AI TRiSM (AI trust, risk and security management)

What is AI TRiSM?

AI TRiSM stands for AI trust, risk and security management. It is the name Gartner gives to everything a company does to keep the AI it runs trustworthy, safe and legal, from knowing which models are in use to being able to stop one that misbehaves.

The term comes from Gartner and from nowhere else. It reached a wide audience when Gartner put AI trust, risk and security management on its list of top strategic technology trends for 2023, published in October 2022. There is no committee behind it, no public document you can read cover to cover, and no exam you can sit. Treat it as a filing cabinet rather than a rulebook: a few drawers to sort your existing controls into, so you notice which drawer is empty.

The four layers, as Gartner states them now

The framework has been restated and both versions still circulate, so it pays to know which one you are reading. The current one, in Gartner's market guide on AI TRiSM in its 2025 edition, has four layers.

  1. AI governance. Visibility and accountability over every AI asset: an inventory, a named owner per system, a record of what was decided. Gartner puts this at the bottom, as the foundation the rest stands on.

  2. AI runtime inspection and enforcement. Watching models, applications and agent interactions while they run, and being able to step in. Logging, blocking, spend and rate limits, a kill switch.

  3. Information governance. Keeping an AI system to data it is permitted to reach, which is a matter of access rights on the data rather than of anything you do to the model.

  4. Infrastructure and stack. Endpoint, network, cloud and identity security. Nothing new here, and that is the point.

The earlier formulation, from 2022 and 2023, named explainability and model monitoring, ModelOps, AI application security, and privacy. It was written when AI inside a company mostly meant a model your own team had trained. A vendor page still showing you those four is quoting a framework from before agents.

What AI TRiSM is not

Not a standard and not law. No clause list, no annex of controls, no accredited auditor, so there is nothing to be certified against. No regulation names it either, so doing all of it discharges no legal duty and skipping all of it breaches none. A supplier who calls itself TRiSM compliant has said something you cannot check.

Not a product. Several security vendors now sell an AI TRiSM platform. What is in the box is a piece of one layer, almost always runtime inspection, because that is the layer with software in it. The governance layer is a list, an owner and a meeting, and no product holds those for you.

AI TRiSM versus ISO/IEC 42001

Both organise AI work rather than build AI, and they split on one dimension: whether anyone outside your company can check that you did it.

ISO/IEC 42001 is a published standard with numbered clauses and a normative annex of controls. An accredited body audits you, issues a certificate with a written scope, and comes back on a surveillance audit. A customer can ask for it, read what it covers, and reach a conclusion without having to trust you. AI TRiSM has none of that machinery, so saying you follow it is a statement about your own vocabulary. A customer who wants proof has to ask the next question anyway: show me the inventory, show me who owns this system, show me a log of what it did last month. The sentence buys you nothing in a tender and quite a lot in a design discussion.

Four things get mixed together in that conversation while sitting in different categories:

  • The EU AI Act is law. It applies whether you have heard of it or not, and it carries fines.

  • ISO/IEC 42001 is voluntary and certifiable. An outside party can verify that you hold it.

  • The NIST AI Risk Management Framework, version 1.0 of 26 January 2023, is voluntary, published and not certifiable. Its four functions, govern, map, measure and manage, are free to borrow.

  • AI TRiSM is vocabulary. Good for sorting, no use for proving.

The five questions, and the drawer that comes back empty

Strip the analyst wording and TRiSM asks five things: which AI is in use here, including what arrived inside software you already pay for; can you explain a decision one of them made, in the words you would use to the person on the receiving end; what data does it see; would you notice if it stopped working properly; and who is accountable, by name rather than by department.

Take a technical wholesaler in Limburg, sixty people, no data team. Microsoft 365 across the company, a quotation assistant a supplier built on their ERP, a chatbot on the website. Three drawers are full already. Infrastructure was in place before any AI arrived. Information governance holds too, with an old problem showing through: Copilot respects the SharePoint permissions exactly, so the salary file half the company could always open is now a file half the company can ask questions about. AI governance is half there: the usage policy and IT's purchase list miss the transcription tool three account managers use, and nobody owns the quotation assistant since the project manager who ordered it left.

The empty drawer is runtime inspection. The assistant proposes a discount, a salesperson accepts or edits it, and the proposal disappears. Nothing records what was suggested against what went out the door, so if it drifts towards discounts that are too generous, the first signal anyone gets is the margin report at quarter end. Closing that does not take a platform. It takes logging the suggestion next to the sent quote, then half an hour a month with twenty of those pairs side by side.

That result is the normal one. Most companies already have security for their systems and governance for their data, and neither covers how a model behaves, whether it still behaves that way six months later, or what an agent did on Tuesday afternoon. Gartner named the hole, and the name is the least interesting part of it.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
ai trism ai trust risk and security management gartner ai governance responsible ai explainable ai model drift data governance iso 42001 ai act nist ai rmf ai risk management