Governance & Compliance · Software component
Risk Monitor
Software componentGovernance & ComplianceSafety, Security & Governancearc:RiskMonitor
A governance component that periodically re-estimates each registered risk's probability and impact from live signals such as drift and vulnerability scans, updates the register and escalates threshold crossings.
Responsibility. Keeps registered risk scores current and escalates risks that exceed their thresholds.
Also known as: Continuous risk monitoring
Relationships
is configured by structural
invokes dependency
reads dependency
writes dependency
escalates to dynamic
receives data from dynamic
sends data to dynamic
Design guidance
- SHOULD monitor probability indicators, impact indicators, control effectiveness and residual risk for each risk.
- MUST escalate when a re-computed score exceeds the risk's threshold.
Quantitative guidance
As stated by the sources; verify before use.
- Monitoring interval 3600 s (hourly); drift detected raises degradation probability from 0.3 to 0.7 (Ref9.07).
Classification
- Patterns
- Continuous risk re-assessmentKey risk indicators
- Quality attributes
- Performance efficiency (ISO/IEC 25010)Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Risk register becoming obsolete as systems and contexts change
- Frameworks & regulations
- NIST AI RMF: MANAGENIST AI RMF: MEASURE
Sources
- Ref9.07: "Risk Assessment and Management for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/07-Risk-Assessment-Management.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note