Score
Designs, implements, and evaluates processes, metrics, controls, and governance to identify, assess, prioritize, mitigate, monitor, and report potential harms, losses, or uncertainties to an organization or project; builds risk registers, tolerance thresholds, response plans, and ongoing monitoring to ensure mitigations are effective and residual risk is acceptable.
This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.
This study addresses the challenge of effectively monitoring early-stage agent systems, where structural flaws often obscure task-level errors. The authors propose a three-dimensional (quality, suitability, efficiency) and three-granularity (intra-run, inter-run, structural) monitoring and triaging framework tailored for low-maturity agent systems. They introduce a novel system maturity staging model based on the coefficient of variation and monitoring granularity, integrated with a severity classification adapted from FMEA to guide human review. The resulting transferable monitoring architecture supports document-driven, multi-stage workflows, enhanced by a synthetic testbed with controlled error injection. Experimental results demonstrate that structural defects significantly mask task-level signals; 97% of issues can be automatically traced, with only 2% requiring human intervention, and each granularity level precisely identifies its corresponding defect type (coefficients of variation: 0.02, 1.25, and 0.00, respectively).
This paper addresses the conceptual conflation of “oversight” and “control” in AI safety governance, systematically distinguishing their distinct objectives, operational mechanisms, and temporal scopes. Through a critical cross-disciplinary literature review—and integrating insights from Responsible AI maturity models and risk governance theory—it develops a theoretically rigorous yet policy-actionable analytical framework, introducing the first AI Oversight Maturity Model (AI-OMM). The model identifies critical boundary conditions for oversight failure and establishes a structured, conditional system for assessing the feasibility of meaningful human oversight. Key contributions include: (1) clarifying the normative distinction between oversight and control; (2) diagnosing design gaps and contextual limitations in current oversight mechanisms; and (3) providing regulators, auditors, and developers with a practical tool to evaluate oversight effectiveness, detect capability gaps, and guide technical alignment with governance requirements.
Current AI incident governance frameworks lack consistency in defining, categorizing, monitoring, and reporting incidents, which constrains the depth and accuracy of post-deployment failure analysis. This study addresses this gap through a systematic literature review and comparative analysis across multiple governance frameworks, thereby identifying and synthesizing key inconsistencies that span existing mechanisms. The work reveals systemic deficiencies in data collection practices, classification logics, and analytical rigor, and elucidates critical misalignments among core governance components. By clarifying these structural disconnects, the research establishes a theoretical foundation and proposes a coordinated pathway toward a unified, standardized framework for AI incident governance.
In early-stage collaborative robot task design, safety experts struggle to comprehend task logic, and risk assessment outcomes often lack practical implementability. Method: This paper proposes a model-driven risk assessment approach based on Behavior Trees (BTs)—the first application of BTs in risk assessment—enabling early risk identification, formal verification, and end-to-end traceability via visual modeling. Integrating Model-Driven Engineering (MDE) with Human Factors evaluation, the method was empirically validated by cross-functional practitioners from five industrial enterprises. Contribution/Results: The approach significantly improves risk identification completeness (+32%) and enhances collaboration efficiency between safety experts and development teams, reducing communication overhead by 41%. It establishes a novel, industrial-grade paradigm for trustworthy robotic systems that unifies modeling, analysis, and implementation within a single coherent framework.
This study addresses the limitations of traditional risk matrices in supporting fine-grained, context-sensitive risk decision-making within complex dynamic systems. The authors propose a traceable, three-stage risk analysis framework: first, employing a multidimensional polar-coordinate heatmap to enable context-aware risk prioritization; second, constructing Bowtie causal barrier models for high-priority risks; and third, automatically transforming these Bowtie models into Bayesian networks to facilitate dynamic inference and “what-if” scenario analysis. A key innovation lies in explicitly modeling barriers as activated nodes, thereby establishing an integrated pathway from macro-level risk screening to micro-level intervention. Validation in a real-time payment gateway setting demonstrates that the proposed approach significantly enhances the transparency, auditability, and operational readiness of risk analysis.
Leading AI enterprises lack internal audit mechanisms calibrated to catastrophic and systemic risks. Method: This paper introduces the first four-dimensional integrated framework that tightly couples the Institute of Internal Auditors (IIA) standards with AI safety governance—systematically defining audit scope, resource models, execution frequency, and sensitive information access protocols. It synthesizes risk-based assurance theory, AI governance literature, and real-world operational case studies. Contribution/Results: The framework establishes, for the first time, organizational safety trade-off boundaries, thereby addressing a critical gap in endogenous risk assurance. It delivers an actionable internal audit capability roadmap, enabling boards and regulators to obtain high-confidence, system-level evidence for risk control. By embedding audit rigor into AI safety governance, the framework strengthens the safety governance feedback loop and advances institutional accountability in high-stakes AI development.
This study addresses the complex assurance challenges confronting AI-enabled Cyber-Physical Systems (AI-CPS) across perception, computation, control, human factors, and governance dimensions, noting that mere compliance with ISO/IEC 42001 fails to reveal architectural impacts or practical maturity. The authors propose CEDAR-42001, a two-stage method that uniquely maps compliance audit evidence onto a seven-layer AI-CPS architecture and governance hierarchy. By integrating a five-dimensional maturity profile, constraint identification, and rule-driven reasoning, the approach generates a traceable, architecture-aware assurance posture. Applied to an autonomous vehicle fleet case, it revealed that while 89.9% of audit items were compliant, only 34.3% met a high-assurance baseline. The method successfully reconstructed the 2023 Cruise incident, precisely identifying cross-layer deficiencies and recommending targeted mitigations to inform decision-making from strategic to operational levels.
This study addresses the challenge of managing residual risks that cannot be fully eliminated, noting that existing qualitative analyses lack actionable dynamic management mechanisms. To bridge this gap, the authors propose formalizing the Bowtie risk diagram as a directed acyclic graph (DAG) capable of supporting Bayesian inference and causal intervention. By incorporating safety-state semantics and explicit intervention nodes, and integrating expert probability assessments with do-calculus, the framework enables risks to be observable, quantifiable, and intervenable. The work introduces Realtime Risk Studio—a modeling tool—and Probability Capture—a method for eliciting probabilistic judgments—to construct, for the first time, an executable real-time risk reasoning model. Validation in an instant payment gateway scenario demonstrates the efficacy of transforming Bowtie diagrams into DAGs, fusing noisy expert probabilities, and performing “What-if” causal intervention analyses.
This study addresses the multidimensional risks—operational, security, and governance-related—that enterprises face when deploying large language models, noting that existing open-source tools are fragmented and fail to comprehensively cover authoritative risk taxonomies. To bridge this gap, the work proposes a structured mapping protocol that automatically aligns the capabilities of 21 prominent open-source tools with the 32 subcategories of the MIT AI Risk Framework, leveraging retrieval-augmented generation (RAG) and LLM-based parsing. The protocol’s validity is substantiated through source code and documentation analysis, majority voting, and inter-rater reliability assessment using Fleiss’ Kappa (κ = 0.509, F1 = 75.5%). Findings reveal a pronounced overconcentration of current tools on technical controls, with significant gaps in governance, legal, and market risk domains, thereby providing an empirical foundation for developing layered AI risk mitigation architectures.