Moreover, the audit found that that PRIV’s existing processes lack adequate controls to identify which PCRs are required or recommended by DHS program documentation. An internal review conducted in 2024 revealed several incomplete PCRs, including those related to generative AI tools. This oversight gap is alarming, given the sensitivity of the data handled by these AI systems and the potential for misuse.
In addition to these structural deficiencies, the CRCL has not yet implemented a formalized process to provide ongoing oversight of AI applications within DHS. Although the CRCL has developed a draft AI Risk Assessment Framework for Civil Rights and Civil Liberties, it remains unfinalized, leaving a critical void in the governance structure. This framework is intended to guide the evaluation of AI risks, particularly concerning discrimination, bias, and the infringement of civil liberties. The absence of a finalized framework means that DHS lacks a comprehensive mechanism to safeguard against these risks.