The most commonly reported RAIM activities involved risk assessment (evaluating regulatory risk, identifying harms to stakeholders), the building of a RAIM management structure (responsible official, RAIM committee), and the adoption of substantive RAIM standards (AI ethics principles, RAIM policies). Respondents were much less likely to train employees in RAIM, and to evaluate their employees’ or their organization’s RAIM performance.