Responsible AI risk taxonomy
Proposed referential of risk categories, independent of jurisdictions. Each category becomes a group of sub-qualifications, each risk a sub-qualification rated on the scale below. The mappings link each category to control themes, hence to checks.
Rating scale
Not relevantLowModerateHighCritical
Verdict rule
Overall verdict = worst sub-qualification rating, « Critical » blocking. A « High » requires a documented mitigation.
Fairness & non-discrimination
- Training data bias
- Disparate impact on protected groups
- Proxy variables (zip code, first name)
- Representational harm (stereotypes)
- NIST
- Fair, with harmful bias managed
- OECD
- 1.2
- ISO 42001
- A.5, A.7
- AI Act
- Art. 10(2)(f)
Transparency & explainability
- Undisclosed AI interaction
- Unexplainable decision
- Insufficient documentation for the deployer
- NIST
- Accountable and transparent; Explainable and interpretable
- OECD
- 1.3
- ISO 42001
- A.8
- AI Act
- Art. 13, 50, 86
Human oversight & autonomy
- Automation bias, over-reliance
- No stop or override
- Agent autonomy: actions without approval
- Manipulation or exploitation of vulnerabilities
- NIST
- Govern 3.2, Map 3.5
- OECD
- 1.2
- ISO 42001
- A.9
- AI Act
- Art. 14, 26(2)
Reliability & robustness
- Hallucination, plausible wrong answer
- Data or model drift
- Out of distribution, edge cases
- Uneven performance across populations
- NIST
- Valid and reliable
- OECD
- 1.4
- ISO 42001
- A.6.2.4
- AI Act
- Art. 15
Security
- Prompt injection, jailbreak
- Data poisoning
- Model extraction or theft
- Agent tool abuse (MCP)
- NIST
- Secure and resilient
- OECD
- 1.4
- ISO 42001
- A.6.2.4
- AI Act
- Art. 15(5)
Privacy & data
- Personal data leakage in outputs
- Training data memorisation
- No lawful basis
- Excessive surveillance or profiling
- NIST
- Privacy-enhanced
- OECD
- 1.2
- ISO 42001
- A.7
- AI Act
- Art. 10(5), 26(9)
Safety & harmful content
- Dangerous or illegal content
- Physical harm (robotics, health)
- Dangerous capabilities (CBRN, offensive cyber)
- Drift towards a prohibited use
- NIST
- Safe
- OECD
- 1.4
- ISO 42001
- A.5.4
- AI Act
- Art. 5, 55
Accountability & governance
- No identified owner
- Shadow AI outside the inventory
- No audit trail
- NIST
- Govern 1-2
- OECD
- 1.5
- ISO 42001
- Cl. 5, A.3
- AI Act
- Art. 17, 26
Intellectual property & authenticity
- Infringement in data or outputs
- Deepfake, impersonation
- Unmarked generated content
- NIST
- GAI 600-1: Intellectual property; Information integrity
- OECD
- 1.2
- ISO 42001
- A.7.5
- AI Act
- Art. 50(2), 53(1)(c)
Societal & environmental impact
- Energy and water use
- Impact on jobs and working conditions
- Misinformation at scale
- NIST
- Measure 2.12
- OECD
- 1.1
- ISO 42001
- A.5.5
- AI Act
- Art. 27, considérant 27
Third parties & dependencies
- Dependency on a foundation model
- Vendor lock-in
- Unclear responsibilities along the chain
- NIST
- Govern 6, Manage 3
- OECD
- 1.5
- ISO 42001
- A.10
- AI Act
- Art. 25
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.