Governance & Compliance · Data artifact
Risk Treatment Plan
Data artifactGovernance & ComplianceSafety, Security & Governancearc:RiskTreatmentPlan
A per-risk plan recording the chosen treatment (avoid, mitigate, transfer or accept), the specific technical and organizational controls, their expected probability or impact reduction, owners, timelines and target residual score.
Responsibility. Specifies how one identified risk will be treated and by whom.
Also known as: Mitigation plan, Risk response plan
Relationships
is read by dependency
receives data from dynamic
sends data to dynamic
is constrained by control
is evaluated by assurance
Design guidance
- MUST record a deliberate treatment decision for each risk rather than a default approach.
- SHOULD combine technical controls with organizational controls rather than relying on technology alone.
- SHOULD prefer elimination, then reduction, then transfer, then acceptance with close monitoring.
Quantitative guidance
As stated by the sources; verify before use.
- Example: input validation reduces probability 30%; human review gate reduces impact 50%; residual 0.04 (Ref9.07).
Classification
- Patterns
- Risk avoidanceRisk mitigationRisk transferRisk acceptanceEliminate-reduce-transfer-accept hierarchy
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Default, undeliberated risk treatment
- Frameworks & regulations
- NIST AI RMF: MANAGEISO/IEC 42001 §8 OperationISO 31000
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.
- Ref9.07: "Risk Assessment and Management for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/07-Risk-Assessment-Management.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note