This documentation package provides a practical and defensible structure for assessing AI-related exposures in real organizational settings.
It is designed for risk managers, AI governance leads, security teams, internal audit, compliance functions, and project leaders who need a consistent way to evaluate AI systems, technology initiatives, and business projects beyond generic checklists.
The material combines:
This can be used to:
The value of this package is not just taxonomy. It gives teams a common language and a structured assessment lens to identify where exposure exists, why it matters, and what controls should be considered.
AI Vulnerability, Impact, Risk and Threat Taxonomy.xlsx
AI Quality Characteristics (ISO/IEC 25059): Functional suitability, robustness, and transparency requirements translated into engineering controls.
AI Vulnerability Catalog: Dozens of AI-specific weaknesses (e.g., Weak Runtime Authorization, Prompt Isolation Failures) mapped to root causes, severity, and EU AI Act articles.
AI Threat Vector Matrix: Detailed attack paths (Data Poisoning, Adversarial Deception, Data Exfiltration) linked to exploitable vulnerabilities and detection difficulty.
Impact and Incident Taxonomy: A structured breakdown of internal business losses and external societal impacts (Discrimination, Cognitive Degradation) required for Fundamental Rights Impact Assessments.
Please share the context in which you plan to use the material:
If relevant, specify whether you want the taxonomy applied to: