AIGO — AI Governance Operating Framework
AI Risk Management
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework1. Purpose
The AIGO AI Risk Management model provides a structured, risk-based approach for identifying, assessing, treating, monitoring, and communicating risks associated with artificial intelligence. AI risk management should be integrated throughout the AI governance lifecycle rather than performed as a single assessment activity. The purpose of this document is to provide organizations with a common approach for managing AI-related risks while allowing the specific methods, tools, and assessment techniques to be adapted to organizational context.2. AI Risk Management Principles
AIGO AI risk management should be based on the following principles:- risk management should begin as early as practical;
- risk should be managed throughout the AI system lifecycle;
- risk assessment should be proportionate to potential impact;
- material risks should have clearly assigned owners;
- risk decisions should be supported by appropriate evidence;
- controls should be selected according to identified risks;
- residual risk should be explicitly considered;
- significant risks should be escalated appropriately;
- risk assessments should be updated when circumstances change; and
- risk management should support continuous improvement.
3. AI Risk Management Scope
AIGO AI risk management may apply to:- AI systems;
- AI applications;
- AI models;
- generative AI systems;
- large language model applications;
- retrieval-augmented generation systems;
- AI agents;
- agentic workflows;
- AI-enabled business processes;
- third-party AI services;
- AI APIs;
- AI infrastructure; and
- other AI-enabled capabilities.
4. AI Risk Management Context
AI risks should be assessed within the organizational context in which the AI system operates. Context may include:- organizational objectives;
- business processes;
- affected stakeholders;
- geographic environment;
- regulatory environment;
- technology environment;
- data environment;
- security environment;
- third-party dependencies;
- operational environment; and
- organizational risk tolerance.
5. AI Risk Management Lifecycle
AIGO defines the following primary AI risk management activities:- Establish Context
- Identify Risks
- Analyze Risks
- Evaluate Risks
- Treat Risks
- Approve Residual Risk
- Monitor Risks
- Communicate and Report Risks
- Review and Improve Risk Management
05-lifecycle.
6. Establishing AI Risk Context
6.1 Purpose
The organization should establish sufficient context before performing a detailed AI risk assessment.6.2 Context Information
Context may include:- intended purpose;
- intended users;
- affected stakeholders;
- system architecture;
- AI capabilities;
- data sources;
- model characteristics;
- level of autonomy;
- external dependencies;
- business criticality;
- potential impacts;
- applicable requirements; and
- existing controls.
6.3 Risk Criteria
Organizations should establish criteria for evaluating AI risks. Criteria may consider:- likelihood;
- impact;
- severity;
- duration;
- affected population;
- reversibility;
- detectability;
- uncertainty; and
- organizational risk tolerance.
7. AI Risk Identification
7.1 Purpose
AI risk identification determines what could adversely affect the organization, individuals, stakeholders, systems, or other relevant interests.7.2 Risk Sources
Risk sources may include:- technology;
- data;
- models;
- users;
- suppliers;
- processes;
- infrastructure;
- human factors;
- organizational decisions;
- malicious actors;
- environmental conditions; and
- unexpected system behavior.
7.3 Risk Identification Methods
Organizations may use:- workshops;
- structured assessments;
- interviews;
- threat modeling;
- privacy assessments;
- security assessments;
- scenario analysis;
- testing;
- historical incident analysis;
- expert review; and
- automated assessment tools.
8. AI Risk Categories
AIGO recognizes that AI risks may arise across multiple categories. Organizations may define additional categories according to their context. Core categories may include:- strategic risk;
- business risk;
- operational risk;
- technology risk;
- cybersecurity risk;
- privacy risk;
- data risk;
- model risk;
- legal and regulatory risk;
- ethical risk;
- safety risk;
- human factors risk;
- third-party risk;
- financial risk;
- reputational risk; and
- societal or stakeholder impact risk.
9. Strategic AI Risk
Strategic AI risk relates to the possibility that AI adoption or use may negatively affect organizational strategy, objectives, or long-term interests. Examples may include:- misalignment with organizational strategy;
- inappropriate AI investment;
- dependency on unsuitable technologies;
- excessive vendor dependency;
- failure to adapt to changing AI capabilities; and
- AI initiatives that do not deliver expected value.
10. Business and Operational Risk
Business and operational risks may arise when an AI system:- produces unreliable results;
- disrupts business processes;
- causes operational failures;
- creates excessive dependency;
- performs outside expected conditions;
- creates inaccurate decisions;
- reduces service quality; or
- causes unexpected business consequences.
11. Technology and Model Risk
Technology and model risk relates to failures or limitations of the technical components used by an AI system. Potential sources include:- model limitations;
- inaccurate outputs;
- model degradation;
- model drift;
- insufficient testing;
- infrastructure failure;
- integration failure;
- dependency failure;
- configuration errors; and
- unsupported technical assumptions.
12. Cybersecurity Risk
AI systems may introduce or amplify cybersecurity risks. Potential risks may include:- prompt injection;
- malicious inputs;
- unauthorized access;
- data exfiltration;
- model extraction;
- insecure integrations;
- excessive permissions;
- tool abuse;
- compromised dependencies;
- supply-chain attacks; and
- unauthorized system actions.
13. Privacy and Data Protection Risk
AI systems may create privacy and data protection risks when processing personal or otherwise protected information. Potential risks may include:- unauthorized processing;
- excessive collection;
- inappropriate retention;
- data leakage;
- inappropriate disclosure;
- re-identification;
- unauthorized secondary use;
- insufficient transparency; and
- inappropriate third-party processing.
14. Data Risk
Data-related AI risks may include:- poor data quality;
- incomplete data;
- inaccurate data;
- outdated data;
- inappropriate data sources;
- insufficient provenance;
- unauthorized data;
- data contamination;
- data leakage; and
- inappropriate data transformations.
15. Model Risk
Model risk relates to the possibility that an AI model does not perform as expected or is unsuitable for its intended use. Potential causes may include:- inappropriate model selection;
- insufficient training;
- insufficient validation;
- distribution shift;
- model drift;
- unexpected behavior;
- inaccurate predictions;
- unreliable generated content; and
- limitations that are not sufficiently understood.
16. Generative AI Risk
Generative AI systems may introduce additional risks related to generated content and probabilistic behavior. Potential risks may include:- inaccurate or misleading outputs;
- hallucination;
- harmful content;
- inappropriate content;
- prompt manipulation;
- information disclosure;
- intellectual property concerns;
- excessive user reliance;
- inconsistent outputs; and
- uncontrolled downstream use.
17. AI Agent and Agentic Risk
AI agents and agentic workflows may introduce additional risks because they can interact with tools, systems, data, and external environments. Potential risks may include:- unauthorized actions;
- excessive permissions;
- unintended tool use;
- action chaining;
- failure propagation;
- autonomous decision making;
- insufficient human oversight;
- malicious manipulation;
- unexpected system interactions; and
- inability to stop or contain actions effectively.
18. Human Factors Risk
AI systems may create risks related to human behavior, judgment, interaction, and reliance. Potential risks may include:- automation bias;
- over-reliance;
- insufficient training;
- misunderstanding of AI limitations;
- inappropriate user behavior;
- insufficient human oversight;
- decision fatigue; and
- failure to challenge AI outputs.
19. Legal and Regulatory Risk
AI systems may create legal or regulatory risks depending on their use, jurisdiction, industry, and affected stakeholders. Potential areas may include:- regulatory obligations;
- contractual requirements;
- intellectual property;
- consumer protection;
- privacy;
- employment;
- discrimination;
- product liability;
- sector-specific requirements; and
- reporting or transparency obligations.
20. Ethical and Responsible AI Risk
AI systems may create risks related to organizational values, fairness, accountability, transparency, human dignity, or other responsible AI considerations. Potential concerns may include:- unfair outcomes;
- discriminatory impacts;
- lack of transparency;
- insufficient accountability;
- inappropriate manipulation;
- harmful uses;
- inadequate human oversight; and
- negative stakeholder impacts.
21. Safety Risk
AI systems may create safety risks when their outputs, decisions, recommendations, or actions can contribute to physical, psychological, operational, or other significant harm. Safety risk assessment may consider:- potential harm;
- severity of consequences;
- likelihood of occurrence;
- system operating conditions;
- human intervention;
- failure modes;
- safeguards;
- emergency procedures; and
- ability to stop or contain the system.
22. Third-Party and Supply Chain Risk
AI systems may depend on external providers, models, APIs, datasets, infrastructure, software, or other services. Third-party risk assessment may consider:- provider reliability;
- provider security;
- provider privacy practices;
- data handling;
- model provenance;
- service availability;
- contractual obligations;
- subcontractors;
- geographic dependencies;
- service changes;
- provider concentration;
- exit options; and
- business continuity.
23. Financial Risk
AI systems may create direct or indirect financial risks. Potential sources include:- inaccurate financial decisions;
- unexpected operating costs;
- excessive infrastructure consumption;
- unauthorized transactions;
- fraud;
- business interruption;
- contractual exposure;
- regulatory penalties; and
- loss resulting from incorrect AI outputs or actions.
24. Reputational Risk
AI-related incidents or failures may negatively affect an organization’s reputation and stakeholder trust. Potential sources include:- harmful AI outputs;
- inappropriate use of AI;
- privacy incidents;
- security incidents;
- discriminatory outcomes;
- inaccurate public information;
- lack of transparency;
- failure to respond to incidents; and
- inappropriate autonomous actions.
25. Stakeholder and Societal Risk
Some AI systems may affect individuals, groups, communities, customers, employees, or society more broadly. Risk assessment may consider:- affected stakeholders;
- vulnerable populations;
- potential unequal impacts;
- access and exclusion;
- social consequences;
- public trust;
- human rights considerations; and
- unintended downstream effects.
26. Risk Analysis
Risk analysis determines the characteristics and significance of identified risks. Analysis may consider:- likelihood;
- impact;
- severity;
- exposure;
- duration;
- reversibility;
- detectability;
- uncertainty;
- existing controls; and
- dependencies.
27. Likelihood Assessment
Likelihood represents the estimated possibility that a risk event or condition may occur. Organizations may assess likelihood using categories such as:- Rare
- Unlikely
- Possible
- Likely
- Almost Certain
28. Impact Assessment
Impact represents the potential consequences if a risk materializes. Impact may be assessed across dimensions such as:- financial;
- operational;
- security;
- privacy;
- legal;
- regulatory;
- safety;
- reputational;
- individual;
- stakeholder; and
- societal impact.
- Minimal
- Minor
- Moderate
- Major
- Severe
29. Risk Rating
Organizations may combine likelihood and impact to determine an overall risk rating. A representative model may use: Risk Rating = Likelihood × Impact The actual calculation method may be adapted to the organization’s established risk methodology. Risk ratings should not replace professional judgment. Where uncertainty is significant, organizations should consider whether additional assessment or conservative treatment is appropriate.30. Inherent Risk
Inherent risk represents the level of risk before considering applicable controls or risk treatments. Organizations should identify inherent risk where this is useful for understanding:- the original risk exposure;
- control effectiveness;
- treatment requirements; and
- residual risk.
31. Control Assessment
Existing controls should be considered when analyzing AI risks. Control assessment may consider:- control existence;
- control design;
- control implementation;
- control effectiveness;
- control coverage;
- control ownership; and
- control evidence.
32. Residual Risk
Residual risk represents the remaining risk after applicable controls and treatments have been considered. Residual risk should be:- identified;
- assessed;
- documented where material;
- assigned to an appropriate owner; and
- accepted or otherwise treated according to organizational requirements.
33. Risk Appetite and Risk Tolerance
Organizations should define how much AI-related risk they are willing to accept. Risk appetite represents the broad level and type of risk the organization is willing to pursue or retain. Risk tolerance defines acceptable variation around established risk expectations or thresholds. AI governance decisions should consider organizational risk appetite and tolerance.34. Risk Evaluation
Risk evaluation compares assessed risks against established criteria to determine whether further treatment is required. Evaluation may result in a determination that a risk is:- acceptable;
- acceptable with conditions;
- requires treatment;
- requires escalation;
- requires additional assessment; or
- unacceptable.
35. Risk Treatment
Risk treatment determines how identified risks will be managed. Treatment options may include:- avoid;
- reduce;
- transfer;
- accept;
- restrict;
- monitor; or
- discontinue.
- risk severity;
- effectiveness of available controls;
- cost;
- feasibility;
- business objectives;
- legal requirements;
- stakeholder impact; and
- residual risk.
36. Risk Avoidance
Risk avoidance involves changing or eliminating the proposed activity so that the relevant risk does not arise or is materially reduced. Examples may include:- not deploying the AI system;
- removing a high-risk feature;
- restricting a use case;
- removing autonomous functionality; or
- selecting an alternative approach.
37. Risk Reduction
Risk reduction involves implementing controls or changing system design or operation to reduce likelihood, impact, or both. Risk reduction measures may include:- access controls;
- human oversight;
- validation;
- testing;
- monitoring;
- rate limits;
- output filtering;
- data controls;
- security controls;
- segregation;
- approval workflows; and
- operational restrictions.
38. Risk Transfer
Risk transfer involves allocating some risk responsibility or consequence to another party through mechanisms such as:- contractual arrangements;
- insurance;
- supplier agreements;
- service-level agreements; or
- other organizational mechanisms.
39. Risk Acceptance
Risk acceptance occurs when an authorized role determines that the remaining risk is acceptable within established organizational criteria. Acceptance should consider:- residual risk;
- risk appetite;
- risk tolerance;
- applicable requirements;
- available controls;
- business justification; and
- potential impact.
40. Risk Treatment Plans
Where treatment is required, organizations should establish a risk treatment plan. The plan may identify:- risk identifier;
- risk description;
- risk owner;
- treatment decision;
- required actions;
- responsible parties;
- target dates;
- required controls;
- residual risk; and
- approval status.
41. Risk Ownership
Each material AI risk should have an identified risk owner. The risk owner should have sufficient authority and responsibility to:- understand the risk;
- coordinate treatment;
- monitor the risk;
- escalate material changes; and
- support risk acceptance decisions.
42. Risk Escalation
AI risks should be escalated when they exceed defined authority, tolerance, or governance thresholds. Escalation may be required when:- residual risk exceeds tolerance;
- material controls are unavailable;
- risk treatment is ineffective;
- significant uncertainty exists;
- an incident occurs;
- risk characteristics materially change;
- regulatory concerns arise; or
- appropriate approval cannot be obtained.
43. Risk Monitoring
AI risks should be monitored throughout the AI system lifecycle. Monitoring may include:- risk indicators;
- control performance;
- incidents;
- system changes;
- model changes;
- data changes;
- environmental changes;
- regulatory developments;
- stakeholder feedback; and
- emerging threats.
44. Risk Triggers
Organizations should define events that trigger reassessment. Risk reassessment may be triggered by:- material system changes;
- model changes;
- data changes;
- new use cases;
- increased autonomy;
- new integrations;
- security incidents;
- privacy incidents;
- harmful outputs;
- significant performance degradation;
- new legal requirements;
- changes in organizational context; or
- significant stakeholder concerns.
45. Risk Register
Organizations should maintain an AI risk register where appropriate. A risk register may contain:- risk identifier;
- AI system;
- risk description;
- risk category;
- cause;
- consequence;
- likelihood;
- impact;
- inherent risk;
- existing controls;
- residual risk;
- treatment;
- risk owner;
- approval;
- status; and
- review date.
46. Risk Evidence
Risk management activities should produce sufficient evidence to demonstrate that risks were appropriately considered and managed. Evidence may include:- risk assessments;
- risk registers;
- treatment plans;
- control assessments;
- approval records;
- testing results;
- monitoring records;
- incident records;
- review records; and
- risk acceptance decisions.
47. Risk Communication
Material AI risks should be communicated to stakeholders who require the information to perform their responsibilities. Communication may include:- risk reports;
- management reporting;
- governance committee reporting;
- incident notifications;
- control-owner notifications;
- audit reporting; and
- regulatory or contractual reporting where required.
48. Risk Reporting
Organizations may establish regular AI risk reporting. Reporting may include:- current risk profile;
- significant risks;
- emerging risks;
- overdue treatments;
- control deficiencies;
- accepted risks;
- incidents;
- exceptions;
- changes in risk exposure; and
- trends.
49. Emerging AI Risks
Organizations should maintain awareness of emerging risks associated with changes in AI technology, threats, regulation, business use, and societal expectations. Emerging risks may include:- new attack techniques;
- new model capabilities;
- new forms of autonomous behavior;
- new data risks;
- new regulatory requirements;
- new dependency risks;
- new misuse scenarios; and
- unexpected system interactions.
50. AI Risk Review
AI risk assessments should be reviewed periodically and when significant changes occur. The review should determine whether:- identified risks remain valid;
- new risks have emerged;
- risk ratings remain appropriate;
- controls remain effective;
- treatment remains appropriate;
- residual risk remains acceptable; and
- escalation is required.
51. AI Risk Continuous Improvement
Organizations should use risk management outcomes to improve AI governance. Improvement inputs may include:- incidents;
- audit findings;
- control failures;
- assessment findings;
- stakeholder feedback;
- monitoring results;
- new threats;
- regulatory developments;
- lessons learned; and
- changes in AI capabilities.
52. Risk Traceability
AIGO risk management should support traceability between AI systems, risks, controls, evidence, and decisions. A representative relationship is: AI System → Risk → Control → Evidence → Treatment → Residual Risk → Decision Traceability should support:- accountability;
- assurance;
- auditability;
- governance reporting;
- change management; and
- continuous improvement.
53. Risk Exceptions
Organizations may establish controlled exceptions to defined risk management requirements. An exception should:- identify the requirement;
- document the reason;
- assess associated risk;
- identify compensating measures where appropriate;
- identify an authorized approver;
- define conditions; and
- establish a review or expiration date where appropriate.
54. Risk Assessment Independence
For higher-risk AI systems, organizations should consider whether risk assessment requires independent review. Independent review may be performed by:- risk functions;
- compliance functions;
- security functions;
- privacy functions;
- internal audit;
- qualified specialists; or
- other appropriately independent personnel.
55. Risk Management and AI Lifecycle
AI risk management should operate throughout the lifecycle defined in05-lifecycle.
Risk activities should occur at appropriate lifecycle stages, including:
- initiation;
- initial assessment;
- concept definition;
- classification;
- design;
- development;
- testing;
- approval;
- deployment;
- operation;
- change;
- incident management;
- periodic review; and
- retirement.
56. Risk Management and Controls
Risks should be connected to applicable controls defined within07-controls.
Organizations should be able to identify, where practical:
- which risks are addressed by each control;
- which controls address each material risk;
- who owns the controls;
- what evidence demonstrates control operation; and
- whether residual risk remains acceptable.
57. Risk Management and AI System Profiles
AI System Profiles defined in09-profiles may be used to identify common risk patterns and governance requirements for specific types of AI systems.
Profiles may identify:
- typical risks;
- relevant controls;
- assessment considerations;
- evidence requirements;
- monitoring expectations; and
- governance activities.
58. Risk Management and Maturity
Organizations may assess the maturity of their AI risk management capability. Maturity considerations may include:- defined risk methodology;
- risk ownership;
- consistent assessments;
- control integration;
- evidence;
- monitoring;
- reporting;
- independent assurance; and
- continuous improvement.
59. Risk Management Documentation
Organizations should maintain documentation appropriate to the AI system’s risk and governance requirements. Documentation may include:- risk methodology;
- risk criteria;
- risk assessments;
- risk registers;
- treatment plans;
- control assessments;
- acceptance records;
- escalation records;
- monitoring records;
- review records; and
- risk reports.
60. Risk Management Completion
AI risk management should continue for as long as material AI-related risks remain within the organization’s governance scope. Risk management should be updated when the AI system:- changes;
- enters a new lifecycle stage;
- experiences an incident;
- changes operating context;
- introduces new capabilities;
- receives new data;
- gains additional autonomy; or
- is retired.
61. Document Status
Document: AIGO AI Risk Management Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Type: AI Risk Management Identifier Prefix:AIGO-RSK
This document defines the foundational AI risk management model for the AIGO framework.
Organizations may adapt the model according to their organizational structure, AI systems, risk profile, regulatory environment, and governance maturity while maintaining appropriate accountability, risk assessment, treatment, monitoring, evidence, and assurance.