AI Vulnerability, Impact, Risk and Impact Taxonomy

Best Seller
AI Vulnerability, Impact, Risk and Impact Taxonomy
Digital Product

Document Description

This documentation package provides a practical and defensible structure for assessing AI-related exposures in real organizational settings.

It is designed for risk managers, AI governance leads, security teams, internal audit, compliance functions, and project leaders who need a consistent way to evaluate AI systems, technology initiatives, and business projects beyond generic checklists.

The material combines:

  • AI quality characteristics based on ISO/IEC 25059
  • A structured AI vulnerability taxonomy
  • AI-related threat vectors and attack patterns
  • Impact and loss categories relevant to organizations, individuals, and society
  • Mappings to key regulatory and standards references, including the EU AI Act, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, and OWASP

This can be used to:

  • Assess AI use cases before approval
  • Conduct threat, vulnerability, and impact analysis
  • Structure AI risk assessments and control reviews
  • Support internal audit and model governance work
  • Strengthen documentation for boards, regulators, and assurance teams
  • Build more consistent methods for evaluating AI, IT, and investment projects

The value of this package is not just taxonomy. It gives teams a common language and a structured assessment lens to identify where exposure exists, why it matters, and what controls should be considered.

Content

AI Vulnerability, Impact, Risk and Threat Taxonomy.xlsx

AI Quality Characteristics (ISO/IEC 25059): Functional suitability, robustness, and transparency requirements translated into engineering controls.

AI Vulnerability Catalog: Dozens of AI-specific weaknesses (e.g., Weak Runtime Authorization, Prompt Isolation Failures) mapped to root causes, severity, and EU AI Act articles.

AI Threat Vector Matrix: Detailed attack paths (Data Poisoning, Adversarial Deception, Data Exfiltration) linked to exploitable vulnerabilities and detection difficulty.

Impact and Incident Taxonomy: A structured breakdown of internal business losses and external societal impacts (Discrimination, Cognitive Degradation) required for Fundamental Rights Impact Assessments.

Instructions

Please share the context in which you plan to use the material:

  • AI governance program
  • Use case assessment
  • Internal audit
  • AI security review
  • Vendor evaluation
  • Investment or transformation review
  • Academic or policy research

If relevant, specify whether you want the taxonomy applied to:

  • Generative AI
  • Agentic AI
  • Predictive ML systems
  • Enterprise software projects
  • IT transformation
  • Business case and investment decisions

$350