Site icon The ANSI Blog

Standardizing AI Risk Assessments for Critical Infrastructure

AI Governance and Risk Framework

AI is no longer a pilot project in critical infrastructure; it is active. Power grids, water treatment facilities, manufacturing plants, and hospital systems are all running AI-assisted operations. What hasn’t kept pace is a shared, reliable way to assess the risks those systems introduce. For operators, regulators, and standards professionals, that gap is hard to ignore.

Why Traditional Risk Frameworks Fall Short

According to Appendix B of the NIST AI Risk Management Framework 1.0 (2023), “As with traditional software, risks from AI-based technology can be bigger than an enterprise, span organizations, and lead to societal impacts. AI systems also bring a set of risks that are not comprehensively addressed by current risk frameworks and approaches.” Conventional software and industrial automation systems typically use deterministic systems that behave predictably given defined inputs. AI doesn’t work that way. Machine learning models can degrade silently, behave erratically under unfamiliar conditions, and produce outputs that are genuinely difficult to explain after the fact.

In operational technology (OT) environments, those traits have real consequences. An AI system managing electrical load balancing may handle routine conditions well, then fail in ways a conventional control system simply wouldn’t when it encounters something outside its training data. Standard vulnerability assessments weren’t designed to catch that kind of failure.

What AI Risk Actually Looks Like

Ask practitioners in any sector about AI risk and the same themes surface:

Safety: autonomous decisions causing harm when human oversight is thin.
Reliability: model drift, quietly degrading accuracy, failures that cascade under stress.
Data integrity: confident-looking outputs built on biased or compromised training data.

Then come the threats:

Data poisoning, or activity crafted to slip past AI-based anomaly detection. Add governance gaps like unclear ownership, weak audit trails, and no human in the loop when it counts. And don’t forget the supply chain: vulnerabilities riding inside pre-trained models, external data pipelines, and AI components bundled into commercial OT products.

The takeaway? AI risk in infrastructure is bigger than cybersecurity. It spans engineering reliability, safety assurance, and how organizations actually govern what they deploy.

Frameworks Already in Play

No single standard yet covers AI risk assessment for critical infrastructure OT environments end to end, but several frameworks offer useful building blocks.

The NIST AI Risk Management Framework (AI RMF), released in 2023, organizes AI governance around four functions: Govern, Map, Measure, and Manage.

It is designed to complement existing risk practices. NIST is also developing sector-specific profiles, including one for critical infrastructure.

At the international level, ISO/IEC 23894:2023 provides AI risk management guidance aligned with ISO 31000, while ISO/IEC 42001:2023 offers a certifiable AI management system standard covering documentation, monitoring, and improvement processes. To instill greater trust in this scheme, accreditation bodies accredit organizations that issue ISO/IEC 42001 certifications.

Industrial standards sit at different stages of engagement with AI. ISA/IEC 62443 addresses industrial cybersecurity, and ISA’s position paper Industrial AI and Its Impact on Automation highlights the series as providing a framework that can address and mitigate vulnerabilities in AI automation systems. IEC 61511 covers functional safety in the process industries.

Dedicated AI work is further along on the functional safety side. ISO/IEC TR 5469:2024, Artificial Intelligence — Functional Safety and AI Systems, describes the methods and processes involved in using AI inside a safety-related function, using non-AI safety functions to assure safety for AI-controlled equipment, and using AI systems to design and develop safety-related functions. That groundwork is now being built into normative guidance: joint working group JWG 4, formed by ISO/IEC JTC 1/SC 42 and IEC TC 65/SC 65A—the committee behind the IEC 61508 series—is developing ISO/IEC TS 22440, aimed at AI reliability in areas including industrial control systems.

Where the Gaps Are in AI Frameworks

Good frameworks exist, but translating them into consistent, sector-ready assessment practice is harder than it looks.

Explainability is one persistent obstacle. Deep learning models often can’t tell you why they made a decision, which is a fundamental problem in environments where regulators and engineers need traceable justification for system behaviour.

Cross-sector consistency is another challenge: a methodology suited for healthcare AI won’t map cleanly onto industrial control systems or transportation networks. Without a shared taxonomy for AI failure modes, risk identification remains uneven.

There’s also a skills dimension. OT engineers may have limited exposure to AI validation methods, while AI specialists may be unfamiliar with industrial safety standards. Bridging that divide requires sustained investment in cross-disciplinary expertise.

The Case for Standardization

A common assessment methodology would give regulators a defensible, comparable baseline across operators. It would let infrastructure organizations benchmark their AI governance programs, identify gaps, and demonstrate accountability. For procurement teams, shared criteria would bring AI components in commercial OT products under consistent scrutiny rather than letting risk slip through in vendor-supplied systems.

Moving Forward Together

Mapping the relationships among NIST AI RMF, ISO/IEC 42001, IEC 62443, and sector safety standards would help practitioners understand which tools apply and how they fit together. The OECD AI Principles and EU AI Act implementation efforts offer useful reference points for international alignment.

The foundational work with standardized AI risk assessments is underway. The priority now is translating those foundations into methodologies that are rigorous enough to be credible and practical enough to be used in infrastructure environments.

Contributing Author: Muhammad Ali Khan

Muhammad Ali Khan is an OT/ICS cybersecurity leader with 17 years of experience securing critical infrastructure across manufacturing, oil & gas, power, telecom, and transport. He leads industrial security programs at enterprise scale and advises CISOs, plant leadership, and executives on OT governance and security transformation. A standing member of the ISA/IEC 62443 Standards Development Committee and Assistant Education Director of the ISA Houston Section, he is a 2026 TEDx speaker, a selected speaker for the National Cyber Summit, and volunteers free cyber health checks for community water systems. He holds CISSP, CISM, CISA, CGEIT, AAISM, CEH, CHFI, and ISO 27001 Lead Implementer credentials. Find him on ORCID, Google Scholar, and LinkedIn.

Exit mobile version