Internal control assessment for artificial intelligence risk management Proposed model - COSO ERM according to the framework
Keywords:
COSO ERM framework, AI risk management, internal controlAbstract
This research aims to delve into the theoretical foundations of artificial intelligence (AI), including its definition, importance, management, and risks. It then examines key international efforts, such as the AI Risk Management Framework issued by the National Institute of Standards and Technology (NIST) and the ISO/IEC 42001:2023 standard. The research also addresses the COSO Enterprise Risk Management Framework (ERM) for managing AI risks, which comprises five elements (governance and culture, strategy and goal setting, performance, review and revision, and information, communication, and reporting) and twenty principles. Furthermore, the research seeks to develop a proposed model for evaluating internal controls in AI management based on the COSO ERM framework and apply it to Al-Mansour Investment Bank. The research instrument consisted of a questionnaire containing a set of questions based on the elements and principles of each element. The research concludes with several findings, most notably the necessity of adopting the COSO ERM framework in AI risk management. The results of applying the proposed internal control evaluation questionnaire to Al-Mansour Investment Bank indicate that the effectiveness of internal controls in AI risk management is at a moderate level, at 63%. That is, the risks of control, at 37%, were concentrated in the strengths of the effectiveness of internal control in the information, communications and reporting element at 100%, and the weaknesses of the effectiveness of internal control in the strategy and goal setting element at 56%.
Downloads
Published
Issue
Section
License
The copyright is transferred to the journal when the researcher is notified of the acceptance of his research submitted for publication in the journal.

