Important notice
The Classic Experience will be sunset on
Aug. 1.
If you have questions, contact your Customer Success and Implementation Manager,
Account Manager, or
support@trustarc.com.
Risk Profile uses TrustArc's AI Risk Algorithm to calculate control effectiveness and residual risk directly from your assessment responses. To take advantage of this, your AI risk assessment needs to be prepared with the correct labeling before it can generate dynamic risk reporting.
This article covers how to prepare your AI risk assessment for technical validation, the rules TrustArc uses to validate your labels, and the steps to replace a TrustArc AI Risk Assessment with your own custom assessment in Risk Profile.
What you can do
✓Label question responses so Risk Profile can calculate control effectiveness and residual AI risk
✓Tag questions so the AI Risk Report auto-populates the AI system name, description, and organizational role
✓Replace a TrustArc AI Risk Assessment with your own custom assessment in Risk Profile
Prerequisites
✓Active TrustArc account with access to Risk Profile and Assessment Manager
✓An assessment published and completed at least once in Assessment Manager
Preparing Your Assessment
To ensure your assessment can leverage the full capabilities of Risk Profile — including TrustArc's AI Risk Algorithm and dynamic risk reporting — you must first prepare your AI risk assessment for technical validation.
TrustArc uses labels on question responses to calculate control effectiveness and residual risk, and breaks those calculations out by Trustworthy AI categories that align with TrustArc's Responsible AI Framework. Question tags and role labels are used to pull information into the AI Risk Report.
Labels must be correctly implemented on your assessment to ensure the risk and control effectiveness calculations in your risk reports are accurate, and to populate the AI Risk Report fields. TrustArc's validation and technical testing verifies that the AI risk algorithm and AI risk calculations are working properly, giving you confidence that everything works as expected before you roll your configured AI risk assessments out across your organization.
📋 Note: The Validation
Rules section below outlines exactly which labels and tags are
required on which questions and question responses.
Validation Rules
Your assessment, and any associated child assessments, are all validated and tested at the same time.
Response Tags
•For a question's response to be included in the report, it must contain a specific response tag. Two questions require this. The response to the first question is used to fill in the name of the AI system being assessed in the AI Risk Report — the (AI_System_Name) tag is required for the AI system name to appear in the report's AI System Name field.
Figure 1.0
The response to the second question provides a description of the AI system for the AI Risk Report. The (AI_System_Description) tag is required for the AI System Description field to be populated in the report.
Figure 2.0
⚠️ Warning: These tags must be configured exactly
as shown in Figures 1.0 and 2.0, and each can only be used once
in the assessment. If a tag is missing, the corresponding field
in the report will not be populated.
Role Labels
•To fill in the Role field of the AI Risk Report, questions about the organization's role in AI management must include two labels: the specific role and the organizational role, as shown in Figure 3.0. If no role labels are present in the assessment, the Role field in the report remains empty. Each role label should only be used once in the assessment.
Figure 3.0
Control Effectiveness and Trustworthy AI Category Labels
•Questions used to determine control effectiveness must have both a Control Effectiveness label and a Trustworthy AI Category label on each response, to calculate control effectiveness and residual risk. Additional labels on a response are fine — they don't affect the calculations.
•Questions used only to gather information about the AI system being assessed — or to determine a fact and whether a control applies — do not require labels.
Figure 4.0
📋 Example: Your assessment
might ask a Yes/No question to determine whether an organization's
AI processing is high risk. This question is used to determine
a fact, so it does not require Control Effectiveness or Trustworthy
AI Category labels.
Rules and Error Messages
The table below lists the rules your AI risk assessment is tested against, and the error messages returned if a rule is implemented incorrectly.
Rule
Error message returned
Supported Control Effectiveness values are 0,
1, 2, 3, or 4. Any Control Effectiveness label
with a value greater than 4 will return an error.
Control Effectiveness cannot be greater than 4
Each answer can have only zero or one Control
Effectiveness label. More than one on a single
response will return an error.
Only one Control Effectiveness is allowed per answer
Every Control Effectiveness label must be paired
with a Trustworthy AI Category label. A Control
Effectiveness label without one will return an
error.
Control Effectiveness exists but Trustworthy
AI Category is undefined
The presence of two or more Trustworthy AI Category
labels on a single response will return an error.
Only one Trustworthy AI Category is allowed per answer
All responses for a single question must share
the same Trustworthy AI Category label. A mismatched
response will return an error.
Only one Trustworthy AI Category is allowed per question
The assessment must contain at least one question
with a defined Control Effectiveness and Trustworthy
AI Category. If none exist, an error is returned.
Template has no risk label defined
Table 1.0
Valid AI Management Role Labels
These are the AI management role labels recognized by TrustArc's platform to populate the Role field in the AI Risk Report. Each is paired with an "Organization Role" label, as described above.
•"Provider" + "Organization Role"
•"Deployer" + "Organization Role"
•"Distributor" + "Organization Role"
•"Importer" + "Organization Role"
•"Other" + "Organization Role"
Table 2.0
Valid Control Effectiveness Labels
These are the Control Effectiveness labels recognized by TrustArc's platform intelligence to calculate control effectiveness and risk when generating your risk report.
•"Control Effectiveness = 0"
•"Control Effectiveness = 1"
•"Control Effectiveness = 2"
•"Control Effectiveness = 3"
•"Control Effectiveness = 4"
Table 3.0
Valid Trustworthy AI Category Labels
These are the Trustworthy AI Category labels recognized by TrustArc's platform intelligence to calculate control effectiveness by control category and data transfer risk when generating your risk report. They are paired with Control Effectiveness labels, as shown in Figure 4.0.
•"Valid and Reliable"
•"Explainable and Interapertable"
•"Accountable and Transparent"
•"Privacy Enhanced"
•"Fair with Risk of Harmful Bias Managed"
•"Safe"
•"Secure and Resilient"
Table 4.0
Replacing a TrustArc AI Risk Assessment
To replace a TrustArc AI Risk Assessment with one of your own, follow these steps:
1
Publish the assessment you want to use as a replacement,
and complete it at least once in Assessment Manager. This
makes it available in the right-hand column of the Risk Assessment
Configuration page's Add Template screen, where you select
which TrustArc AI risk assessments to replace.
📋 Note: Publishing
a replacement assessment does not impact your organization's
Risk Profile calculations. The assessment created in Assessment
Manager can be deleted later if needed.
2
On the Add Template screen, indicate which TrustArc AI risk
assessment(s) you want to replace with your own.
3
TrustArc conducts testing to confirm your labels are properly
implemented and that the risk and control effectiveness calculations
work correctly in the report.
4
TrustArc notifies you once your assessment is approved. It
will then appear on the Start Assessment window within the
Risk & Assessments tab, under the AI Risk tab, of a Hub
business process or system record.
Figure 6.0
Removing a Custom Assessment
If you choose to remove your approved custom assessment at a later time, click the trash can icon next to it. A confirmation message appears asking whether you'd like to delete the assessment template you used to replace a default TrustArc AI risk assessment.
Figure 7.0
TrustArc Trust Center · Preparing Your AI Risk Assessment for Risk Profile · support.trustarc.com