Responsible AI risk taxonomy

Proposed referential of risk categories, independent of jurisdictions. Each category becomes a group of sub-qualifications, each risk a sub-qualification rated on the scale below. The mappings link each category to control themes, hence to checks.

Rating scale

Not relevantLowModerateHighCritical

Verdict rule

Overall verdict = worst sub-qualification rating, « Critical » blocking. A « High » requires a documented mitigation.

Fairness & non-discrimination

  • Training data bias
  • Disparate impact on protected groups
  • Proxy variables (zip code, first name)
  • Representational harm (stereotypes)
NIST
Fair, with harmful bias managed
OECD
1.2
ISO 42001
A.5, A.7
AI Act
Art. 10(2)(f)

Transparency & explainability

  • Undisclosed AI interaction
  • Unexplainable decision
  • Insufficient documentation for the deployer
NIST
Accountable and transparent; Explainable and interpretable
OECD
1.3
ISO 42001
A.8
AI Act
Art. 13, 50, 86

Human oversight & autonomy

  • Automation bias, over-reliance
  • No stop or override
  • Agent autonomy: actions without approval
  • Manipulation or exploitation of vulnerabilities
NIST
Govern 3.2, Map 3.5
OECD
1.2
ISO 42001
A.9
AI Act
Art. 14, 26(2)

Reliability & robustness

  • Hallucination, plausible wrong answer
  • Data or model drift
  • Out of distribution, edge cases
  • Uneven performance across populations
NIST
Valid and reliable
OECD
1.4
ISO 42001
A.6.2.4
AI Act
Art. 15

Security

  • Prompt injection, jailbreak
  • Data poisoning
  • Model extraction or theft
  • Agent tool abuse (MCP)
NIST
Secure and resilient
OECD
1.4
ISO 42001
A.6.2.4
AI Act
Art. 15(5)

Privacy & data

  • Personal data leakage in outputs
  • Training data memorisation
  • No lawful basis
  • Excessive surveillance or profiling
NIST
Privacy-enhanced
OECD
1.2
ISO 42001
A.7
AI Act
Art. 10(5), 26(9)

Safety & harmful content

  • Dangerous or illegal content
  • Physical harm (robotics, health)
  • Dangerous capabilities (CBRN, offensive cyber)
  • Drift towards a prohibited use
NIST
Safe
OECD
1.4
ISO 42001
A.5.4
AI Act
Art. 5, 55

Accountability & governance

  • No identified owner
  • Shadow AI outside the inventory
  • No audit trail
NIST
Govern 1-2
OECD
1.5
ISO 42001
Cl. 5, A.3
AI Act
Art. 17, 26

Intellectual property & authenticity

  • Infringement in data or outputs
  • Deepfake, impersonation
  • Unmarked generated content
NIST
GAI 600-1: Intellectual property; Information integrity
OECD
1.2
ISO 42001
A.7.5
AI Act
Art. 50(2), 53(1)(c)

Societal & environmental impact

  • Energy and water use
  • Impact on jobs and working conditions
  • Misinformation at scale
NIST
Measure 2.12
OECD
1.1
ISO 42001
A.5.5
AI Act
Art. 27, considérant 27

Third parties & dependencies

  • Dependency on a foundation model
  • Vendor lock-in
  • Unclear responsibilities along the chain
NIST
Govern 6, Manage 3
OECD
1.5
ISO 42001
A.10
AI Act
Art. 25

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo