
Ai Risk Governance
- 30 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Classify AI use-case risk, draft acceptable-use policies and risk registers, prepare model cards, and map to NIST AI RMF, ISO 42001, and EU AI Act.
About
Guides AI risk management and governance including use-case risk assessment, model documentation, policies, human oversight, and framework mapping. A developer uses it when classifying AI use cases, drafting acceptable-use policies, or reviewing vendor LLMs.
- Use-case intake table for risk tiering by data, automation, and impact
- Maps to NIST AI RMF, ISO 42001, and EU AI Act concepts
Ai Risk Governance by the numbers
- 30 all-time installs (skills.sh)
- Ranked #1,493 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill ai-risk-governanceAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 30 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Classify AI use-case risk, draft acceptable-use policies and risk registers, prepare model cards, and map to NIST AI RMF, ISO 42001, and EU AI Act.
Files
AI Risk & Governance
When to Use
- Classifying AI use cases by risk tier and impact
- Drafting AI acceptable-use policies and governance frameworks
- Building AI risk registers with likelihood/severity/mitigation tracking
- Preparing model cards, system cards, or DPIAs for AI deployments
- Reviewing third-party LLM vendors (data terms, fine-tuning, safety commitments)
- Mapping AI products to frameworks (NIST AI RMF, ISO 42001, EU AI Act concepts)
- Aligning product and engineering teams with compliance requirements
- Designing human-in-the-loop oversight for consequential AI decisions
When NOT to Use
- Implementing RAG pipelines, agents, or production features →
ai-engineer - Running jailbreak tests or adversarial campaigns →
ai-redteam - SOC 2/ISO evidence automation and technical control mapping →
compliance-engineer - General SOC 2 IT controls without AI scope →
cybersecurity - Commercial/enterprise AI solution architecture →
applied-ai-architect-commercial-enterprise - Skills portfolio governance and publish gates →
ai-skill-manager
Related skills
| Need | Skill |
|---|---|
| Building LLM products | ai-engineer |
| Adversarial testing | ai-redteam |
| Research and benchmarks | ai-researcher |
| Enterprise security program | cybersecurity |
| Pipeline and data security | devsecops |
| SOC 2/ISO evidence and technical controls | compliance-engineer |
| AI solution architecture (commercial/enterprise) | applied-ai-architect-commercial-enterprise |
| Agent skills governance | ai-skill-manager |
| Safeguard gateways, classifiers, rollout | ml-infrastructure-engineer-safeguards |
| Safety classifier research and benchmarks | ml-research-engineer-safeguards |
| Privacy research for safeguards | privacy-research-engineer-safeguards |
| Enterprise security risk registers (non-AI scope) | security-risk-analyst |
| M&A/investment cyber diligence and board packs | cyber-diligence-governance |
Core Workflows
1. Use-case intake and classification
Capture:
| Field | Purpose |
|---|---|
| Purpose and users | Scope and accountability |
| Data types | PII, special categories, IP |
| Automation level | Human-in-loop vs autonomous |
| Impact if wrong | Safety, legal, financial, reputational |
| External exposure | Customer-facing vs internal |
Risk tier (example):
| Tier | Criteria | Controls |
|---|---|---|
| Low | Internal, low impact, no sensitive data | Standard policy + logging |
| Medium | Customer-facing or internal PII | Review + eval + monitoring |
| High | Regulated domain, high impact, autonomous actions | Governance board + red-team + enhanced oversight |
See `references/risk_classification.md` for EU AI Act–oriented mapping (non-legal).
2. Risk assessment
Use structured worksheet:
1. Identify hazards (bias, hallucination, leakage, misuse, dependency) 2. Estimate likelihood and severity 3. Define mitigations (technical, process, legal) 4. Assign owner and review date 5. Residual risk acceptance sign-off
See `references/risk_assessment.md` for worksheets and NIST AI RMF functions.
3. Documentation artifacts
| Artifact | When |
|---|---|
| Model card / system card | Every production model or vendor model |
| Data sheet | Training/fine-tune data described |
| Eval summary | Pre-deploy and periodic |
| Incident log | AI-specific harms and near-misses |
See `references/documentation.md` for model card sections and change log.
4. Policy and oversight
- Acceptable use policy (prohibited uses, approval paths)
- Human oversight rules for consequential decisions
- Escalation for policy violations and serious incidents
- Training for builders and reviewers
See `references/policy_oversight.md` for governance committee cadence.
5. Vendor and third-party models
Review: data processing terms, subprocessors, retention, fine-tuning on customer data, safety commitments, breach notification, exit plan.
See `references/vendor_review.md` for vendor questionnaire topics.
When to load references
- Tiering and regulation mapping →
references/risk_classification.md - Assessments and frameworks →
references/risk_assessment.md - Model cards →
references/documentation.md - Policies and committees →
references/policy_oversight.md - Vendors →
references/vendor_review.md
Documentation
Table of contents
1. Model card sections 2. Change log
Model card sections
- Intended use and out-of-scope uses
- Training/fine-tune data summary
- Evaluation results and limitations
- Ethical considerations and biases observed
- Environmental impact (optional)
Change log
Track: model version, prompt version, retrieval index version, deploy date, approver.
Policy and oversight
Table of contents
1. AUP topics 2. Committee cadence
AUP topics
- Prohibited uses (e.g., covert surveillance, illegal content)
- Required human review domains
- Data handling and retention
- Third-party model restrictions
Committee cadence
| Meeting | Purpose |
|---|---|
| Monthly | Tier-2 launches, metrics |
| Ad hoc | High-risk approvals |
| Quarterly | Policy refresh, incident themes |
Risk assessment
Table of contents
1. Worksheet 2. NIST AI RMF mapping
Worksheet
| Hazard | Likelihood | Severity | Mitigation | Residual | Owner |
Review quarterly or on material change.
NIST AI RMF mapping
| Function | Activities |
|---|---|
| Govern | Policies, roles, culture |
| Map | Context, categorization |
| Measure | Eval, tracking |
| Manage | Prioritize, respond |
Risk classification
Table of contents
1. Tiering factors 2. EU AI Act orientation
Tiering factors
Score each 1–3: impact, autonomy, data sensitivity, scale, reversibility.
Sum → Low / Medium / High governance path.
EU AI Act orientation
Not legal advice. Map use case to:
- Prohibited practices checklist (reject early)
- High-risk annex domains (enhanced documentation)
- GPAI provider vs deployer obligations for third-party models
Escalate ambiguous cases to legal/compliance.
Vendor review
Table of contents
1. Questionnaire topics 2. Exit plan
Questionnaire topics
- Subprocessors and data residency
- Training on customer data (opt-in/out)
- Retention and deletion SLAs
- Safety evaluations and incident history
- API logging and enterprise controls (SSO, SCIM)
Exit plan
Alternative model/provider, data export, contract termination assistance.