Score
Constructing mapping tables and taxonomic crosswalks that translate items (e.g., risks, measures) between frameworks so external users and auditors can interpret and use them. This includes mapping state‑level findings to an established risk taxonomy and aligning that taxonomy with external standards and practical audit workflows.
Rapid deployment of AI systems in regulated domains exposes a critical gap between technical security and legal compliance, as algorithmic vulnerabilities (e.g., those cataloged in MITRE ATLAS) lack systematic mapping to quantifiable financial impacts—undermining evidence-based decisions on contingency reserves and cyber-insurance pricing. Method: We propose the first cross-domain AI threat vector classification framework that directly links technical threats to five business loss dimensions: confidentiality, integrity, availability, legal liability, and reputational harm. Leveraging structured ontology modeling, we integrate MITRE ATLAS, the EU AI Act, NIST AI Risk Management Framework, and ISO/IEC 42001 to define 53 actionable sub-threats. Contribution/Results: The framework achieves 100% coverage across 133 real-world AI incidents reported in 2025, demonstrating both conceptual completeness and audit readiness for regulatory and economic risk assessment.
The EU’s digital elections face regulatory challenges in monitoring political content, as existing analytical methods fail to meet compliance requirements under new legislation such as the Digital Services Act (DSA). Method: This study develops the first multidimensional classification framework for political content compliance aligned with EU regulatory standards. Integrating legal doctrinal analysis with empirical content analysis, it designs a structured coding manual and establishes a cross-platform annotation and classification framework for user-generated content and political advertisements. Contribution/Results: The framework yields a reusable, scalable, and auditable compliance assessment tool supporting standardized oversight by both regulators and platforms. Its core innovation lies in achieving the first technical alignment between legal norms and content analysis—thereby filling a critical methodological gap in the quantitative evaluation of political content compliance in digital elections.
Rapid advances in generative AI have exposed interoperability limitations in existing AI risk classification frameworks, hindering cross-stakeholder governance collaboration. To address this, we propose the first ontology-driven unified AI risk taxonomy, enabling semantic alignment of heterogeneous risk definitions, evaluation benchmarks, datasets, and mitigation strategies via a structured knowledge graph. Our approach integrates formal ontology modeling, AI-assisted compliance workflows, and an open-source toolchain—Risk Atlas Nexus—to automate risk identification, prioritization, and policy implementation. Key contributions include: (1) a standardized cross-framework risk mapping protocol; (2) a scalable, verifiable governance knowledge infrastructure grounded in formal semantics; and (3) a substantial reduction in the operational barrier to AI governance, empowering researchers, practitioners, and policymakers to collaboratively mitigate emerging generative AI risks and advance responsible AI at scale.
This study addresses the challenges of extracting structured risk factors from corporate 10-K filings, particularly inconsistencies with predefined hierarchical taxonomies and the absence of continuous optimization mechanisms. The authors propose an end-to-end, three-stage framework: first, a large language model (LLM) extracts risk factors with source citations; second, semantic embeddings map these factors to a taxonomy; and third, an LLM-as-a-judge mechanism filters erroneous matches. Additionally, an AI agent is introduced to autonomously diagnose and iteratively refine the taxonomy. Experiments on S&P 500 company filings demonstrate a 63% increase in within-industry risk similarity (Cohen’s d = 1.06, AUC = 0.82) and a 104.7% improvement in embedding separation between categories, confirming the method’s effectiveness and generalizability.
This study addresses the gap between conceptual AI risk frameworks and actionable auditing methodologies by proposing the first end-to-end operationalizable framework. It decouples risk definitions into their manifestation mechanisms and introduces Eticas AI Risk Taxonomy v2.0.0—an open, extensible classification system comprising 76 subcategories—demonstrating a complete pipeline from risk definition through executable testing, quantitative scoring, to risk tiering, exemplified by PII leakage risks. The taxonomy is published under CC BY 4.0 using SKOS/JSON-LD semantic standards, providing stable URIs, calibrated thresholds, and mappings to 18 external frameworks. Empirical evaluation on GPT-4-0314 reveals PII disclosure rates rising to 84% under adversarial prompting, leading to its classification as an E-level systemic risk, thereby validating the framework’s effectiveness and practical utility.
Software traceability faces practical bottlenecks including inconsistent link granularity, heterogeneous data structures across artifacts, and ambiguous responsibility assignment. To address these, we propose Taxonomic Trace Links (TTL), a paradigm shift from direct link construction to semantic alignment via lightweight domain taxonomies—reframing traceability as “taxonomy-enabled collaboration” rather than “link maintenance.” Our method comprises domain modeling, taxonomy design, semantic mapping of artifacts to taxonomy concepts, and empirical validation. We preliminarily validate TTL using existing taxonomies, identify six critical implementation challenges, and propose a systematic technology evolution roadmap and evaluation framework. TTL is the first approach to treat domain taxonomies as foundational infrastructure for traceability, significantly reducing manual effort and tool dependency. It offers a scalable, industry-ready paradigm for operationalizing traceability in complex software engineering contexts.
This study addresses the challenges of traceability in software engineering—stemming from fine-grained artifacts, heterogeneity of work products, and ambiguous responsibilities—by proposing Taxonomic Trace Links (TTL) as a complementary mechanism to traditional trace links. TTL leverages domain ontologies and taxonomies, integrated with automated classifiers, to establish early and structured traceability relationships among requirements, business use cases, and test cases. Empirical validation in an industrial case study at Ericsson demonstrates that TTL effectively supports traceability in real-world settings; however, its deployment is constrained by limitations in classifier accuracy and the complexity of ontology construction. The feasibility and applicability boundaries of TTL are rigorously assessed through a mixed-methods approach combining quantitative link evaluation with qualitative feedback from focus groups.
To address the fidelity loss, provenance gaps, and service instability of the original OxO ontology mapping system, we designed and implemented OxO2. Methodologically, we first deeply integrated the SSSOM standard into the ontology mapping browser; proposed sound mapping generation conditions and verification mechanisms based on Nemo Datalog; and established a provenance-driven, trustworthy mapping management paradigm—unifying provenance modeling, incremental reasoning, and memory-aware optimization. Contributions include: achieving zero timeouts and zero crashes across all requests, markedly enhancing service robustness; and enabling auditable, reproducible, and high-confidence cross-ontology mapping discovery and browsing. OxO2 thus provides a logically consistent, source-traceable infrastructure for integrating heterogeneous biomedical data.
This work addresses the challenge of large language models generating row-level data in cross-Wiki table construction without verifiable source support. To mitigate this issue, the authors propose the first auditable framework that enforces separation of write permissions between curators and auditors, introduces a row-level source citation gating mechanism, and defines a comprehensive set of 12 audit categories spanning coverage keys, schema alignment, and source roles. This design ensures that every generated table row is explicitly grounded in and traceable to credible sources. Experimental evaluation on a benchmark of 51 instances demonstrates substantial improvements: source-front precision increases by 42% (from 0.356 to 0.505) and F1 score rises by 35% (from 0.334 to 0.451), significantly enhancing both source accuracy and overall auditability.
This study addresses critical challenges faced by regulated enterprises—including cross-system data inconsistencies, reconciliation difficulties, asset record drift, and overreliance on manual audits—by proposing the GERA framework. GERA innovatively integrates deterministic reconciliation, robust anomaly detection based on Z-Score and its variants, governance-driven semantic standardization, and NIST CSF 2.0 security controls within a four-layer architecture comprising ingestion, staging, core modeling, and semantic services. Empirical validation across banking, broadband service providers, and technology firms demonstrates that the framework significantly enhances reconciliation automation and audit readiness, effectively mitigating 39% of compliance deficiencies identified during PCAOB inspections.
This study addresses a critical gap between compliance and effectiveness in current auditing standards—such as ASB 018—whose reliance on ambiguous language and undefined terminology obscures the potential risks associated with the use of probabilistic genotyping software in criminal justice. Through a qualitative content analysis comparing the standard’s text with five real-world audit reports, this work demonstrates for the first time that audits deemed compliant often fail to delineate the boundaries of software application. The research attributes this disconnect to structural deficiencies in the standard itself and offers concrete recommendations for revising auditing frameworks and evaluating their practical efficacy. These contributions provide both theoretical insight and actionable guidance for enhancing the governance of forensic technologies within the justice system.
Official statistics often exhibit complex structures across geographic and subpopulation dimensions that traditional tabular formats struggle to convey effectively, thereby hindering policymakers’ comprehension and application. This study introduces linked micromaps as a visualization framework that systematically integrates descriptive statistics, multivariate relationships, ranking structures, and spatiotemporal heterogeneity to enable intuitive exploration of high-dimensional official data. The approach substantially enhances the interpretability and readability of statistical information, uncovering latent patterns while also offering new avenues for subsequent modeling and uncertainty quantification. By doing so, it expands the potential of linked micromaps in public policy analysis and social science research.
This work addresses the incompleteness of query results in decentralized knowledge graph querying caused by lexical heterogeneity. It proposes a method that dynamically discovers and applies local schema alignment rules during link-traversal query processing (LTQP), without requiring prior centralized alignment or altering the original traversal behavior. This approach enables, for the first time, runtime online schema alignment through scoped, on-demand semantic mappings, significantly improving query completeness. Implemented within the Comunica framework, the system integrates a web interface, command-line tools, and a reusable library. Its effectiveness is demonstrated in a decentralized social media scenario, where it recovers complete results with low overhead, establishing a practical foundation for Web-scale distributed LTQP.