Assess Before You Decide
When a business conducts a risk assessment, only a handful of people see it.
Access is on a "need to know" basis, which rarely includes stakeholders who might be at greatest risk.
When consumers conduct risk assessments, consumers own the work product,
which they can use for any legal purpose they desire.
For what purpose will you conduct risk assessments?
When a business conducts an impact assessment, they are most often concerned about the impact to the organization itself.
If the impact assessment is focused on Consumers, aka "the general public",
the Consumer is best positioned to validate the harms or benefits to themselves.
When consumers conduct impact assessments,
they need evidence of impacts caused by or associated with decisions made or actions taken by an organization.
Yo-AI is designed to discover these decisions, the factors used to arrive at outcomes, and impacts of these outcomes on the subject of these decisions.
Personal Risk
"When there is a choice"
-
Ask Questions
-
Exercise Your Rights
-
Conduct Due Diligence
-
Get Promises in Writing
Issue Resolution
"When there is a problem"
-
Identify the issue
-
Provide evidence of harm
-
Propose an effective, workable solution
Escalating Complaints
"When all other efforts fail"
-
File complaints with regulators
-
Inform all stakeholders
-
Apply pressure on all stakeholders
Cybersecurity Risk Assessments & Audits
Every organization must protect personal information
If Yo-AI falls short on discovering harm from automated decision-making technologies or cannot prove an organization violated laws pertaining to privacy and the use of AI, other consumer protections may still apply.
As mandated by the GDPR in the EU, there are Data Protection Authorities where individuals can lodge complaints.
In the United States, the legal and regulatory landscape is scattered across state and federal agencies.
Many businesses and government agencies must comply with mandates to certify claims they make about their products, services, and business practices.
SOC2, ISO, FedRAMP, PCI-DSS, HIPAA, etc. are compliance frameworks introduced by industries and lawmakers, as standard guidelines for objective, independent auditors to evaluate.
Many organizations in the US, the EU, and elsewhere use Data Processing Agreements (DPAs).
These are legal agreements made between two parties - generally only offered to businesses.
Yo-AI is hosted by PrivacyPortfolio, a business incorporated and registered with the California Secretary of State,
which represents consumers as their authorized agent.
The Yo-AI Platform provides you with the capability of granting
organizations the consent and authorization THEY NEED for processing your personal information,
AND ENFORCING written agreements (such as Data Processing Agreements) between parties.
Deviations from requirements agreed to in a Data Processing Agreement can be enforced by regulators with jurisdiction
or in a court of law.
(Risks of submitting late or incomplete assessments) |
(Risk of Getting A One-Star Review) |
Assess Your Risk
|
(Risk of Not Paying) |
(84 percent Risk of WHAT?) |