AI Risk Domains
AI Risk Domains for Regulated AI Systems
Classify AI risks, identify evidence gaps, and map each risk to controls, owners, escalation paths, vendor responsibilities, human review, and reviewable records.
AI Risk Register View
Evidence Gap ScanThe risk question
AI risk is an evidence problem.
The central AI risk question is not only whether a model performs well. In regulated environments, the question is whether the organization can reconstruct how the system was governed, reviewed, escalated, controlled, and evidenced.
Risk taxonomy
AI Risk Domain Matrix
This matrix separates AI risk domains from the evidence needed to govern them. The goal is not generic risk awareness. The goal is control mapping, ownership, escalation, and reviewable documentation.
| Risk Domain | What Can Go Wrong | Control Implication | Evidence Needed |
|---|---|---|---|
|
Vendor Vendor AI Risk |
Vendor claims cannot be verified, model limitations are unclear, shared responsibility is vague, or change notices are incomplete. | Require documentation, testing evidence, contractual controls, audit rights, monitoring, change notice, incident terms, and periodic review. | Vendor questionnaire, SOC report, model documentation, testing summary, issue log, change record, contract checklist. |
|
Oversight Human Oversight Risk |
Human review exists on paper but reviewers lack authority, context, escalation paths, override ability, or decision records. | Define reviewer authority, escalation triggers, override conditions, review evidence, and decision documentation standards. | Reviewer notes, decision rationale, escalation log, override record, approval trail, human oversight checklist. |
|
Financial Crimes AML / Financial-Crime AI |
Alerts lack explainability, escalation logic is inconsistent, or reviewer disposition cannot be reconstructed. | Require reviewable rationale, case handling standards, escalation rules, quality review, exception records, and retained evidence. | Alert disposition, case notes, escalation rationale, quality review, exception record, audit trail. |
|
LLM LLM / RAG Risk |
Outputs fabricate, leak data, retrieve unsupported content, bypass access boundaries, or create unreviewed advice. | Apply access controls, retrieval testing, prompt/output monitoring, human review, logging, incident handling, and content boundaries. | Prompt logs, retrieval tests, access review, output review notes, red-team notes, incident record. |
|
Model Risk Model Risk Support |
Limitations, monitoring, assumptions, performance changes, validation dependencies, or change approvals are not documented. | Prepare validation-readiness artifacts, monitoring records, limitation registers, issue tracking, approvals, and change evidence. | Limitation register, monitoring summary, issue log, test evidence, approval record, change review notes. |
|
Data Data and Input Risk |
Data lineage, quality, permission, sensitivity, access, retention, or drift is not controlled or documented. | Map data governance controls to AI use, access boundaries, lineage, retention, sensitivity, and quality checks. | Data lineage record, access review, quality checks, sensitivity review, retention evidence, drift monitoring. |
Vendor AI Risk
Dedicated page for third-party AI documentation, vendor opacity, contract risk, shared responsibility, and evidence requests.
Open Vendor AI RiskHuman Oversight
Dedicated page for reviewer authority, rationale, escalation, overrides, intervention records, and oversight evidence.
Open Human OversightEvidence Library
Registers, checklists, questionnaires, crosswalks, and prototype files for AI assurance evidence mapping.
Open Evidence LibraryEvidence gap severity
Risk Signals
InfoSecured.ai treats weak evidence as a risk signal. A control that cannot be evidenced is not ready for audit, governance review, or serious challenge.
- Policy exists and is mapped to the AI use case.
- Control owner is assigned.
- Review records are retained.
- Escalation path is documented.
- Control exists but review records are incomplete.
- Vendor documentation is partial.
- Human review criteria are unclear.
- Exceptions are tracked inconsistently.
- No accountable owner is assigned.
- No retained evidence proves the control operated.
- Human review cannot be reconstructed.
- Vendor claims cannot be verified.
Control mapping logic
From risk to evidence.
Practical artifact
AI Risk Register Starter Kit
A template set for documenting AI risk in a way that supports governance review, vendor diligence, control mapping, human oversight, and audit-readiness.
- AI Use Case Inventory
- Risk Domain Taxonomy
- Risk-to-Control Map
- Control Owner Register
- Human Oversight Checklist
- Vendor AI Risk Questionnaire
- Evidence Register Fields
- Escalation and Exception Log
- Model Change Review Notes
- Audit-Readiness Gap List
Prototype proof-of-work
GridLock GRC Connection
GridLock GRC is the prototype layer that turns this risk taxonomy into structured evidence: use case, risk domain, failure mode, control, owner, evidence artifact, exception, remediation, and review status.
The purpose is to make AI risk reviewable. Broad AI risk language becomes a traceable register that can be inspected, challenged, improved, and mapped to governance workflows.
GridLock GRC is not production software, a certified compliance platform, legal guidance, formal audit guidance, or a model-validation system. It is a public proof-of-work project for AI assurance evidence mapping.
Use notice
Independent research and portfolio artifacts.
InfoSecured.ai publishes independent AI assurance research, templates, and public proof-of-work artifacts for education, review, adaptation, and validation by qualified internal teams.
Materials are not legal advice, audit advice, certification advice, regulatory advice, model-validation advice, or a substitute for organization-specific professional review.
Build an AI risk register that produces evidence.
Map AI risks into controls, owners, evidence records, vendor documentation, human oversight notes, exceptions, and audit-ready review status.