← Back to catalogue
Published

AI Safety / Governance Assessment

vr.wm-ai-008 · wm-ai-008-ai-safety-governance-assessment

Provide the format-neutral context an agent needs to create, inspect and operate a governance or safety assessment record for a specific AI system: what was assessed, under which obligation regime, against which risks and safeguards, on what evidence, with what residual risk, and what was decided by whom.

World Models Information and virtual systems INF.AI.GOV

Bundle → Layer → Finding → Questions Filled

6 bundles · 13 layers · 28 findings · 112 questions

Assessment Frame What is being assessed, in which context, and what this particular assessment record is.

Subject and Context

Binding to the assessed AI system version and the declared purpose, context and classification profile.

Assessed subject binding

The identity of the exact AI system, model version, configuration and component boundary that this assessment judges. The binding must be reproducible so that a later reader can tell whether a given deployed artefact is covered.

  1. Which exact AI system, model version and deployment configuration does this assessment bind to? identity
  2. Which components, upstream models and third-party services fall inside the assessed system boundary? composition
  3. Which system of record issued the subject identifier and when was the binding captured? provenance
  4. What changes to the subject invalidate this binding and require a fresh assessment? constraint

Intended purpose and system classification profile

The declared intended purpose, reasonably foreseeable misuse, deployment setting and a coded classification profile of the system along recognised classification dimensions.

  1. What is the declared intended purpose of the system and which uses are explicitly excluded? definition
  2. How is the system profiled along the recognised classification dimensions of people and planet, economic context, data and input, model and task and output? classification
  3. In which jurisdictions, sectors and organisational or physical settings is the system deployed? spatial
  4. Which user groups, affected persons and non-user third parties interact with or are subject to the system? relationship

Assessment Record Frame

The identity, revision, mandate, scope and method of the assessment itself.

Assessment identity, revision and mandate

Identifiers, revision designation, temporal anchors and the authority under which the assessment was opened.

  1. Which identifier uniquely designates this assessment record and its revision? identity
  2. What are the evidence cut-off time and the record creation time for this assessment? temporal
  3. How are assessment revisions numbered and which revision is authoritative right now? lifecycle
  4. Under whose mandate and on which basis was this assessment opened? authority

Assessment scope, exclusions and method

What kind of assessment this is, what question it answers, what it deliberately excludes, and the method, criteria and sampling used to reach findings.

  1. What assessment type is this and what specific question is it answering? definition
  2. Which parts of the system, lifecycle stage or use context are explicitly excluded from this assessment? constraint
  3. Which method, criteria and sampling approach produced the findings? process
  4. What depth of assurance does this method support and what could it not establish? quality
Obligation and Applicability Frame Which role the organisation holds, which regimes apply, which risk tier the system falls into, and which requirements therefore bind.

Role and Regime

Operator role determination and the set of legal, contractual and internal regimes asserted to apply.

Operator role and applicable regime set

Which role the assessed organisation holds for this system in each market, which regimes apply on what territorial basis, and which exemptions are relied on.

  1. Which operator role does the assessed organisation hold for this system in each market it serves? classification
  2. Which legal, regulatory, contractual and internal regimes are asserted to apply and on what territorial basis? authority
  3. Which other operators in the value chain hold obligations that this assessment relies on? relationship
  4. Which exemptions, derogations or research exclusions are claimed and how is each justified? exception

Risk Tier and Obligation Set

The risk-tier determination and the resulting applicability statement over normative requirements.

Risk tier or category determination

The classification of the system into a risk tier or category under each applicable regime, with the reasoning and evidence that supports it, including any documented not-high-risk derogation.

  1. Which risk tier or category does the system fall into under each applicable regime? classification
  2. What reasoning and evidence support the tier determination, including any claim that a listed system is not high-risk? evidence
  3. Who determined the tier and when must that determination be revisited? decision
  4. How does the tier under one regime map onto tiers or thresholds under the others? interoperability

Requirement applicability statement

The enumerated normative requirements that apply given role and tier, those excluded with justification, and the party responsible for each.

  1. Which individual normative requirements apply to this system given its role and tier? requirement
  2. Which requirements are excluded and what justification is recorded for each exclusion? composition
  3. Which party is responsible for satisfying each applicable requirement? ownership
  4. How are overlapping requirements from different regimes deduplicated without losing traceability to each source? interoperability
Risk, Impact and Threat Analysis AI-specific risk tagging, stakeholder impact analysis, the binding to externally owned risk items, and the adversarial and data-provenance findings.

Harm and Impact

Taxonomy assignment, stakeholder impact characterisation and risk-evidence binding.

AI risk taxonomy assignment

Assignment of AI-specific risk category codes and trustworthiness characteristics to the assessed subject, including entries explicitly considered and ruled out.

  1. Which AI-specific risk categories and trustworthiness characteristics are implicated by this system? classification
  2. Which taxonomy scheme and version supplies the code list used for each tag? definition
  3. How does each risk tag map onto the referenced risk register items? relationship
  4. Which taxonomy entries were considered and explicitly ruled out, and on what basis? quality

Affected stakeholder and impact analysis

Identification of individuals, groups, communities and environmental receptors that could be affected, with characterised severity, breadth and reversibility, and the record of stakeholder consultation.

  1. Which individuals, groups, communities and environmental receptors could be affected, including people who never interact with the system? relationship
  2. How are severity, likelihood, reversibility and breadth of impact characterised for each affected group? measurement
  3. Which stakeholders were consulted and how was their input incorporated or rejected? process
  4. What personal data or special-category processing does the system entail and which separate assessment covers it? privacy

Risk and opportunity register binding

The citation of externally owned risk and opportunity register items as evidence, with the assessment-scoped parameters that may legitimately be carried on the binding.

  1. Which risk and opportunity register items does this assessment cite as evidence? relationship
  2. Which revision of each cited register item is bound so the citation stays reproducible? identity
  3. Which assessment-scoped parameters may be recorded on the binding without duplicating register state? constraint
  4. When was each register item read and which register version was current at that moment? provenance

Threat and Data Analysis

Adversarial attack surface and data-provenance findings specific to the assessed subject.

Adversarial threat surface

Credible adversarial attack classes against the system's training and inference stages, the trust boundaries and untrusted input channels, and the attacker assumptions adopted.

  1. Which adversarial attack classes are credible against this system's learning and inference stages? security
  2. Which trust boundaries, untrusted input channels and tool or agent surfaces exist in the deployment? composition
  3. What attacker capability, knowledge and access assumptions were adopted for the analysis? classification
  4. Which security tests or red-team exercises probed each identified attack class? validation

Data and provenance risk finding

Assessment findings on the origin, licensing, quality, representativeness and restrictions of training, validation and test data, referencing dataset documentation held elsewhere.

  1. What is the origin, licensing status and collection basis of the training, validation and test data? provenance
  2. Which data quality, representativeness and bias properties were examined against the intended purpose? quality
  3. Which data-related restrictions bind the system's permitted use? constraint
  4. Where is the authoritative dataset record held and who retains it? ownership
Safeguards and Evidence Declared safeguards, human oversight, capability-threshold tiering, effectiveness judgements, and the evidence base with its metrics and validity limits.

Safeguard Declaration

The safeguards selected, the human oversight arrangement and the capability-threshold safeguard tier.

Safeguard selection and applicability

The safeguards and controls selected to address each applicable requirement and risk, how they are layered across lifecycle stages, who owns them, and which are declared but not yet implemented.

  1. Which safeguards are selected to address each applicable requirement and identified risk? requirement
  2. How are safeguards layered across design, training, deployment and operational stages? composition
  3. Which organisational unit owns each declared safeguard? ownership
  4. Which safeguards are declared but not yet implemented and by when are they due? state

Human oversight arrangement

The oversight measures built into the system and those the deployer must add, the overseer's authority to intervene, and the competence and conditions effective oversight requires.

  1. What oversight measures are built into the system and which measures must the deployer add? process
  2. Which decisions can a human overseer override, halt or escalate, and under what authority? authority
  3. What competence, training, tooling and time budget does effective oversight require? requirement
  4. How is automation bias detected and counteracted in the oversight arrangement? quality

Capability threshold and safeguard tier

Whether the model approaches or crosses declared capability thresholds, which safeguard tier is consequently required, which is in force, and what elicitation effort backs a not-crossed claim.

  1. Which declared capability thresholds does the model approach or cross? measurement
  2. Which safeguard tier is required by the determination and which tier is currently in force? state
  3. What triggers a capability reassessment ahead of the scheduled interval? event
  4. What elicitation effort backs a claim that a threshold is not crossed? evidence

Effectiveness and Residual Risk

Point-in-time judgement of safeguard effectiveness and the resulting residual risk position.

Safeguard effectiveness judgement and residual risk position

The assessor's point-in-time judgement of whether each credited safeguard is effective, the residual risk that remains per category, and the deficiencies accepted as open.

  1. On what basis is each credited safeguard judged effective, partially effective or ineffective? validation
  2. What residual risk remains per risk category after the assessed safeguards? measurement
  3. As of which point in time does the effectiveness judgement hold? temporal
  4. Which deficiencies are left open, by whose acceptance, and under what compensating measure? exception

Evaluation Evidence

Citations to evaluation results, the metrics and thresholds they are read against, and the validity limits of those measurements.

Evaluation evidence citation

The set of evaluation runs, benchmarks, audits and red-team exercises cited as evidence, each identified, integrity-checked, attributed and judged for sufficiency and currency.

  1. Which evaluation runs, benchmarks, audits and red-team exercises are cited as evidence? evidence
  2. How is each cited evidence item identified and integrity-checked? identity
  3. Who executed each evaluation, against which subject version, and under which harness configuration? provenance
  4. Is the cited evidence sufficient and current for the claim it is used to support? quality

Metrics and acceptance thresholds

The metrics that express accuracy, robustness, safety and fairness for this system, the acceptance thresholds set for them, the conditions under which those thresholds hold, and current measured values.

  1. Which metrics and units express accuracy, robustness, safety and fairness for this system? measurement
  2. What acceptance threshold applies to each metric and who set it? requirement
  3. Under which operating conditions and populations do the declared thresholds hold? constraint
  4. What is the current measured value against each threshold and is it passing? state

Measurement validity and limitations

Honest qualification of the evidence base: construct validity of each metric relative to the harm it stands for, risks acknowledged as unmeasurable, contamination and distribution-shift caveats, and staleness intervals.

  1. What is the construct validity of each metric relative to the harm it is taken to represent? quality
  2. Which identified risks are acknowledged as not measurable with the available methods? exception
  3. Which contamination, elicitation-gap or distribution-shift caveats apply to the cited results? constraint
  4. How quickly do the cited results go stale and what revalidation interval applies? temporal
Decision and Accountability Operational signal linkage, the assessment conclusion and conditions, accountable sign-off and independent review citations.

Operational Signal Linkage

References to post-market monitoring and incident or hazard records that feed the assessment.

Post-market signal and incident binding

References to the post-market monitoring arrangement and to incident and hazard records considered by this assessment, with the classes of signal that must feed back into it.

  1. Which post-market monitoring arrangement and which incident or hazard records does this assessment reference? relationship
  2. Which incident and hazard classes must be fed back into this assessment? event
  3. What timelines apply from signal detection to assessment update? temporal
  4. Which system owns incident case management and what does this assessment retain? ownership

Decision, Conditions and Assurance

The conclusion and residual-risk acceptance, attached conditions and triggers, accountable sign-off, and citations to independent review.

Assessment conclusion and residual risk acceptance

The terminating judgement of the assessment, who holds authority to accept the stated residual risk, which deployment scopes the conclusion covers and how long it is valid.

  1. What is the assessment conclusion: approve, approve with conditions, defer or reject? decision
  2. Who holds authority to accept residual risk at the stated level? authority
  3. Which deployment scopes, markets and use cases does the conclusion cover? constraint
  4. For how long is the conclusion valid absent a triggering change? temporal

Conditions, restrictions and reassessment triggers

The conditions and restrictions attached to an approval, the events that trigger reassessment, what happens to approval status while reassessment is pending, and who monitors for triggers.

  1. Which conditions, restrictions and prohibited uses attach to the approval? constraint
  2. Which changes to the model, data, deployment context or law trigger reassessment? event
  3. What happens to approval status when a trigger fires but reassessment is not yet complete? state
  4. Who watches for trigger conditions and how are they notified? process

Accountable ownership and sign-off

The named accountable person or body owning the assessment outcome, the delegated authority permitting sign-off at this risk level, the form of the sign-off and what happens when the owner changes.

  1. Which named person or body owns this assessment and its outcome? ownership
  2. Which delegated authority permits sign-off at this risk level? authority
  3. What form does the sign-off take and how is signer identity established? evidence
  4. What happens to accountability when the named owner leaves the role? lifecycle

Independent review and attestation citation

Citations to internal audit, external review, notified body or certification records related to this assessment, with independence characterisation and explicit limits on what may be claimed from them.

  1. Which internal audit, external review or certification records relate to this assessment? relationship
  2. How independent was each reviewer from the development and deployment teams? quality
  3. What is the exact scope of each cited external attestation? evidence
  4. What may and may not be claimed on the basis of each cited review? validation
Record Lifecycle, Retention and Disclosure The assessment record's own state machine, supersession provenance, retention and disposition, disclosure tiering and alignment crosswalks.

Record Lifecycle and Retention

States, transitions, supersession provenance, retention period and disposition of the assessment record.

Record state and supersession provenance

The lifecycle state of the assessment record, which transitions are permitted, what changed relative to the superseded revision, and the separate event and recording times of each transition.

  1. Which lifecycle state is this assessment record currently in? state
  2. Which transitions are permitted and which changes require a new revision rather than an in-place edit? lifecycle
  3. What changed relative to the superseded revision and why was the assessment reopened? provenance
  4. When did each transition occur in event time and when was it recorded in the system? temporal

Retention and disposition of the assessment record

How long the assessment and its supporting citations must be kept, under which authority, what remains discoverable after disposition, and how personal data inside the record is minimised.

  1. How long must this assessment and its supporting citations be retained and under which rule? retention
  2. Which policy or authority sets the retention period and authorises disposition? authority
  3. What must remain discoverable after disposition, such as a tombstone or index entry? access
  4. How is personal data inside the assessment minimised or redacted before long-term retention? privacy

Disclosure and Alignment

Audience-tiered disclosure with redaction, and traceable crosswalks to aligned external frameworks.

Disclosure tiering and redaction

Which audiences may see which parts of the assessment, what is withheld as trade secret or security-sensitive, how a redacted external version is derived, and which disclosures are mandatory regardless of preference.

  1. Which audiences may see which parts of this assessment? access
  2. Which content is withheld as trade secret, security-sensitive or dual-use hazardous? security
  3. How is a redacted external version derived and kept consistent with the internal record? process
  4. Which disclosures are legally mandatory regardless of confidentiality preference? requirement

Framework alignment crosswalk

Traceable mapping from this assessment's elements onto each aligned external framework, with mapping strength, conflicts between frameworks and the framework version used.

  1. How do this assessment's elements map onto each aligned framework's structure? interoperability
  2. Which mappings are exact, partial or absent, and what evidence supports each claim? validation
  3. Where do the aligned frameworks conflict or use the same term with different meanings? exception
  4. Which framework version was used for each mapping and when was it last verified? provenance

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
aggregate
Navigation path
NAV.INF.AI.GOV
Domain
INF.AI.GOV
Industry
Cross-industry
Tags
aisafetygovernanceassessmentinf.ai.gov

What it is Filled

This model describes one assessment record: a bounded, dated, signed judgement about the safety, risk and regulatory position of a named AI system version. It owns the assessment's own identity, scope, method, applicability determinations, risk and impact analysis, declared safeguards, evidence citations, residual-risk position, decision, conditions, record lifecycle and disclosure tiering. It carries references and subject-specific bindings to externally owned records (risk register items, evaluation runs, incident cases, certificates, dataset documentation) but never reproduces those records' lifecycles, execution semantics or audit trails. It is storage- and interface-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics.

In scope

  • Assessment record identity, revision and mandate
  • Binding to a specific assessed AI system version, configuration and component boundary
  • Intended purpose, foreseeable misuse, deployment context and system classification profile
  • Operator role and applicable regulatory, contractual and internal regime determination
  • Risk-tier or category determination and its documented justification
  • Applicability statement over normative requirements and selected safeguards
  • AI-specific risk taxonomy tagging and stakeholder impact analysis
  • Adversarial threat-surface and data-provenance findings for the assessed subject
  • Declared human-oversight arrangement and capability-threshold safeguard tier
  • Evidence citations with integrity, currency and sufficiency judgements
  • Metric and acceptance-threshold declarations plus measurement-validity caveats
  • Residual-risk position, decision, conditions and reassessment triggers
  • Accountable ownership, sign-off and independence declarations
  • Record lifecycle states, supersession provenance, retention and disclosure tiering
  • Crosswalks asserting alignment to external frameworks with conflict notes

Out of scope

  • The risk and opportunity register's own item lifecycle, scoring methodology, treatment workflow and closure states, owned by WM-KNW-015
  • Full technical documentation of the AI system (architecture, training procedure, dataset inventories) which belongs to a separate AI system technical record
  • Execution of evaluations, benchmarks or red-team runs; this model cites results and never owns harness configuration, run orchestration or scoring semantics
  • Runtime guardrail, filter or policy-enforcement engines and their decision semantics
  • Incident case management, triage, notification workflow and regulator correspondence
  • Operational audit trails of control execution; only point-in-time assessor judgements are held here
  • Conformity assessment procedures, notified-body activity, certification issue and CE marking, which are cited as external attestations only
  • Organisation-level AI management system clauses (leadership, competence, internal audit programme, management review) which sit above a single assessment
  • Dataset creation, labelling, consent capture and data-subject rights handling
  • Model training, fine-tuning, deployment automation and release engineering
  • Personal data processing records and DPIA execution, which are cited as separate assessments
  • Legal advice, litigation position and regulatory enforcement outcomes

Why it exists Filled

Provide the format-neutral context an agent needs to create, inspect and operate a governance or safety assessment record for a specific AI system: what was assessed, under which obligation regime, against which risks and safeguards, on what evidence, with what residual risk, and what was decided by whom.

Distinguishing features Filled

  • A point-in-time governance or safety assessment of one AI system under a stated obligation regime.
  • Decides on residual risk and approval, unlike an evaluation record that supplies evidence.
  • References risk register items by revision rather than owning the register.
  • Does not enforce runtime guardrails or manage incidents.

What robots and AI may and may not do Filled

Must not

  • Assert conformance to a framework without a cited attestation.
  • Approve an assessment while a credited safeguard lacks evidence.
  • Use evidence from a different system version without marking it.
  • Withhold content from a mandated recipient without recorded justification.
  • Copy owned content from referenced models into findings.

Only with a human decision

  • Issuing the assessment decision and accepting residual risk.
  • Determining the operator role and risk tier when disputed.

May

  • Open an assessment and bind the system version and classification profile.
  • Compile applicable requirements and safeguards for the operator role and risk tier.
  • Attach risk, impact and evaluation evidence references.
  • Record effectiveness and residual risk positions for review.

Moral aspects Filled

  • Assessments decide whether people can be exposed to an AI system; understated risk shifts harm to them.
  • Fundamental rights impacts must be considered, not only technical safety.
  • Disclosure to regulators supports public accountability.

Who is affected

  • People affected by the AI system
  • Providers and deployers
  • Regulators and notified bodies

Owners Filled

Steward

The adopting Dimension must name a single accountable owner for the assessment model instance, typically the AI system owner together with the accountable deployer, and record the delegation instrument that permits residual-risk acceptance.

Roles

Assessment owner
Hold accountability for the assessment scope, method and outcome; Ensure every credited safeguard has evidence and a responsible party; Initiate supersession when a reassessment trigger fires
Assessor
Perform the analysis and record findings, ratings and residual risk with as-of times; Cite evidence with identifiers, digests and sufficiency judgements; State measurement limitations and unmeasurable risks explicitly
Risk acceptance authority
Accept or refuse the stated residual risk within a recorded delegation limit; Approve attached conditions and restrictions; Escalate acceptance beyond the delegation limit to a higher body
Records and retention custodian
Apply the retention schedule, legal holds and disposition approvals; Maintain tombstones and prevent dangling citations; Log access to restricted findings and artifacts
Disclosure reviewer
Review withholding decisions and their justifications; Verify that mandatory disclosures are not suppressed; Confirm each released variant is traceable to a signed revision by digest
Boundary steward
Verify that no finding reproduces a referenced model's owned content; Maintain composition links, forbidden-field allow-lists and boundary notes; Re-verify crosswalk entries when an aligned framework version changes

Links to other meta-models Filled

references

  • WM-KNW-015 - Cite risk and opportunity register items as the evidence base for this assessment. This model carries the item reference, revision key, read time and assessment-scoped parameters such as AI risk category tags. It does not carry register item state, scoring methodology, treatment plans, register ownership or register review cadence.
  • AI system technical record (sibling model not yet registered) - Reference the provider-maintained technical documentation describing the system's design, training and performance. This model records the reference and an adequacy judgement only. The sibling model is not present in the registry and is recorded as a structural gap.
  • AI evaluation run record and evaluation harness - Reference evaluation runs cited as evidence. Task, solver, scorer, sandbox and log semantics remain owned by the harness; this model holds the run reference, digest, subject version and sufficiency judgement.
  • AI incident and hazard record - Reference incident and hazard records considered by the assessment using interoperable incident definitions. Case management, triage, notification workflow and authority correspondence remain owned by the incident register and the applicable reporting regime.

child

  • WM-ACT-037 - This model is registered as a child of WM-ACT-037 and specialises only the AI-specific assessment surface. Generic assessment-activity scheduling, actor mechanics and workflow state are expected to remain in the parent; the parent's exact surface is unverified and is recorded as an open boundary.

aligned

  • Regulation (EU) 2024/1689 (Artificial Intelligence Act) - Align operator role, risk tier, requirement applicability, human oversight, technical documentation, post-market monitoring and serious incident vocabulary. Alignment is recorded in the crosswalk with mapping strength; no conformance is asserted without cited attestation evidence.
  • ISO/IEC 42001:2023 AI management system - Align the applicability statement, control selection and record retention concepts with the management system standard's Annex A controls and Statement of Applicability. Organisation-level management system clauses remain outside this model.
  • NIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) - Align the MAP, MEASURE and MANAGE analysis layers, the trustworthiness characteristic vocabulary and the generative-AI risk category codes used for taxonomy tagging.
  • ISO/IEC 23894:2023 AI risk management guidance - Align risk terminology and reinforce the separation between the risk management process owned by the register and the assessment that consumes its output as evidence.
  • ISO/IEC 42005:2025 AI system impact assessment - Align the impact analysis finding, its lifecycle placement and its update conditions with the impact assessment guidance.
  • OECD Framework for the Classification of AI Systems - Supply the coded classification profile dimensions used to characterise the assessed system independently of any single regulatory tier scheme.

neighbor

  • WM-KNW-015 risk and opportunity register - This model cites register items as risk evidence and may add assessment-scoped parameters (AI risk taxonomy code, trustworthiness characteristic, assessment-local severity view) on the binding. It must not carry register-item state, scoring method, treatment plans, register owner assignment or register review cadence.
  • AI system technical record (EU AI Act Annex IV technical documentation) - Annex IV documentation is a distinct, provider-maintained artefact describing the system itself. This model references it and records whether it exists and is adequate, not its content.
  • AI evaluation run record and evaluation harness - Harnesses such as Inspect own task, solver, scorer and log semantics. This model stores the run reference, subject version, integrity digest and an adequacy judgement only.
  • AI incident and hazard record - Incident definition, case management and authority notification are owned by the incident register and the applicable reporting regime. This model records which incidents were considered as inputs and what they changed in the assessment.
  • AI management system (ISO/IEC 42001 AIMS) - Organisation-level policy, resourcing, internal audit programme and management review belong to the management system. A single assessment instance is an output of that system, not the system itself.
  • Conformity assessment body and certification record - Certificates, notified-body decisions and CE marking are external attestations. This model cites their identifiers and scope and must not assert conformance without cited evidence.
  • WM-ACT-037 parent model - The registry declares WM-ACT-037 as parent. Generic assessment-activity scheduling, workflow and actor mechanics are expected to sit there; only AI-specific assessment content is specialised here. The parent's exact surface is unverified and is recorded as an open boundary.
  • Runtime guardrail and policy-enforcement engine - A safeguard declared and judged here may be enforced by a runtime engine. Referencing that engine grants no ownership of its evaluation, enforcement or logging semantics.

parent

  • WM-ACT-037

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier: the identifier issued by the system of record for the assessment, for example the AI management system, GRC platform or quality management system assessment number, used verbatim as the primary key whenever one exists.
  • Governed global identifier or IRI: an identifier from a governed scheme, such as a registration identifier in an official database for high-risk AI systems, an accredited certificate number, or a persistent DOI or organisation-governed IRI.
  • UUID or ULID minted by the adopting Dimension, used only when neither a master-system identifier nor a governed global identifier is available, and recorded together with the reason no higher-priority identifier applied.
  • A date, a title, a file name, a storage path or an author name is never an identifier and must not be used as a key or as a disambiguator on its own.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • An assessment names the system version, regime, risk tier, safeguards, evidence and a decision.
  • Often confused with a model evaluation, a conformity certificate, a risk register and an incident record.

Capabilities and actions required Filled

  • Open assessment: Create a new assessment record in draft state under a stated mandate, with identity, revision and temporal anchors set.
  • Bind subject and record classification profile: Fix the assessed system version, component boundary, intended purpose and coded classification profile.
  • Determine operator role and risk tier: Record the operator role per market, the applicable regime set and the risk tier determination with its justification.
  • Compile requirement and safeguard applicability: Derive the applicable requirement set from role and tier, record exclusions with justification, and map selected safeguards to each requirement and risk.
  • Attach risk and impact references: Bind externally owned risk and opportunity register items as evidence, carrying only reference, revision, read time and assessment-scoped parameters.
  • Register evaluation evidence reference: Add a citation to an externally produced evaluation, audit or exercise, with identifier, digest, executing party, evaluated subject version and sufficiency judgement.
  • Record effectiveness and residual risk position: Capture per-safeguard effectiveness ratings, residual risk levels per category, the as-of time and any accepted open deficiencies.
  • Issue assessment decision: Terminate the assessment with a conclusion, residual-risk acceptance by an authorised role, coverage scope, validity window, attached conditions and reassessment triggers.
  • Supersede or reopen assessment: Create a new revision in response to a fired trigger or scheduled review, linking the superseded revision and recording the change reason and both event and recording times.
  • Emit audience-tiered disclosure view: Derive an audience-scoped release from a signed revision, applying withholding rules and recording digests of both the source revision and the released variant.

Hazards and failure modes required Filled

  • False approval from evidence that does not match the system version.
  • Uncovered risks from incomplete requirement mapping.
  • Regulatory breach from wrong operator role or tier.

Standards and interfaces required Filled

  • ISO/IEC 42001 AI management system.
  • ISO/IEC 23894 AI risk management.
  • ISO/IEC 42005 AI system impact assessment.
  • NIST AI Risk Management Framework.
  • EU AI Act (Regulation (EU) 2024/1689).

Context of use required Filled

  • Regulatory role and tier vocabulary is drawn primarily from the European Union regime; other jurisdictions require additional coded regime entries and may not use a comparable tiering concept.
  • Retention periods are assumed to be set by the adopting Dimension and by applicable law; the model prescribes only the clock-start event and the tombstone rule, not a numeric period.
  • Serious incident reporting deadlines and recipients are jurisdiction-specific and are referenced rather than encoded.
  • Personal data handling assumes a jurisdiction with a data protection impact assessment instrument; where none exists, the linkage field is left empty rather than the concept being redefined.
  • Capability-threshold and safeguard-tier practice is drawn from voluntary developer frameworks and the European general-purpose AI regime, and is not a global requirement.

Sources Filled

  1. AI Risk Management Framework (AI RMF 1.0) — AI RMF Core - National Institute of Standards and Technology (NIST)
  2. AI Risk Management Framework — AI Risks and Trustworthiness - National Institute of Standards and Technology (NIST)
  3. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - European Union (Official Journal, EUR-Lex)
  4. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) - National Institute of Standards and Technology (NIST)
  5. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2 E2025) - National Institute of Standards and Technology (NIST)
  6. ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system - International Organization for Standardization / International Electrotechnical Commission
  7. ISO/IEC 23894:2023 Information technology — Artificial intelligence — Guidance on risk management - International Organization for Standardization / International Electrotechnical Commission
  8. ISO/IEC 42005:2025 Information technology — Artificial intelligence — AI system impact assessment - International Organization for Standardization / International Electrotechnical Commission
  9. General-Purpose AI Code of Practice - European Commission, Directorate-General for Communications Networks, Content and Technology
  10. Defining AI incidents and related terms (OECD Artificial Intelligence Papers No. 16) - Organisation for Economic Co-operation and Development (OECD)
  11. Anthropic Responsible Scaling Policy - Anthropic
  12. Inspect: an open-source framework for large language model evaluations - UK AI Security Institute
  13. OECD Framework for the Classification of AI Systems (OECD Digital Economy Papers No. 323) - Organisation for Economic Co-operation and Development (OECD)

Open questions

  • Verify the WM-ACT-037 parent surface and re-run the duplication check against assessment identity, scope and method, accountable sign-off, record state and supersession, and retention findings.
  • Register or author the AI system technical record sibling for EU AI Act Annex IV documentation and the AI evaluation run record, then convert the reference-only bindings into typed edges in the relationship contract.
  • Design the compute, energy and emissions measurement structure that the sustainability checklist dimension currently records as an open gap.
  • Model agentic and multi-agent composition, tool authority scoping and delegation chains, which the cited sources presently treat only as attack surfaces and autonomy attributes.
  • Establish supply-chain attestation structure such as an AI bill of materials and provenance signatures to carry the value-chain risk the sources name but do not structure.
  • Add contestation and redress mechanisms for affected persons beyond what the impact analysis and human oversight findings currently hold.
  • Close the operating-surface gaps: an operation that records a fired reassessment trigger and sets interim status, a withdraw or void operation distinct from supersession, a capability-tier determination operation, and operations producing the impact assessment and threat model artifacts.
  • Obtain independent second-provider corroboration of the aggregate boundary, source set and question surface if the owner-authorized Grok waiver is ever lifted.
  • No dedicated finding for compute, energy or emissions measurement, despite environmental impact being a named generative-AI risk category.
  • No structure for agentic or multi-agent system composition, tool authority scoping or delegation chains; current sources treat these only as attack surfaces and autonomy attributes rather than as a governed structure.
  • No structure for model or system supply-chain attestation such as bill-of-materials or provenance signatures; value chain risk is named by the cited sources but no normative structure is established for an assessment record.
  • No sector-specific overlays, for example medical device, financial services or automotive assessment content, which would sit in sibling models.
  • No treatment of contestation and redress mechanisms for affected persons beyond the impact analysis and oversight findings.
  • The AI system technical record sibling model is not registered; the reference is declared as a structural gap rather than a canonical link.
  • The parent model WM-ACT-037 surface is unverified, so the split between generic assessment-activity mechanics and AI-specific content is asserted rather than confirmed.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-ai-008-ai-safety-governance-assessment/spec.yaml, ver-cy/world-models/card-supplements/wm-ai-008-ai-safety-governance-assessment.json