Governance & Compliance · Software component
AI Risk Tier Classifier
Software componentGovernance & ComplianceSafety, Security & Governancearc:RiskTierClassifier
A governance component that assigns each inventoried AI system a risk category from failure impact, affected populations, applicable regulation and organizational dependence, so controls can be proportionate.
Responsibility. Categorizes inventoried AI systems into risk tiers for proportional governance.
Also known as: Risk categorization, Risk tiering
Relationships
is configured by structural
reads dependency
writes dependency
receives data from dynamic
Design guidance
- SHOULD prioritize high-risk systems for intensive management and apply proportional controls to lower-risk systems.
- SHOULD scale documentation depth with risk tier while documenting every system at least at a basic level.
Classification
- Patterns
- Categorize stage of staged NIST AI RMF implementationRisk-proportionate governance
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)Performance efficiency (ISO/IEC 25010)
- Risks mitigated
- Identical governance applied to systems with vastly different riskOverwhelmed governance capacity
- Frameworks & regulations
- NIST AI RMF: MAPEU AI Act: risk tiers (high-risk, limited-risk)
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.