Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Ai Risk Governance

  • 30 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Classify AI use-case risk, draft acceptable-use policies and risk registers, prepare model cards, and map to NIST AI RMF, ISO 42001, and EU AI Act.

About

Guides AI risk management and governance including use-case risk assessment, model documentation, policies, human oversight, and framework mapping. A developer uses it when classifying AI use cases, drafting acceptable-use policies, or reviewing vendor LLMs.

  • Use-case intake table for risk tiering by data, automation, and impact
  • Maps to NIST AI RMF, ISO 42001, and EU AI Act concepts

Ai Risk Governance by the numbers

  • 30 all-time installs (skills.sh)
  • Ranked #1,493 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill ai-risk-governance

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs30
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Classify AI use-case risk, draft acceptable-use policies and risk registers, prepare model cards, and map to NIST AI RMF, ISO 42001, and EU AI Act.

Files

SKILL.mdMarkdownGitHub ↗

AI Risk & Governance

When to Use

  • Classifying AI use cases by risk tier and impact
  • Drafting AI acceptable-use policies and governance frameworks
  • Building AI risk registers with likelihood/severity/mitigation tracking
  • Preparing model cards, system cards, or DPIAs for AI deployments
  • Reviewing third-party LLM vendors (data terms, fine-tuning, safety commitments)
  • Mapping AI products to frameworks (NIST AI RMF, ISO 42001, EU AI Act concepts)
  • Aligning product and engineering teams with compliance requirements
  • Designing human-in-the-loop oversight for consequential AI decisions

When NOT to Use

  • Implementing RAG pipelines, agents, or production features → ai-engineer
  • Running jailbreak tests or adversarial campaigns → ai-redteam
  • SOC 2/ISO evidence automation and technical control mapping → compliance-engineer
  • General SOC 2 IT controls without AI scope → cybersecurity
  • Commercial/enterprise AI solution architecture → applied-ai-architect-commercial-enterprise
  • Skills portfolio governance and publish gates → ai-skill-manager

Related skills

NeedSkill
Building LLM productsai-engineer
Adversarial testingai-redteam
Research and benchmarksai-researcher
Enterprise security programcybersecurity
Pipeline and data securitydevsecops
SOC 2/ISO evidence and technical controlscompliance-engineer
AI solution architecture (commercial/enterprise)applied-ai-architect-commercial-enterprise
Agent skills governanceai-skill-manager
Safeguard gateways, classifiers, rolloutml-infrastructure-engineer-safeguards
Safety classifier research and benchmarksml-research-engineer-safeguards
Privacy research for safeguardsprivacy-research-engineer-safeguards
Enterprise security risk registers (non-AI scope)security-risk-analyst
M&A/investment cyber diligence and board packscyber-diligence-governance

Core Workflows

1. Use-case intake and classification

Capture:

FieldPurpose
Purpose and usersScope and accountability
Data typesPII, special categories, IP
Automation levelHuman-in-loop vs autonomous
Impact if wrongSafety, legal, financial, reputational
External exposureCustomer-facing vs internal

Risk tier (example):

TierCriteriaControls
LowInternal, low impact, no sensitive dataStandard policy + logging
MediumCustomer-facing or internal PIIReview + eval + monitoring
HighRegulated domain, high impact, autonomous actionsGovernance board + red-team + enhanced oversight

See `references/risk_classification.md` for EU AI Act–oriented mapping (non-legal).

2. Risk assessment

Use structured worksheet:

1. Identify hazards (bias, hallucination, leakage, misuse, dependency) 2. Estimate likelihood and severity 3. Define mitigations (technical, process, legal) 4. Assign owner and review date 5. Residual risk acceptance sign-off

See `references/risk_assessment.md` for worksheets and NIST AI RMF functions.

3. Documentation artifacts

ArtifactWhen
Model card / system cardEvery production model or vendor model
Data sheetTraining/fine-tune data described
Eval summaryPre-deploy and periodic
Incident logAI-specific harms and near-misses

See `references/documentation.md` for model card sections and change log.

4. Policy and oversight

  • Acceptable use policy (prohibited uses, approval paths)
  • Human oversight rules for consequential decisions
  • Escalation for policy violations and serious incidents
  • Training for builders and reviewers

See `references/policy_oversight.md` for governance committee cadence.

5. Vendor and third-party models

Review: data processing terms, subprocessors, retention, fine-tuning on customer data, safety commitments, breach notification, exit plan.

See `references/vendor_review.md` for vendor questionnaire topics.

When to load references

  • Tiering and regulation mappingreferences/risk_classification.md
  • Assessments and frameworksreferences/risk_assessment.md
  • Model cardsreferences/documentation.md
  • Policies and committeesreferences/policy_oversight.md
  • Vendorsreferences/vendor_review.md

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.