Deployers must implement a risk management policy and programme
Under Colorado AI Act, C.R.S. 6-1-1703(2)
What does it require?
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Practical action
Adopt an AI risk policy referencing NIST AI RMF or ISO/IEC 42001 and keep programme records.
Who does it apply to?
Deployers of high-risk AI systems affecting Colorado consumers.
Applies from:
Evidence examples
- AI risk management policy and programme (document)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | Whole framework (named in the statute) | The statute names the AI RMF as a recognised framework. | high |
| ISO/IEC 42001:2023 | Whole management system (named in the statute) | The statute names ISO/IEC 42001 as a recognised framework. | high |
Similar obligations in other instruments
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.