Hospitality Company Builds Foundation for Pursuing Responsible AI, Mitigating Risk with Comprehensive Standards and Enhanced Controls

Client Snapshot

Profile

The client is a multinational hospitality company that manages and franchises a broad portfolio of hotels and resorts.

 

Client Situation

Before exploring and adopting generative artificial intelligence capabilities across the enterprise, the client wanted to establish a comprehensive AI governance standard and control framework to address any new risks.

 

Work Performed

Protiviti conducted a thorough analysis of the client’s existing information security and technology standards and controls, then enhanced those controls and developed a customised AI governance standard, addressing the risks and concerns cited in leading industry standards on AI.

 

Outcome/Benefits

The introduction of a comprehensive governance standard and updated controls paved the way for the organisation to move forward aggressively, yet responsibly, with critical AI initiatives.

 
This tailored AI governance standard significantly improved the client's ability to guide and accelerate the responsible and ethical use of AI technologies across the organisation.

Benefits realised

The output we created gave the client the assurance and confidence needed to expeditiously pursue AI solutions and use cases, knowing that the right governance building blocks and the right framework to protect the organisation were in place. Having the right governance framework is essential and acts as an accelerator for AI-powered transformation.

The careful analysis enabled our team to deliver results that exceeded the client’s expectations, particularly given the limited timeframe. Most of the NIST AI RMF controls required already existed and simply needed to be extended to address AI technologies. Leveraging the majority of existing controls allowed the client to focus on the few unique controls that needed to be developed to effectively govern and control AI across the company. The new standard and controls were custom tailored to fit seamlessly into the client’s structure.

Once the mapping exercise was complete, daily working sessions were held to develop the new AI standard with particular attention to the modification of existing controls and the creation of new controls. In total, we delivered one new AI standard and nine net new AI controls, along with six modified controls. Additionally, updated procurement procedures, an acceptable use policy, user training and processes were implemented to help the client educate and enforce the new controls.

With these updates, the client is now well positioned to leverage the latest, powerful types of AI into its daily operations, giving it a competitive advantage over its peers across the industry. 

Loading...