Governance & Compliance · Software component

AI Risk Tier Classifier

Software componentGovernance & ComplianceSafety, Security & Governancearc:RiskTierClassifier

A governance component that assigns each inventoried AI system a risk category from failure impact, affected populations, applicable regulation and organizational dependence, so controls can be proportionate.

Responsibility. Categorizes inventoried AI systems into risk tiers for proportional governance.

Also known as: Risk categorization, Risk tiering

reads; writesreceives data fromis configured byAI Use Inventory: reads; writesAI Use InventoryAI System Context Record: receives data fromAI System Context RecordRisk Tiering Criteria: is configured byRisk Tiering Criteria
Direct neighbourhood (hover for relationship types)

Relationships

is configured by structural

reads dependency

writes dependency

receives data from dynamic

Design guidance

Classification

Patterns
Categorize stage of staged NIST AI RMF implementationRisk-proportionate governance
Quality attributes
Transparency and accountability (NIST AI RMF: accountable and transparent)Performance efficiency (ISO/IEC 25010)
Risks mitigated
Identical governance applied to systems with vastly different riskOverwhelmed governance capacity
Frameworks & regulations
NIST AI RMF: MAPEU AI Act: risk tiers (high-risk, limited-risk)

Sources

  1. Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.