Governance & Compliance · Data artifact
Harm Risk Register
Data artifactGovernance & ComplianceSafety, Security & Governancearc:AIRiskRegister
A catalogue of identified potential harms (physical, financial, privacy, reputational, societal) scored by probability times impact severity, each with documented input, processing, output and monitoring mitigations.
Responsibility. Records assessed agent harms and their planned mitigations.
Also known as: Risk assessment, Risk heat map, Risk matrix, Risk register, Risk log, Harm Risk Register
Relationships
configures structural
is read by dependency
is written by dependency
receives data from dynamic
is audited by assurance
Design guidance
- SHOULD define safety requirements and identify potential harms at design time, before development.
- SHOULD document a mitigation strategy per risk across input, processing, output and monitoring controls.
- MUST assign an owner and status to every registered risk.
- SHOULD cover safety, performance, security, bias and fairness, privacy, regulatory and reputational risk categories.
- SHOULD record residual risk after mitigation and a review date for re-assessment.
Quantitative guidance
As stated by the sources; verify before use.
- Probability levels: rare <1%, unlikely 1-5%, possible 5-25%, likely 25-75%, almost certain >75% (Ref9.01).
- Example: model-degradation risk scored 0.60 (HIGH) reduced to residual 0.15 (MEDIUM) after drift detection, retraining, alerting and manual review (Ref9.07).
Classification
- Patterns
- Risk score = probability x impactSafety by designIdentify-assess-mitigate-monitor risk cycleResidual risk tracking
- Quality attributes
- Safety (ISO/IEC 25010 | NIST AI RMF: safe)Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Unmitigated high-impact harmsUntracked or ownerless risksResources spent on low-priority risks while critical ones are missed
- Frameworks & regulations
- NIST AI RMF: MEASURENIST AI RMF: MANAGEISO/IEC 42001 §6 PlanningISO 31000
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.
- Ref9.01: "AI Safety Frameworks for Agent Systems," unpublished reference note (01-AI-Safety-Frameworks.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.07: "Risk Assessment and Management for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/07-Risk-Assessment-Management.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note