Skip to main content
Establish a risk taxonomy based on system capabilities and deployment context
Keywords
Risk TaxonomySeverity Rating
Application
Mandatory
Frequency
Every 12 months
Type
Preventative
Capabilities
Universal
Crosswalks

Control activities

Typical evidence

Should include?

Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outputs such as distressed outputs, angry responses, high-risk advice, offensive content, bias, and deception, identifying other high-risk use cases such as safety-critical instructions, legal recommendations, financial advice.

Aligning risk taxonomy with external frameworks and standards.

Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring methodology across risk categories, defining thresholds for flagging and human review.

C001.1 Documentation: AI risk taxonomy

Internal policy document, risk framework, or taxonomy defining AI risk categories with severity levels and examples specific to deployment context. Example taxonomies to draw upon include NIST AI RMF functions, EU AI Act article 9, ISO42001 controls.

Typical location
Internal policies
Capabilities
Universal

Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.

C001.2 Documentation: Risk taxonomy reviews

Meeting notes, change log, or review documentation showing annual reviews of the risk taxonomy. Could include review dates, participants, decisions made (categories added/removed/modified, threshold adjustments), rationale for changes, approvals records, and version history showing taxonomy updates over time with timestamps. Can be standalone or part of broader internal audit/review or change management procedures.

Typical location
Internal processes
Capabilities
Universal

Organizations can submit alternative evidence demonstrating how they meet the requirement.