GMU; Joe Pugh, AARP
Download

Techniques, Templates, and Toolkits in a Flash! – 2018

In this 2018 Summit presentation… Technology, tools, and templates should be seen as accelerators for a sound Enterprise Risk Management (ERM) framework, not a substitute. As with most other aspects of ERM implementation, the tools and templates developed and deployed by an ERM program should follow a maturity model approach and be customized to an organization. 

Tool or templates are only as good as the information input and how effectively their outputs put the right information in front of the right people at the right time. During this session, attendees learned how federal ERM programs have developed and deployed tools to support their programs’ maturation. Organizations beginning their ERM journeys can learn what tools provided the greatest value to the ERM program and organizational leadership from the initial stages of ERM implementation. While organizations with mature ERM programs can hear how tools continue to support organizations in making risk-informed decisions.

Speakers: Doug Clift, Census Bureau; Greg Keith, Ginnie Mae; Jason Leecost, Ginnie Mae; Debra Elkins, HHS
Download

Effective Integration of ERM and Internal Control – 2018

In this 2018 Summit presentation… OMB Circular A-123 requires Federal agencies to integrate their ERM and internal controls activities. In this session, the Enterprise Risk Management Officer and Director of Internal Controls for the National Institute of Standards and Technology (NIST) shared their experiences and the progress they’ve made toward this goal. The speakers described NIST’s ERM-Internal Controls Integration Framework, NIST’s new Audit Subcommittee, and lessons learned.

Speakers: Nahla Ivy, NIST; April Szuchyt, NIST
Download

Leveraging Technology to Enhance Your Agency’s ERM Capabilities – 2018

In this 2018 Summit presentation… Technology cannot provide an out of the box ERM program, but it can definitely facilitate the process. This session discussed how using technology can jump start your ERM program capabilities, and how these platforms are creating innovative solutions to challenges your ERM program may face through maturity such as risk identification, collection, collaboration, and prioritization.

Speakers: W. Curtis McNeil, AOC; LaTaiga Proctor, Census Bureau
Download

Applying ERM Principles to Functional Divisions: A Federal Grants Risk Management Case Study – 2018

In this 2018 Summit presentation… Today, buzz words like “enterprise risk management” (ERM) and “accountability” abound in the public and private sectors. But how do they really work operationally? Faced with an $11 billion budget for grant programs but finite internal resources to manage them, the Health Resources and Services Administration (HRSA) sought a way to use risk management to improve accountability and oversight of grants. Seeking a risk-based, data driven approach to strategic decisions, HRSA embarked on a one-of-a-kind assessment of current risks and related risk management practices, and the development of risk tools for decision makers.

This presentation provides a case study for operationalizing risk management in the grants world, and more generally at the sub-agency level. Those seeking to integrate risk management into their operations heard about project challenges and successes, key risk findings and recommendations, and considerations when taking on such a project. During the presentation, the speakers:

  • Explained the context within which HRSA determined to launch such an ambitious study, and the questions faced in developing the project;
  • Briefly walked through the tools developed to document and assess key risks and opportunities;
  • Described the findings of the study and how ERM principles were applied; and
  • Discussed the challenges and limitations faced with a risk management study of this kind.

Speakers: Lori Giblin, CNCS; Suzanne Auerbach, HRSA
Download

Shaping the Future Cybersecurity Risk in the Public Sector: A CIO Perspective – 2018

In this 2018 Summit presentation… CIO’s lessons learned in leveraging ERM to mitigate cybersecurity risks, including:

  • Innovative approaches for staying ahead of emerging risks
  • Motivating a risk culture that promotes transparency
  • Integrating risk monitoring with other entities (OIG, OMB, DHS, Board of Directors, others)
  • Best practices for addressing (and mitigating) reputational risks

Speaker: Howard Whyte, Chief Information Officer (CIO) and Chief Privacy Officer (CPO), FDIC
Download

Cyber Risk and the Chief Risk Officer: What CROs Need to Know About the New NIST Risk Management Framework – 2018

In this 2018 Summit presentation… NIST is doing a major upgrade to one of its flagship security guidelines, Special Publication 800-37, the Risk Management Framework (RMF). The updated RMF 2.0, to be published this Fall, will provide many new features for Cyber Risk Officers and Enterprise Risk Management (ERM) programs. In addition to managing security risk, the RMF 2.0 will also address privacy and supply chain risks and the alignment with key constructs in the Cybersecurity Framework (CSF) as part of a comprehensive and unified ERM approach.

Speaker: Ron Ross, NIST
Download