AI Governance in Practice: Build responsible, audit-ready programs with ISO/IEC 42001, NIST AI RMF, and lifecycle controls
暫譯: AI 治理實務:運用 ISO/IEC 42001、NIST AI RMF 與生命週期控制措施,建立負責任且可供稽核的治理計畫

Doshi, Hemang

  • 出版商: Packt Publishing
  • 出版日期: 2026-09-30
  • 售價: $1,550
  • 貴賓價: 9.5 折 $1,472
  • 語言: 英文
  • 頁數: 250
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1807300811
  • ISBN-13: 9781807300814
  • 相關分類: 人工智慧、資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Build an audit-ready AI governance program with practical assessments, lifecycle controls, and guidance aligned with ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act

Key Features:

- Apply ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act in practice

- Conduct AI impact and risk assessments using structured methods and practical templates

- Build audit-ready lifecycle controls, documentation, monitoring, and accountability

- Purchase of the print or Kindle book includes a free PDF eBook

Book Description:

Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle.

This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act, and other frameworks. You'll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance.

You'll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices.

Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you'll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes.

What You Will Learn:

- Explain responsible AI principles and governance lifecycle risks

- Compare ISO/IEC 42001, NIST AI RMF, OECD, and the EU AI Act

- Conduct structured AI impact and risk assessments

- Define accountable governance roles and decision rights

- Create policies and lifecycle controls for responsible AI

- Document AI systems for transparency and auditability

- Prepare for AI incidents with structured response processes

- Perform AI audits and improve governance from findings

Who this book is for:

AI governance, compliance, and risk management professionals responsible for overseeing AI systems, evaluating AI risks, or implementing responsible AI practices, along with data scientists, ML engineers, internal auditors, privacy leaders, and technology executives. A foundational understanding of AI concepts, basic IT risk principles, and organizational policies or governance frameworks is recommended. This book also provides a strong foundation for AI GRC certifications such as AIGP, AAIA, AAIR, AAISM, AIMS, and others.

Table of Contents

- Understanding Artificial Intelligence

- Introduction to AI Governance

- Principles of Responsible AI

- Overview of Global AI Governance Frameworks - ISO/IEC 42001 and EU AI Act

- AI Governance Framework - ISO/IEC 42001

- AI Governance Framework - NIST AI RMF

- AI Governance Framework - OECD AI Principles

- European Union AI Act

- AI Impact Assessment

- AI Risk Assessment

- Comparative Analysis of AI Frameworks - ISO/IEC 42001 and EU AI Act

- AI Governance Structure

- AI Governance Documents

- AI Lifecycle Governance

- Security of AI Systems

- AI Incident Management

- AI System Audits

商品描述(中文翻譯)

建立可供稽核的 AI 治理計畫,透過實務評估、生命週期控制,以及符合 ISO/IEC 42001、NIST AI RMF、OECD AI Principles 與 EU AI Act 的指引,打造完善的治理機制

主要特色:

- 實務應用 ISO/IEC 42001、NIST AI RMF、OECD AI Principles 與 EU AI Act
- 使用結構化方法與實用範本,執行 AI 影響評估與風險評估
- 建立可供稽核的生命週期控制、文件、監控與問責機制
- 購買紙本或 Kindle 書籍,即免費獲得 PDF 電子書

書籍簡介:

將 AI 治理原則、標準與法規要求,轉化為貫穿 AI 生命週期、能夠實際運作的治理計畫。

本書將說明如何以 ISO/IEC 42001、NIST AI RMF、OECD AI Principles、EU AI Act 及其他框架為基礎,建立負責任的 AI 治理機制。您將學習執行 AI 風險與影響評估、定義治理角色與決策權限、建立政策與生命週期控制,以及製作支援透明度、問責與 AI 法規遵循的文件。

您將學習如何在開發、部署、監控與除役等階段落實治理;處理 AI 安全性與可靠性;為 AI 事件做好準備;並運用 AI 稽核與監控結果強化控制措施。實務情境、範本、檢查清單與逐步指引,能將各項框架轉化為可重複執行的組織實務。

本書作者 Hemang Doshi 擁有超過 20 年的系統稽核、IT 風險與法規遵循、內部稽核、風險管理、資訊安全稽核、第三方風險管理及營運風險管理經驗。本書將治理框架與實務導入串聯起來。閱讀完本書後,您將能夠建立具備問責機制、可供稽核的 AI 治理計畫,並將 AI 風險管理整合至既有的法規遵循、安全性、隱私與風險管理流程中。

您將學會:

- 說明負責任 AI 原則與治理生命週期風險
- 比較 ISO/IEC 42001、NIST AI RMF、OECD 與 EU AI Act
- 執行結構化的 AI 影響評估與風險評估
- 定義具備問責機制的治理角色與決策權限
- 為負責任 AI 建立政策與生命週期控制
- 建立 AI 系統文件,以提升透明度與可稽核性
- 透過結構化的回應流程,為 AI 事件做好準備
- 執行 AI 稽核,並根據稽核結果改善治理機制

適合讀者:

本書適合負責監督 AI 系統、評估 AI 風險或導入負責任 AI 實務的 AI 治理、法規遵循與風險管理專業人員,以及資料科學家、ML 工程師、內部稽核人員、隱私主管與科技主管。建議讀者具備 AI 概念、基本 IT 風險原則,以及組織政策或治理框架的基礎理解。本書也能為準備 AI GRC 認證(例如 AIGP、AAIA、AAIR、AAISM、AIMS 等)的讀者打下良好基礎。

目錄

- 認識 Artificial Intelligence
- AI 治理簡介
- 負責任 AI 原則
- 全球 AI 治理框架概觀:ISO/IEC 42001 與 EU AI Act
- AI 治理框架:ISO/IEC 42001
- AI 治理框架:NIST AI RMF
- AI 治理框架:OECD AI Principles
- European Union AI Act
- AI 影響評估
- AI 風險評估
- AI 框架比較分析:ISO/IEC 42001 與 EU AI Act
- AI 治理架構
- AI 治理文件
- AI 生命週期治理
- AI 系統安全性
- AI 事件管理
- AI 系統稽核

最後瀏覽商品 (11)