RisksEnterprise

How Airia evaluates, treats, and tracks AI risks across a use case — from initial identification through ongoing monitoring.

Every use case carries a Risk Profile — the container that aggregates all risks, treatments, and scores for that use case into a single composite picture of exposure and coverage.


Risk Profile Composition

A risk profile has three layers, each evolving as the use case moves through its lifecycle.

Each element reflects an analysis of the use case as a whole.


Framework risk

Risks can be mapped to a regulatory or standards framework — for example, EU AI Act, NIST AI RMF, or ISO 42001. Framework classifications each carry their own score, confidence, and rationale, and update independently from the domain risk scores.

See Frameworks for how frameworks are activated and applied to a use case.


Domain risk

Judged against each subdomain of the MIT risk taxonomy. Each applicable risk is scored for inherent and residual exposure prior to approval.

Inherent and residual scoring

Each risk carries two scores, both expressed as likelihood × impact but judged against different inputs, each with its own confidence and rationale.

ScoreJudged against
InherentThe use case's intended purpose, its known associated assets, and completed assessments — no controls factored in.
ResidualThat same original scope, re-weighted for the influence of enabled controls (for example, runtime security or attestations) in lessening likelihood or impact.

By default, Airia's governance flow reassesses the inherent score using every data point made available from Register through Assess stages, then seals it into the use case's Nutrition Label artifact. Residual is calculated during Mitigate as controls are applied, and sealed once the use case is approved, with the active controls behind it recorded in the signed Receipt artifact.

Risk treatments

Each risk gets a single treatment decision.

TypeDescriptionOutcome
AvoidEliminate the activity or use case that creates the risk entirely.Does not change the risk's residual level.
AcceptAcknowledge the risk with no action taken; document the rationale for accepting it.Does not change the risk's residual level.
TransferShift the risk to a third party such as a vendor or insurer.Does not change the risk's residual level.
MitigateApply control(s) or safeguard(s) to reduce likelihood or impact.Targets a reduced residual risk level through identifying and applying controls to the associated assets.

Risks assessed as having a Low Inherent score are automatically accepted.

Was this page helpful?

On this page