← Back to list

04: Governance & Risk Management — Certified LLM Security Professional : සිංහල

මේ module එකේ focus එක technical attack එකකට වඩා organization-level AI security management.

Chanuka Isuru Sampath · 2026-06-06 09:35 · 0 claps · 10.2 min read
#ai-governance #ai-risk-managment #cllmsp #ai #llm
Open on Medium ↗
Wiki topics: LLM · Large Language Models AI · AI · General BIZ · Business Strategy ⏱️ · Productivity

04: Governance & Risk Management — Certified LLM Security Professional : සිංහල

මේ module එකේ focus එක technical attack එකකට වඩා organization-level AI security management.

LLM එකක් company එකක use කරනකොට “model safe ද?”, “data privacy protect වෙනවද?”, “law/regulation follow කරනවද?”, “incident එකක් වුණොත් කවුද responsible?” වගේ දේවල් manage කරන්න ඕන.

💡 Example:

Pentest tool එකක් තියෙන එක alone enough නැහැ. Company policy, approval, logging, risk register, responsible team මේ ඔක්කොම ඕන. AI වලත් එහෙම.

📌 Governance කියන්නේ මොකක්ද?

Governance කියන්නේ organization එකක් rules, responsibilities, processes දාලා system එක properly control කරන එක.

AI governance කියන්නේ AI systems safe, legal, ethical, accountable විදිහට use කරන framework එක.

💡 Example:

School එකක rules තියෙනවා: uniform, exam rules, attendance, discipline. ඒ rules නැත්තම් chaos. Company AI use එකටත් rules ඕන.

📌 Risk Management කියන්නේ මොකක්ද?

Risk management කියන්නේ possible problems identify කරලා, ඒවාට controls දාලා, impact reduce කරන process එක.

AI වල risks: data leak, bias, hallucination, prompt injection, legal violation, wrong decisions.

💡 Example:

Bike ride කරනකොට accident risk තියෙනවා. Helmet, license, traffic rules, brake check — මේවා risk management.

📌 Why AI Governance Important?

AI system එකක් wrong decision දුන්නොත් company reputation, legal compliance, customer trust, money ඔක්කොම impact වෙන්න පුළුවන්.

Especially hiring, banking, healthcare, insurance වගේ domains වල AI decision එක serious.

💡 Example:

AI loan approval system එකක් wrong bias නිසා fair customers reject කළොත් legal සහ reputation issue වෙනවා.

📌 4.1 NIST AI RMF

NIST AI RMF කියන්නේ AI risks manage කරන්න use කරන framework එකක්.

RMF = Risk Management Framework.

මේක voluntary framework එකක්, but many companies and governments AI governance වලදී reference කරනවා.

💡 Example:

Cybersecurity වල NIST CSF use කරනවා වගේ, AI risk වලට NIST AI RMF use කරනවා.

📌 NIST AI RMF Core Functions

NIST AI RMF functions 4ක් තියෙනවා:

  • Govern
  • Map
  • Measure
  • Manage

මේ 4 steps AI risk lifecycle එක cover කරනවා.

💡 Example:

Exam prepare වෙනකොට: plan හදනවා, syllabus map කරනවා, progress measure කරනවා, weak areas manage කරනවා.

📌 Govern

Govern කියන්නේ AI risk management policies, roles, accountability define කරන එක.

කවුද AI approve කරන්නේ?

කවුද monitor කරන්නේ?

කවුද incident handle කරන්නේ?

Rules මොනවද?

💡 Example:

Company එකක firewall change කරන්න approval process තියෙනවා. ඒ වගේ AI model deploy කරන්නත් governance process තියෙන්න ඕන.

📌 Map

Map කියන්නේ AI system එක use වෙන්නේ කොහෙද, impact එක මොකක්ද, risks මොනවද කියලා identify කරන එක.

Use case එක low-risk ද high-risk ද කියලා understand කරනවා.

💡 Example:

AI chatbot එක jokes කියනවා නම් low risk. AI එක loan approval decide කරනවා නම් high risk.

📌 Measure

Measure කියන්නේ identified risks test/assess/quantify කරන එක.

Model accuracy, bias, jailbreak resistance, hallucination rate, privacy leakage risk වගේ metrics measure කරන්න පුළුවන්.

💡 Example:

Gym progress බලන්න weight, reps, body measurements track කරනවා. AI risk වලටත් metrics ඕන.

📌 Manage

Manage කියන්නේ risks reduce කරන්න controls implement කරන එක.

Guardrails, monitoring, human review, access control, red teaming, policy updates වගේ mitigations apply කරනවා.

💡 Example:

Bike brake weak කියලා measure කළාට වැඩක් නැහැ. Brake fix කරන්න ඕන. ඒක manage.

📌 ISO/IEC 42001

ISO/IEC 42001 කියන්නේ AI Management System standard එකක්.

Organizations AI systems responsibly manage කරන්න requirements define කරන international standard එකක්.

💡 Example:

ISO 27001 information security management system එකක් වගේ, ISO 42001 AI management system එකකට.

📌 AIMS කියන්නේ මොකක්ද?

AIMS = Artificial Intelligence Management System.

AI develop, deploy, monitor, improve කරන organization process එක structured කරන්න use කරන system එක.

💡 Example:

Restaurant එකක hygiene management system තියෙනවා. ඒකෙන් food safety maintain වෙනවා. AI වලට AIMS එහෙම.

📌 Why ISO 42001 Useful?

It helps company prove කරගන්න AI responsibly manage කරනවා කියලා.

Audits, compliance, customer trust, procurement requirements වලට useful.

💡 Example:

Company එකක් “අපි secure” කියනවට වඩා ISO certification තියෙනවා නම් customers trust කරනවා.

📌 4.2 EU AI Act & Global Regulations

EU AI Act කියන්නේ AI systems regulate කරන major law එකක්.

AI systems risk level අනුව classify කරනවා.

Main idea: high-risk AI systems වලට strict requirements.

💡 Example:

Toy car එකකට simple rules. Real car එකකට license, insurance, road rules, safety tests ඕන. AI systems වලත් risk අනුව rules වෙනස්.

📌 EU AI Act Risk Tiers

EU AI Act risk categories:

  • Unacceptable Risk
  • High Risk
  • Limited Risk
  • Minimal Risk

Risk වැඩි වුණාම rules strict වෙනවා.

💡 Example:

Water bottle sell කරන business එකට one level rules. Medicine sell කරන business එකට much stricter rules.

📌 Unacceptable Risk

Unacceptable risk AI systems usually banned.

Examples: social scoring, manipulative AI, some biometric surveillance use cases.

මේවා society/user rights වලට too dangerous කියලා consider කරනවා.

💡 Example:

Government එක citizensට score දීලා ඒ score අනුව services deny කරන system එකක් dangerous.

📌 High Risk

High-risk AI කියන්නේ serious decisions වල use වෙන AI.

Examples: hiring, credit scoring, healthcare diagnosis, law enforcement, education access.

මෙවට documentation, human oversight, monitoring, risk controls required.

💡 Example:

AI එක job applicant reject කරනවා නම්, ඒ decision fair ද explainable ද කියලා check කරන්න ඕන.

📌 Limited Risk

Limited risk AI systems වල main requirement එක transparency.

Userට AI එක්ක interact කරනවා කියලා clearly inform කරන්න ඕන.

💡 Example:

Website chatbot එක human agent නෙවෙයි AI chatbot කියලා userට කියන්න ඕන.

📌 Minimal Risk

Minimal risk AI apps වලට heavy requirements නැහැ.

Examples: AI game character, spam filter, simple creative tools.

💡 Example:

AI meme generator එකක් high-risk healthcare diagnosis system එකක් වගේ regulate කරන්න ඕන නැහැ.

📌 Data Residency

Data residency කියන්නේ data store/process වෙන්නේ කොයි country/region එකේද කියන requirement එක.

Some sensitive data local region එකෙන් පිට යන්න බැහැ.

💡 Example:

Bank customer data Sri Lanka/approved region තුළම store කරන්න policy එකක් තිබුණොත්, random overseas AI API එකකට send කරන්න බැහැ.

📌 GDPR Article 22

GDPR Article 22 automated decision-making ගැන relevant.

Userට significant automated decision එකක් ගැන explanation/right to challenge තියෙන්න පුළුවන්.

💡 Example:

AI එක loan reject කළා නම් customerට “ඇයි reject වුණේ?” කියලා explanation request කරන්න පුළුවන්.

📌 Vendor Risk Management

Third-party LLM API use කරනකොට vendor risk manage කරන්න ඕන.

Model behavior, data handling, logging, training usage, compliance, incident response — මේවා verify කරන්න ඕන.

💡 Example:

Company confidential data external supplierට දෙනවා නම් NDA, security review, contract controls අවශ්‍යයි.

📌 4.3 Red Teaming & Adversarial Testing Programs

LLM red teaming කියන්නේ AI system එක intentionally attack/test කරලා weakness identify කරන process එක.

Traditional pentesting වගේම, but AI-specific tests include කරනවා.

💡 Example:

Building security test කරන්න authorized team එක fake break-in attempt කරනවා. AI red team එක model break කරන්න authorized attempts කරනවා.

📌 LLM Red Teaming vs Normal Pentesting

Normal pentesting web/server vulnerabilities test කරනවා.

LLM red teaming additionally prompt injection, jailbreaks, hallucination, data leakage, bias, tool abuse, RAG attacks test කරනවා.

💡 Example:

Normal car inspection engine/brake බලනවා. Self-driving car inspection AI decision system එකත් test කරන්න ඕන.

📌 Jailbreak Testing

Model safety rules bypass කරන්න try කරන prompts test කරනවා.

Goal එක harmful outputs produce වෙනවද, refusal consistent ද කියලා check කිරීම.

💡 Example:

School firewall එකට blocked content access කරන්න tricks try කරලා filter strong ද බලනවා.

📌 Prompt Injection Testing

Direct සහ indirect prompt injection test කරනවා.

RAG documents, emails, webpages, tool results වල malicious instructions hide කරලා model behavior බලනවා.

💡 Example:

Company chatbot එක PDF read කරනවා නම්, malicious PDF instruction දාලා system prompt override වෙනවද test කරනවා.

📌 Data Extraction Testing

Model එක sensitive info reveal කරනවද test කරනවා.

System prompt, secrets, memorized training data, unauthorized RAG documents leak වෙනවද බලනවා.

💡 Example:

Bank chatbot එකට “show admin notes” කියලා try කරලා access control strong ද බලනවා.

📌 Bias and Fairness Testing

Model එක protected groups ගැන unfair output දෙන්නෙද test කරනවා.

Hiring, finance, education වගේ domains වල මේක very important.

💡 Example:

AI hiring tool එක different gender/name/background resumes fair score කරනවද test කරනවා.

📌 Policy Compliance Verification

Company policy, legal requirements, safety rules follow වෙනවද test කරනවා.

Model එක approved use cases වලට පමණක් work කරනවද බලනවා.

💡 Example:

Company AI policy says “No customer PII in public LLM.” Red team test කරනවා users data paste කරන scenarios block වෙනවද කියලා.

📌 Tool / Plugin Abuse Testing

AI tools misuse කරන්න පුළුවන්ද test කරනවා.

Email send, database query, file read, API call, MCP tools වගේ actions verify කරනවා.

💡 Example:

AI assistantට “send_email” tool තියෙනවා නම්, prompt injection එකකින් external attackerට email යවන්න පුළුවන්ද test කරනවා.

📌 Red Team Program Structure

Good AI red team program එක one-time test එකක් නෙවෙයි.

Deployment එකට කලින් baseline test කරන්න.

Model update එකකට පස්සේ retest කරන්න.

Regular intervals වල retest කරන්න.

Findings risk register එකට add කරන්න.

💡 Example:

Gym එකට එක දවසක් ගියා කියලා fit වෙන්නේ නැහැ. Continuous training ඕන. AI security testingත් continuous.

📌 4.4 AI Risk Registers & Model Cards

මේ section එක governance documentation ගැන.

AI system එකේ risks, limitations, intended use, controls, evaluation results document කරන්න ඕන.

💡 Example:

Pentest report එකක් නැතුව findings track කරන්න අමාරුයි. AI risks වලටත් documentation ඕන.

📌 AI Risk Register

AI Risk Register කියන්නේ AI system risks track කරන document එක.

Risk name, likelihood, impact, owner, controls, mitigation plan, status වගේ fields තියෙනවා.

💡 Example:

Project task tracker එකක් වගේ. But tasks වෙනුවට risks track කරනවා.

📌 AI Risk Register Example Fields

Risk: Prompt Injection

Likelihood: High

Impact: High

Control: Input guardrails, tool restrictions

Owner: AI Security Team

Status: In progress

💡 Example:

Hospital එකක patient risk chart එකක් තියෙනවා. Condition, severity, treatment, doctor owner. Risk register එකත් ඒ වගේ.

📌 Technical Risks

Technical risks include:

  • Prompt injection
  • Hallucination
  • Data leakage
  • Model drift
  • Tool abuse
  • RAG poisoning

💡 Example:

AI chatbot එක malicious document follow කරලා wrong answer දෙන්න පුළුවන් : technical risk.

📌 Operational Risks

Operational risks include:

  • Vendor dependency
  • Model downtime
  • Cost spikes
  • Lack of monitoring
  • Poor incident response

💡 Example:

Company එක full AI API vendor එකකට depend නම්, vendor outage එකකදී service down වෙනවා.

📌 Ethical Risks

Ethical risks include:

  • Bias
  • Fairness issues
  • Discrimination
  • Lack of transparency
  • Harmful recommendations

💡 Example:

AI loan approval system එක certain group එකකට unfairly reject කරනවා නම් ethical + legal risk.

📌 Reputational Risks

Reputational risk කියන්නේ AI mistake එකක් නිසා company trust damage වෙන එක.

💡 Example:

Company chatbot එක offensive answer එකක් දුන්නොත් screenshot social media වල viral වෙන්න පුළුවන්.

📌 Model Cards

Model card කියන්නේ model එක ගැන standardized documentation එකක්.

It explains model capabilities, limitations, intended use, evaluation results, known failure modes.

💡 Example:

Medicine packet එකේ label එක තියෙනවා: use, dosage, side effects, warnings. Model card එකත් AI model label එක වගේ.

📌 Model Card Contents

Model card එකක usually තියෙන්නේ:

  • Model name
  • Purpose
  • Training data summary
  • Intended use
  • Not intended use
  • Performance metrics
  • Limitations
  • Risks
  • Evaluation results

💡 Example:

“මේ model එක customer support සඳහා designed. Medical diagnosis සඳහා use කරන්න එපා” කියලා model card එකේ mention කරන්න පුළුවන්.

📌 Why Model Cards Important?

Model use කරන teamsට model එකෙන් කරන්න පුළුවන් දේ සහ බැරි දේ තේරුම් ගන්න help වෙනවා.

Governance, compliance, responsible deployment වලට useful.

💡 Example:

Tool manual එකක් නැතුව machine එක use කළොත් accident වෙන්න පුළුවන්. Model card එක model manual එක වගේ.

📌 4.5 Shadow AI, Acceptable Use & Accountability

මේ section එක company employees unauthorized AI tools use කරන risk එක ගැන.

AI governance නැතිනම් employees personal ChatGPT/Gemini tools වලට confidential data paste කරන්න පුළුවන්.

💡 Example:

Employee කෙනෙක් company source code personal AI tool එකකට paste කරලා “fix this code” කියනවා. Data leak risk.

📌 Shadow AI

Shadow AI කියන්නේ IT/security approval නැතුව employees AI tools use කරන එක.

Shadow IT වගේම, but data leakage risk වැඩි.

💡 Example:

Company approve නොකළ file sharing app එකක් use කරනවා වගේ. මෙතන approve නොකළ AI chatbot එකක් use කරනවා.

📌 Why Shadow AI Dangerous?

Sensitive data external AI providersට යන්න පුළුවන්.

Prompts logs වල store වෙන්න පුළුවන්.

Data training වලට use වෙන්න පුළුවන්.

Compliance violation වෙන්න පුළුවන්.

💡 Example:

HR employee කෙනෙක් employee salary sheet public AI tool එකකට paste කළොත් huge privacy issue.

📌 Acceptable Use Policy

Acceptable Use Policy කියන්නේ employeesට AI tools use කරන්න allowed/prohibited rules define කරන policy.

මේක clear කරන්න ඕන:

  • Approved AI tools
  • Allowed data types
  • Prohibited data
  • Approval process
  • Escalation path
  • Monitoring rules

💡 Example:

Company internet policy එකේ “pirated software download කරන්න එපා” කියලා තියෙනවා. AI policy එකේ “customer PII public LLM වලට paste කරන්න එපා” කියලා තියෙන්න ඕන.

📌 Approved Use Cases

Policy එකේ approved use cases list කරන්න ඕන.

Example:

  • Grammar improvement
  • Public content summarization
  • Code suggestions with review
  • Internal chatbot with approved data

💡 Example:

Employeeට public blog post draft කරන්න AI use කරන්න allow. But confidential contract upload කරන්න not allowed.

📌 Prohibited Activities

Policy එකේ prohibited activities clear කරන්න ඕන.

Examples:

  • Uploading customer PII
  • Sharing passwords/API keys
  • Using AI for final legal/medical decisions without review
  • Bypassing security controls
  • Unauthorized model training

💡 Example:

“Company AWS secret key ChatGPT එකට paste කරන්න එපා” කියලා policy එකේ explicitly තියෙන්න ඕන.

📌 Algorithmic Accountability

Algorithmic accountability කියන්නේ AI-driven decisions explain කරන්න සහ justify කරන්න organizationට හැකියාව තියෙන්න ඕන කියන එක.

AI decision එකක් නිසා harm වුණොත් “AI did it” කියලා blame shift කරන්න බැහැ.

💡 Example:

AI hiring tool එක candidate reject කළා. Company explain කරන්න ඕන decision basis එක, human oversight එක, appeal process එක.

📌 Audit Trails

AI systems වල audit trails තියෙන්න ඕන.

  • Who asked?
  • What prompt?
  • What model?
  • What output?
  • What tool actions?
  • Who approved?

💡 Example:

Bank transaction logs වගේ AI decision logsත් තියෙන්න ඕන.

📌 Human Accountability

AI system එක final decision support කළත් human owner එකක් තියෙන්න ඕන.

Especially high-risk domains වල human oversight mandatory.

💡 Example:

Autopilot plane fly කළත් pilot responsible. AI decision system එකක් use කළත් organization responsible.

📌 Responsible Disclosure

LLM vulnerability එකක් discover කළොත් responsible disclosure follow කරන්න ඕන.

Vendorට report කරන්න.

Reasonable fix time දෙන්න.

Then public disclosure කරන්න if appropriate.

💡 Example:

Website vulnerability එකක් හම්බුණාම directly social media post කරන්නේ නැහැ. First company security teamට report කරනවා.

✅ MODULE 04 — Exam Memory Points

Governance = AI systems responsibly control කරන organization framework.

Risk management = risks identify, measure, reduce, monitor කරන process.

NIST AI RMF core functions: Govern, Map, Measure, Manage.

ISO/IEC 42001 = AI Management System standard.

EU AI Act AI systems risk tiers වලට classify කරනවා.

Risk tiers: Unacceptable, High, Limited, Minimal.

High-risk AI වල documentation, human oversight, monitoring required.

LLM red teaming includes jailbreak, prompt injection, data extraction, bias, tool abuse testing.

AI risk register tracks risk, likelihood, impact, controls, owner, mitigation.

Model card is like model documentation/manual.

Shadow AI = unauthorized AI tool usage by employees.

Acceptable Use Policy defines allowed/prohibited AI usage.

Algorithmic accountability means AI decisions explain and justify කරන්න ඕන.

Responsible disclosure means vulnerability ethically report කිරීම.

🧠 MODULE 04 Mini Quiz

1. NIST AI RMF functions 4 මොනවද?

A. Scan, Exploit, Report, Patch

B. Govern, Map, Measure, Manage

C. Train, Prompt, Output, Delete

2. Shadow AI කියන්නේ මොකක්ද?

A. Dark mode AI interface එක

B. IT approval නැතුව employees AI tools use කරන එක

C. AI model එක local machine එකේ run කරන එක

3. Model Card එකක purpose එක මොකක්ද?

A. Model එකේ documentation, capabilities, limitations explain කරන එක

B. Password store කරන එක

C. Prompt injection attack කරන එක

✅ Answers

  1. B
  2. B
  3. A

🌐 Follow Me

LinkedIn: https://www.linkedin.com/in/chanuka-isuru-sampath/

GitHub: https://github.com/RIO6IX

Medium: https://medium.com/@chanuka1

Portfolio Website: https://rio6ix.github.io/chanuka/

Youtube: https://www.youtube.com/@chanukaisuru0


메타데이터
post_id
dc3360db487d
slug
04-governance-risk-management-certified-llm-security-professional-සිංහල-dc3360db487d
url
https://medium.com/@chanuka1/04-governance-risk-management-certified-llm-security-professional-%E0%B7%83%E0%B7%92%E0%B6%82%E0%B7%84%E0%B6%BD-dc3360db487d
canonical_url
https://medium.com/@chanuka1/04-governance-risk-management-certified-llm-security-professional-%E0%B7%83%E0%B7%92%E0%B6%82%E0%B7%84%E0%B6%BD-dc3360db487d
author_url
https://medium.com/@chanuka1
status
ok
fetched_at
2026-06-09 15:37:30