Governance & Compliance · Data artifact

Risk Treatment Plan

Data artifactGovernance & ComplianceSafety, Security & Governancearc:RiskTreatmentPlan

A per-risk plan recording the chosen treatment (avoid, mitigate, transfer or accept), the specific technical and organizational controls, their expected probability or impact reduction, owners, timelines and target residual score.

Responsibility. Specifies how one identified risk will be treated and by whom.

Also known as: Mitigation plan, Risk response plan

is evaluated bysends data tois read byreceives data fromis constrained byOversight Governance Committee: is evaluated byOversight Governance Com…Harm Risk Register: sends data toHarm Risk RegisterRemediation Tracker: is read byRemediation TrackerAI Control Catalog: receives data fromAI Control CatalogRisk Tolerance Policy: is constrained byRisk Tolerance Policy
Direct neighbourhood (hover for relationship types)

Relationships

is read by dependency

receives data from dynamic

sends data to dynamic

is constrained by control

is evaluated by assurance

Design guidance

Quantitative guidance

As stated by the sources; verify before use.

Classification

Patterns
Risk avoidanceRisk mitigationRisk transferRisk acceptanceEliminate-reduce-transfer-accept hierarchy
Quality attributes
Transparency and accountability (NIST AI RMF: accountable and transparent)
Risks mitigated
Default, undeliberated risk treatment
Frameworks & regulations
NIST AI RMF: MANAGEISO/IEC 42001 §8 OperationISO 31000

Sources

  1. Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.
  2. Ref9.07: "Risk Assessment and Management for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/07-Risk-Assessment-Management.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note