IT Risk Management in the Age of AI
Über das eBook
Your risk function is already using AI. The question is whether it can still defend its conclusions.
Somewhere in your organisation, a language model drafted a risk assessment. An anomaly detector is scoring your colleagues. A vendor's platform shipped a "smart" feature nobody assessed. None of it appeared in a project plan.
This book builds one unified risk process - seven stations, from context-setting to reporting - that satisfies COSO ERM, NIST RMF, NIST AI RMF, ISO 27001/27005, ISO 42001, GDPR, DORA, NIS2 and the EU AI Act without being run nine times. Then it examines every AI capability twice: what it contributes, and where it fails. AI makes rigour cheaper - full populations instead of samples, current state instead of a nine-month-old snapshot. It also amplifies whatever it is given, including your blind spots, at machine speed and with perfect fluency.
Inside: a maturity model that measures whether governance survived adoption; use-case screening on value, feasibility and defensibility; human oversight specified as a designed control; what must never be delegated, argued rather than asserted; fairness when the risk model itself discriminates; agentic systems, continuous assurance and post-quantum migration assessed for what they change now. Plus nine appendices of working material - a master framework crosswalk, a combined DPIA/FRIA/conformity template, an EU AI Act classification decision tree, a 41-indicator KRI library, and worked register entries across five industries.
Machine informs, drafts, and checks. Human judges, owns, and signs. That formula is the argument of this book, and the reason the profession is not ending but concentrating.
For chief risk officers, IT risk and compliance leaders, internal auditors, and information security managers.
Über den Autor
Juan Falcon works where this book does: between the frameworks organisations must satisfy and the operational reality of satisfying them.
He currently serves as global head of IT continuity governance and IT risk management for a multinational manufacturer, where he designed and deployed enterprise risk and continuity frameworks aligned to NIS2, NIST 800-53 and COSO ERM - including risk appetite and KRI structures. As AI governance lead and a member of the enterprise AI committee, he built the policy, assessment and control apparatus for responsible AI adoption against the EU AI Act and the NIST AI RMF. His earlier career spans a decade at PwC across IT audit, information security and global compliance, serving regulated financial institutions, banks and fintechs, and covering SOX and J-SOX ITGC, GDPR, SOC 2, ISO 27001 and ISO 22301, DORA, and GxP assurance under FDA 21 CFR Part 11.
He is CISSP-certified, a member of the IIA and ISACA, an MBA student at Durham University, and the author of four previous books on enterprise AI, including The Responsible AI Blueprint.
Produkt Details
Verlag: BoD - Books on Demand
Genre: Sprache - Englisch
Sprache: English
Umfang: 0 Seiten
Größe: 1,0 MB
ISBN: 9783696764777
Veröffentlichung: 26. August 2026