/home/techb158/balavpn.abdallabala.com/prisma
Edit: /home/techb158/balavpn.abdallabala.com/prisma/seed-import.json (170983B)
{
"schemaVersion": "1.0.0",
"exportType": "COSMIC_AI_RISK_PROJECT_SEED",
"generatedAt": "2026-07-08",
"sourceBasis": {
"presentationDerived": [
"AI risks require measurement because AI projects depend on data quality, model variability, experimentation, opacity, organizational deployment, governance, and measurement.",
"The project uses organizational, technical, and human governance dimensions.",
"The project objective includes measurable risk indicators, software prototype, API, and integration with project management tools."
],
"softwareDesignExtension": [
"Risk scoring formula, JSON schema, Trello lists, gate rules, sample risks, mitigations, experiments, and API seed endpoints are operational implementation logic for the software prototype."
]
},
"project": {
"id": "AI-PROJ-2026-001",
"name": "Retail Customer Support GenAI Assistant",
"shortName": "SupportGenAI",
"description": "AI assistant for customer support agents. It answers order, refund, shipping, and product questions using an approved knowledge base and escalates sensitive cases to human support.",
"industry": "Retail and e-commerce",
"organization": "Example Retail Group",
"status": "active_pilot",
"currentLifecycleStageId": "LC-04",
"projectTypology": [
"AI-Enabler",
"Incremental"
],
"businessObjectives": [
"Reduce average support handling time by 20 percent",
"Improve answer consistency across support channels",
"Maintain legal, privacy, ethical, and operational risk within approved thresholds"
],
"startDate": "2026-06-01",
"plannedPilotDate": "2026-08-15",
"plannedProductionDate": "2026-09-15",
"sponsorRole": "Executive Sponsor",
"managerRole": "Project Manager"
},
"aiSystem": {
"systemType": "Retrieval augmented generation assistant",
"modelFamily": "Large language model with approved knowledge base retrieval",
"modelVersion": "cs-rag-v0.2",
"deploymentMode": "Human in the loop support copilot",
"userGroups": [
"Customer support agents",
"Team leads",
"Quality assurance reviewers"
],
"dataSources": [
{
"id": "DATA-001",
"name": "Support knowledge base",
"classification": "internal",
"containsPII": false,
"ownerRole": "Product Owner"
},
{
"id": "DATA-002",
"name": "Historical support tickets",
"classification": "confidential",
"containsPII": true,
"ownerRole": "Data Steward"
},
{
"id": "DATA-003",
"name": "Refund and return policy documents",
"classification": "internal",
"containsPII": false,
"ownerRole": "Legal Reviewer"
}
],
"approvedUseCases": [
"Draft answers for support agents",
"Summarize customer issue history after redaction",
"Recommend escalation when request is sensitive or outside approved scope"
],
"prohibitedUseCases": [
"Fully automated refund approval",
"Legal advice to customers",
"Medical, financial, or regulated advice",
"Use of raw personal data in model prompts when redaction is available"
]
},
"lifecycleStages": [
{
"id": "LC-01",
"name": "Identification and analysis of needs",
"status": "completed",
"entryCriteria": [
"Business problem defined",
"AI suitability reviewed",
"Initial stakeholders assigned"
],
"exitCriteria": [
"Problem statement approved",
"Expected value documented",
"Initial risk scan completed"
],
"ownerRole": "Project Manager",
"startDate": "2026-06-01",
"endDate": "2026-06-07",
"deliverables": [
"Project charter",
"Business objectives",
"Initial AI risk assessment"
]
},
{
"id": "LC-02",
"name": "Data collection and preparation",
"status": "completed",
"entryCriteria": [
"Data sources identified",
"Data access approved"
],
"exitCriteria": [
"Data quality score at least 80",
"PII handling approved",
"Dataset version frozen for baseline"
],
"ownerRole": "Data Steward",
"startDate": "2026-06-08",
"endDate": "2026-06-21",
"deliverables": [
"Data inventory",
"Data quality report",
"PII treatment log"
]
},
{
"id": "LC-03",
"name": "Design",
"status": "completed",
"entryCriteria": [
"Use cases prioritized",
"Data readiness confirmed"
],
"exitCriteria": [
"Architecture approved",
"Prompt strategy documented",
"Human fallback workflow approved"
],
"ownerRole": "Solution Architect",
"startDate": "2026-06-22",
"endDate": "2026-07-02",
"deliverables": [
"Solution architecture",
"Prompt design specification",
"Risk control design"
]
},
{
"id": "LC-04",
"name": "AI model development and training",
"status": "in_progress",
"entryCriteria": [
"Architecture approved",
"Training and evaluation datasets ready"
],
"exitCriteria": [
"Baseline experiment completed",
"Safety controls tested",
"Model card drafted"
],
"ownerRole": "ML Engineer",
"startDate": "2026-07-03",
"endDate": "2026-07-22",
"deliverables": [
"Experiment logs",
"Model card",
"Prompt registry",
"Evaluation report"
]
},
{
"id": "LC-05",
"name": "Testing and performance evaluation",
"status": "planned",
"entryCriteria": [
"Candidate model selected",
"Risk controls implemented"
],
"exitCriteria": [
"Performance thresholds met",
"Ethical review completed",
"Legal review completed"
],
"ownerRole": "QA Lead",
"startDate": "2026-07-23",
"endDate": "2026-08-09",
"deliverables": [
"Test report",
"Red team report",
"Bias evaluation",
"Legal and ethical review evidence"
]
},
{
"id": "LC-06",
"name": "Deployment, support, and monitoring",
"status": "planned",
"entryCriteria": [
"Deployment gate passed",
"Rollback plan approved"
],
"exitCriteria": [
"Production monitoring active",
"Incident playbook tested",
"Post deployment review completed"
],
"ownerRole": "MLOps Lead",
"startDate": "2026-08-10",
"endDate": "2026-09-15",
"deliverables": [
"Deployment checklist",
"Monitoring dashboard",
"Incident response log",
"Continuous improvement backlog"
]
}
],
"governance": {
"dimensions": [
"Organizational",
"Technical",
"Human"
],
"riskCategories": [
"Strategic and organizational risks",
"Technical risks",
"Legal and ethical risks"
],
"decisionBodies": [
{
"name": "Weekly AI Risk Review",
"cadence": "weekly",
"participants": [
"Project Manager",
"Product Owner",
"Data Scientist",
"ML Engineer",
"Security Officer"
]
},
{
"name": "Deployment Gate Committee",
"cadence": "per gate",
"participants": [
"Executive Sponsor",
"Legal Reviewer",
"Ethics Reviewer",
"MLOps Lead",
"Project Manager"
]
}
],
"riskScoringModel": {
"scale": {
"likelihood": "1 to 5",
"impact": "1 to 5",
"uncertainty": "1 to 5",
"controlEffectiveness": "0 to 100 percent"
},
"formula": "inherentScore = round((likelihood * impact * uncertainty) / 125 * 100); residualScore = round(inherentScore * (1 - controlEffectiveness / 100))",
"severityRules": [
{
"severity": "low",
"condition": "residualScore < 25"
},
{
"severity": "medium",
"condition": "25 <= residualScore < 50"
},
{
"severity": "high",
"condition": "residualScore >= 50"
}
],
"gateRule": "Deployment is blocked when at least one high residual risk is not approved or formally accepted, or when legal, ethical, security, monitoring, or rollback criteria fail."
}
},
"roles": [
{
"id": "ROLE-PM",
"name": "Project Manager",
"permissions": [
"create_project",
"edit_risks",
"approve_mitigation_plan",
"view_reports"
],
"person": "Project Manager"
},
{
"id": "ROLE-PO",
"name": "Product Owner",
"permissions": [
"edit_requirements",
"approve_scope",
"view_metrics"
],
"person": "Product Owner"
},
{
"id": "ROLE-DS",
"name": "Data Scientist",
"permissions": [
"create_experiment",
"edit_metrics",
"view_data_quality"
],
"person": "Data Scientist"
},
{
"id": "ROLE-MLE",
"name": "ML Engineer",
"permissions": [
"create_experiment",
"deploy_candidate",
"edit_model_card"
],
"person": "ML Engineer"
},
{
"id": "ROLE-DST",
"name": "Data Steward",
"permissions": [
"edit_data_inventory",
"approve_data_readiness",
"view_pii_logs"
],
"person": "Data Steward"
},
{
"id": "ROLE-LEGAL",
"name": "Legal Reviewer",
"permissions": [
"approve_legal_review",
"edit_legal_notes"
],
"person": "Legal Counsel"
},
{
"id": "ROLE-ETHICS",
"name": "Ethics Reviewer",
"permissions": [
"approve_ethics_review",
"edit_ethics_notes"
],
"person": "Ethics Officer"
},
{
"id": "ROLE-SEC",
"name": "Security Officer",
"permissions": [
"approve_security_controls",
"view_audit_log",
"edit_incident_playbook"
],
"person": "Security Officer"
},
{
"id": "ROLE-MLOPS",
"name": "MLOps Lead",
"permissions": [
"approve_deployment",
"edit_monitoring",
"trigger_rollback"
],
"person": "MLOps Lead"
},
{
"id": "ROLE-SPONSOR",
"name": "Executive Sponsor",
"permissions": [
"approve_gate",
"accept_residual_risk",
"view_executive_report"
],
"person": "Executive Sponsor"
}
],
"metrics": [
{
"id": "MET-DQ-01",
"name": "Data completeness",
"dimension": "Technical",
"measurand": "Share of required fields populated",
"unit": "%",
"value": 91,
"target": ">=90",
"status": "pass",
"collectedAt": "2026-07-08"
},
{
"id": "MET-DQ-02",
"name": "PII exposure rate",
"dimension": "Legal and ethical",
"measurand": "Detected PII tokens per 1000 output tokens",
"unit": "rate",
"value": 0.3,
"target": "<=0.5",
"status": "pass",
"collectedAt": "2026-07-08"
},
{
"id": "MET-MOD-01",
"name": "Answer groundedness",
"dimension": "Technical",
"measurand": "Answers supported by approved knowledge base",
"unit": "%",
"value": 86,
"target": ">=85",
"status": "pass",
"collectedAt": "2026-07-08"
},
{
"id": "MET-MOD-02",
"name": "Hallucination rate",
"dimension": "Technical",
"measurand": "Unsupported factual claims in test responses",
"unit": "%",
"value": 4.8,
"target": "<=5",
"status": "pass",
"collectedAt": "2026-07-08"
},
{
"id": "MET-MOD-03",
"name": "Unsafe answer rate",
"dimension": "Legal and ethical",
"measurand": "Outputs violating safety policy",
"unit": "%",
"value": 1.6,
"target": "<=1",
"status": "watch",
"collectedAt": "2026-07-08"
},
{
"id": "MET-MOD-04",
"name": "Escalation precision",
"dimension": "Human",
"measurand": "Correct human handoff decisions",
"unit": "%",
"value": 82,
"target": ">=88",
"status": "fail",
"collectedAt": "2026-07-08"
},
{
"id": "MET-MOD-05",
"name": "Bias parity gap",
"dimension": "Legal and ethical",
"measurand": "Maximum response quality gap across customer segments",
"unit": "%",
"value": 6.2,
"target": "<=5",
"status": "watch",
"collectedAt": "2026-07-08"
},
{
"id": "MET-OPS-01",
"name": "Average response latency",
"dimension": "Technical",
"measurand": "Mean API response time",
"unit": "ms",
"value": 1380,
"target": "<=2000",
"status": "pass",
"collectedAt": "2026-07-08"
},
{
"id": "MET-OPS-02",
"name": "Monitoring coverage",
"dimension": "Organizational",
"measurand": "Critical controls with active monitoring",
"unit": "%",
"value": 76,
"target": ">=90",
"status": "fail",
"collectedAt": "2026-07-08"
},
{
"id": "MET-GOV-01",
"name": "Mitigation completeness",
"dimension": "Organizational",
"measurand": "Completed mitigation actions divided by required actions",
"unit": "%",
"value": 68,
"target": ">=80",
"status": "watch",
"collectedAt": "2026-07-08"
}
],
"experiments": [
{
"id": "EXP-001",
"name": "Baseline RAG customer support assistant",
"modelVersion": "cs-rag-v0.1",
"datasetVersion": "kb-support-2026-06-21",
"promptVersion": "prompt-support-v1",
"status": "completed",
"startedAt": "2026-07-03",
"completedAt": "2026-07-04",
"ownerRole": "Data Scientist",
"metrics": {
"groundedness": 78,
"hallucinationRate": 8.2,
"unsafeAnswerRate": 2.4,
"latencyMs": 1260
},
"decision": "Rejected. Hallucination and unsafe answer rates exceeded target.",
"linkedRiskIds": [
"RISK-002",
"RISK-018",
"RISK-021"
]
},
{
"id": "EXP-002",
"name": "RAG with retrieval allowlist and refusal policy",
"modelVersion": "cs-rag-v0.2",
"datasetVersion": "kb-support-2026-07-06",
"promptVersion": "prompt-support-v2",
"status": "completed",
"startedAt": "2026-07-05",
"completedAt": "2026-07-07",
"ownerRole": "ML Engineer",
"metrics": {
"groundedness": 86,
"hallucinationRate": 4.8,
"unsafeAnswerRate": 1.6,
"latencyMs": 1380
},
"decision": "Conditionally accepted for broader testing. Unsafe answer rate and handoff precision still require mitigation.",
"linkedRiskIds": [
"RISK-001",
"RISK-002",
"RISK-003",
"RISK-018"
]
},
{
"id": "EXP-003",
"name": "Escalation classifier tuning",
"modelVersion": "handoff-clf-v0.2",
"datasetVersion": "tickets-escalation-2026-07-02",
"promptVersion": "not_applicable",
"status": "in_progress",
"startedAt": "2026-07-08",
"completedAt": null,
"ownerRole": "Data Scientist",
"metrics": {
"escalationPrecision": 82,
"escalationRecall": 74
},
"decision": "Continue tuning. Precision below gate threshold.",
"linkedRiskIds": [
"RISK-005",
"RISK-011"
]
}
],
"risks": [
{
"id": "RISK-001",
"title": "Prompt injection bypasses customer support chatbot safeguards",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-04",
"ownerRole": "Security Officer",
"likelihood": 4,
"impact": 5,
"uncertainty": 4,
"inherentScore": 64,
"controlEffectiveness": 10,
"residualScore": 58,
"severity": "high",
"status": "open",
"approvalState": "pending",
"gateEffect": "blocked",
"dueDate": "2026-07-18",
"linkedMetricIds": [
"MET-MOD-03"
],
"mitigationIds": [
"MIT-001-01",
"MIT-001-02",
"MIT-001-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-002",
"title": "Hallucinated refund policy gives incorrect customer advice",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-05",
"ownerRole": "Product Owner",
"likelihood": 4,
"impact": 4,
"uncertainty": 3,
"inherentScore": 38,
"controlEffectiveness": 58,
"residualScore": 16,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-07-24",
"linkedMetricIds": [
"MET-MOD-01",
"MET-MOD-02"
],
"mitigationIds": [
"MIT-002-01",
"MIT-002-02",
"MIT-002-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-003",
"title": "Personal data leaks through generated summaries",
"category": "Legal and ethical risks",
"governanceDimension": "Legal and ethical",
"lifecycleStageId": "LC-04",
"ownerRole": "Data Steward",
"likelihood": 3,
"impact": 5,
"uncertainty": 4,
"inherentScore": 48,
"controlEffectiveness": 62,
"residualScore": 18,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending_legal",
"gateEffect": "pass",
"dueDate": "2026-07-20",
"linkedMetricIds": [
"MET-DQ-02"
],
"mitigationIds": [
"MIT-003-01",
"MIT-003-02",
"MIT-003-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-004",
"title": "Bias in response quality across customer segments",
"category": "Legal and ethical risks",
"governanceDimension": "Human",
"lifecycleStageId": "LC-05",
"ownerRole": "Ethics Reviewer",
"likelihood": 3,
"impact": 4,
"uncertainty": 4,
"inherentScore": 38,
"controlEffectiveness": 50,
"residualScore": 19,
"severity": "low",
"status": "open",
"approvalState": "pending_ethics",
"gateEffect": "pass",
"dueDate": "2026-07-28",
"linkedMetricIds": [
"MET-MOD-05"
],
"mitigationIds": [
"MIT-004-01",
"MIT-004-02",
"MIT-004-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-005",
"title": "Human handoff fails for urgent complaints",
"category": "Strategic and organizational risks",
"governanceDimension": "Human",
"lifecycleStageId": "LC-06",
"ownerRole": "Project Manager",
"likelihood": 4,
"impact": 5,
"uncertainty": 4,
"inherentScore": 64,
"controlEffectiveness": 5,
"residualScore": 61,
"severity": "high",
"status": "open",
"approvalState": "pending",
"gateEffect": "blocked",
"dueDate": "2026-08-02",
"linkedMetricIds": [
"MET-MOD-04"
],
"mitigationIds": [
"MIT-005-01",
"MIT-005-02",
"MIT-005-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-006",
"title": "Vendor LLM outage disrupts production support",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-06",
"ownerRole": "MLOps Lead",
"likelihood": 3,
"impact": 4,
"uncertainty": 4,
"inherentScore": 38,
"controlEffectiveness": 55,
"residualScore": 17,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-05",
"linkedMetricIds": [
"MET-OPS-01"
],
"mitigationIds": [
"MIT-006-01",
"MIT-006-02",
"MIT-006-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-007",
"title": "Unclear ownership delays mitigation decisions",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-01",
"ownerRole": "Project Manager",
"likelihood": 3,
"impact": 4,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 65,
"residualScore": 10,
"severity": "low",
"status": "in_mitigation",
"approvalState": "approved",
"gateEffect": "pass",
"dueDate": "2026-07-12",
"linkedMetricIds": [
"MET-GOV-01"
],
"mitigationIds": [
"MIT-007-01",
"MIT-007-02",
"MIT-007-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-008",
"title": "Training data contains outdated product information",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-02",
"ownerRole": "Data Steward",
"likelihood": 4,
"impact": 4,
"uncertainty": 3,
"inherentScore": 38,
"controlEffectiveness": 60,
"residualScore": 15,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-07-17",
"linkedMetricIds": [
"MET-DQ-01",
"MET-MOD-01"
],
"mitigationIds": [
"MIT-008-01",
"MIT-008-02",
"MIT-008-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-009",
"title": "Legal review is incomplete before deployment",
"category": "Legal and ethical risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-05",
"ownerRole": "Legal Reviewer",
"likelihood": 3,
"impact": 5,
"uncertainty": 3,
"inherentScore": 36,
"controlEffectiveness": 35,
"residualScore": 23,
"severity": "low",
"status": "open",
"approvalState": "pending_legal",
"gateEffect": "pass",
"dueDate": "2026-08-01",
"linkedMetricIds": [
"MET-GOV-01"
],
"mitigationIds": [
"MIT-009-01",
"MIT-009-02",
"MIT-009-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-010",
"title": "Model monitoring does not detect quality drift",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-06",
"ownerRole": "MLOps Lead",
"likelihood": 4,
"impact": 5,
"uncertainty": 4,
"inherentScore": 64,
"controlEffectiveness": 20,
"residualScore": 51,
"severity": "high",
"status": "open",
"approvalState": "pending",
"gateEffect": "blocked",
"dueDate": "2026-08-08",
"linkedMetricIds": [
"MET-OPS-02"
],
"mitigationIds": [
"MIT-010-01",
"MIT-010-02",
"MIT-010-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-011",
"title": "Support agents overtrust AI recommendations",
"category": "Legal and ethical risks",
"governanceDimension": "Human",
"lifecycleStageId": "LC-06",
"ownerRole": "Ethics Reviewer",
"likelihood": 3,
"impact": 4,
"uncertainty": 4,
"inherentScore": 38,
"controlEffectiveness": 45,
"residualScore": 21,
"severity": "low",
"status": "open",
"approvalState": "pending_ethics",
"gateEffect": "pass",
"dueDate": "2026-08-07",
"linkedMetricIds": [
"MET-MOD-04"
],
"mitigationIds": [
"MIT-011-01",
"MIT-011-02",
"MIT-011-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-012",
"title": "Cost grows above budget because of token usage",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-06",
"ownerRole": "Project Manager",
"likelihood": 4,
"impact": 3,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 50,
"residualScore": 14,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-04",
"linkedMetricIds": [
"MET-OPS-01"
],
"mitigationIds": [
"MIT-012-01",
"MIT-012-02",
"MIT-012-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-013",
"title": "API integration exposes excessive customer data to model provider",
"category": "Legal and ethical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-04",
"ownerRole": "Security Officer",
"likelihood": 3,
"impact": 5,
"uncertainty": 4,
"inherentScore": 48,
"controlEffectiveness": 55,
"residualScore": 22,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending_security",
"gateEffect": "pass",
"dueDate": "2026-07-22",
"linkedMetricIds": [
"MET-DQ-02"
],
"mitigationIds": [
"MIT-013-01",
"MIT-013-02",
"MIT-013-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-014",
"title": "Evaluation dataset is too small for reliable gate decisions",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-05",
"ownerRole": "Data Scientist",
"likelihood": 3,
"impact": 4,
"uncertainty": 4,
"inherentScore": 38,
"controlEffectiveness": 48,
"residualScore": 20,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-07-26",
"linkedMetricIds": [
"MET-MOD-01",
"MET-MOD-02"
],
"mitigationIds": [
"MIT-014-01",
"MIT-014-02",
"MIT-014-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-015",
"title": "Project scope expands beyond approved AI use cases",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-03",
"ownerRole": "Product Owner",
"likelihood": 3,
"impact": 3,
"uncertainty": 3,
"inherentScore": 22,
"controlEffectiveness": 70,
"residualScore": 7,
"severity": "low",
"status": "controlled",
"approvalState": "approved",
"gateEffect": "pass",
"dueDate": "2026-07-15",
"linkedMetricIds": [
"MET-GOV-01"
],
"mitigationIds": [
"MIT-015-01",
"MIT-015-02",
"MIT-015-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-016",
"title": "Weak audit trail prevents post incident analysis",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-06",
"ownerRole": "Security Officer",
"likelihood": 3,
"impact": 4,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 42,
"residualScore": 17,
"severity": "low",
"status": "open",
"approvalState": "pending_security",
"gateEffect": "pass",
"dueDate": "2026-08-06",
"linkedMetricIds": [
"MET-OPS-02"
],
"mitigationIds": [
"MIT-016-01",
"MIT-016-02",
"MIT-016-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-017",
"title": "Low user adoption reduces business value",
"category": "Strategic and organizational risks",
"governanceDimension": "Human",
"lifecycleStageId": "LC-06",
"ownerRole": "Product Owner",
"likelihood": 3,
"impact": 4,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 52,
"residualScore": 14,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-12",
"linkedMetricIds": [
"MET-GOV-01"
],
"mitigationIds": [
"MIT-017-01",
"MIT-017-02",
"MIT-017-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-018",
"title": "Model gives prohibited advice in regulated contexts",
"category": "Legal and ethical risks",
"governanceDimension": "Legal and ethical",
"lifecycleStageId": "LC-05",
"ownerRole": "Legal Reviewer",
"likelihood": 4,
"impact": 5,
"uncertainty": 4,
"inherentScore": 64,
"controlEffectiveness": 20,
"residualScore": 51,
"severity": "high",
"status": "open",
"approvalState": "pending_legal",
"gateEffect": "blocked",
"dueDate": "2026-07-29",
"linkedMetricIds": [
"MET-MOD-03"
],
"mitigationIds": [
"MIT-018-01",
"MIT-018-02",
"MIT-018-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-019",
"title": "Rollback procedure is not tested before launch",
"category": "Technical risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-06",
"ownerRole": "MLOps Lead",
"likelihood": 3,
"impact": 5,
"uncertainty": 3,
"inherentScore": 36,
"controlEffectiveness": 40,
"residualScore": 22,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-09",
"linkedMetricIds": [
"MET-OPS-02"
],
"mitigationIds": [
"MIT-019-01",
"MIT-019-02",
"MIT-019-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-020",
"title": "Supplier terms conflict with privacy requirements",
"category": "Legal and ethical risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-03",
"ownerRole": "Legal Reviewer",
"likelihood": 2,
"impact": 5,
"uncertainty": 4,
"inherentScore": 32,
"controlEffectiveness": 50,
"residualScore": 16,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending_legal",
"gateEffect": "pass",
"dueDate": "2026-07-19",
"linkedMetricIds": [
"MET-DQ-02"
],
"mitigationIds": [
"MIT-020-01",
"MIT-020-02",
"MIT-020-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-021",
"title": "Knowledge base retrieval returns irrelevant documents",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-04",
"ownerRole": "ML Engineer",
"likelihood": 4,
"impact": 4,
"uncertainty": 3,
"inherentScore": 38,
"controlEffectiveness": 55,
"residualScore": 17,
"severity": "low",
"status": "in_mitigation",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-07-21",
"linkedMetricIds": [
"MET-MOD-01"
],
"mitigationIds": [
"MIT-021-01",
"MIT-021-02",
"MIT-021-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-022",
"title": "Incident response responsibilities are unclear",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-06",
"ownerRole": "Project Manager",
"likelihood": 3,
"impact": 4,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 46,
"residualScore": 16,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-10",
"linkedMetricIds": [
"MET-OPS-02"
],
"mitigationIds": [
"MIT-022-01",
"MIT-022-02",
"MIT-022-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-023",
"title": "Data preparation pipeline is not reproducible",
"category": "Technical risks",
"governanceDimension": "Technical",
"lifecycleStageId": "LC-02",
"ownerRole": "Data Steward",
"likelihood": 3,
"impact": 4,
"uncertainty": 3,
"inherentScore": 29,
"controlEffectiveness": 58,
"residualScore": 12,
"severity": "low",
"status": "in_mitigation",
"approvalState": "approved",
"gateEffect": "pass",
"dueDate": "2026-07-16",
"linkedMetricIds": [
"MET-DQ-01"
],
"mitigationIds": [
"MIT-023-01",
"MIT-023-02",
"MIT-023-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
},
{
"id": "RISK-024",
"title": "Executive sponsor accepts risk without sufficient evidence",
"category": "Strategic and organizational risks",
"governanceDimension": "Organizational",
"lifecycleStageId": "LC-05",
"ownerRole": "Executive Sponsor",
"likelihood": 2,
"impact": 5,
"uncertainty": 4,
"inherentScore": 32,
"controlEffectiveness": 30,
"residualScore": 22,
"severity": "low",
"status": "open",
"approvalState": "pending",
"gateEffect": "pass",
"dueDate": "2026-08-03",
"linkedMetricIds": [
"MET-GOV-01"
],
"mitigationIds": [
"MIT-024-01",
"MIT-024-02",
"MIT-024-03"
],
"interpretationRule": "Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"evidenceRequired": [
"metric_snapshot",
"mitigation_evidence",
"review_decision",
"owner_comment"
],
"createdAt": "2026-06-10",
"updatedAt": "2026-07-08"
}
],
"mitigations": [
{
"id": "MIT-001-01",
"riskId": "RISK-001",
"title": "Add prompt injection test suite",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-18",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-001-02",
"riskId": "RISK-001",
"title": "Implement retrieval allowlist",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-18",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-001-03",
"riskId": "RISK-001",
"title": "Block tool use for untrusted content",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-18",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-002-01",
"riskId": "RISK-002",
"title": "Ground responses in approved policy articles",
"ownerRole": "Product Owner",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-24",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-002-02",
"riskId": "RISK-002",
"title": "Add confidence threshold and fallback",
"ownerRole": "Product Owner",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-24",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-002-03",
"riskId": "RISK-002",
"title": "Create weekly policy drift review",
"ownerRole": "Product Owner",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-24",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-003-01",
"riskId": "RISK-003",
"title": "Mask customer identifiers",
"ownerRole": "Data Steward",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-20",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-003-02",
"riskId": "RISK-003",
"title": "Add output PII scanner",
"ownerRole": "Data Steward",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-20",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-003-03",
"riskId": "RISK-003",
"title": "Store redacted logs only",
"ownerRole": "Data Steward",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-20",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-004-01",
"riskId": "RISK-004",
"title": "Define segment fairness tests",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-28",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-004-02",
"riskId": "RISK-004",
"title": "Review low quality clusters",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-28",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-004-03",
"riskId": "RISK-004",
"title": "Add human review for sensitive cases",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-28",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-005-01",
"riskId": "RISK-005",
"title": "Improve escalation classifier",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-02",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-005-02",
"riskId": "RISK-005",
"title": "Add manual escalation button",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-02",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-005-03",
"riskId": "RISK-005",
"title": "Test urgent complaint workflow",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-02",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-006-01",
"riskId": "RISK-006",
"title": "Configure secondary model provider",
"ownerRole": "MLOps Lead",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-08-05",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-006-02",
"riskId": "RISK-006",
"title": "Cache approved answers",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-05",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-006-03",
"riskId": "RISK-006",
"title": "Create outage runbook",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-05",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-007-01",
"riskId": "RISK-007",
"title": "Assign accountable risk owners",
"ownerRole": "Project Manager",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-007-02",
"riskId": "RISK-007",
"title": "Create weekly risk review cadence",
"ownerRole": "Project Manager",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-007-03",
"riskId": "RISK-007",
"title": "Document escalation authority",
"ownerRole": "Project Manager",
"status": "in_progress",
"completionPercent": 45,
"dueDate": "2026-07-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-008-01",
"riskId": "RISK-008",
"title": "Add source freshness checks",
"ownerRole": "Data Steward",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-17",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-008-02",
"riskId": "RISK-008",
"title": "Version approved knowledge base",
"ownerRole": "Data Steward",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-17",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-008-03",
"riskId": "RISK-008",
"title": "Retire expired articles",
"ownerRole": "Data Steward",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-17",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-009-01",
"riskId": "RISK-009",
"title": "Complete legal review checklist",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-01",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-009-02",
"riskId": "RISK-009",
"title": "Record approved use boundaries",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-01",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-009-03",
"riskId": "RISK-009",
"title": "Block deployment until signoff",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-01",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-010-01",
"riskId": "RISK-010",
"title": "Create drift dashboard",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-08",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-010-02",
"riskId": "RISK-010",
"title": "Add alert thresholds",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-08",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-010-03",
"riskId": "RISK-010",
"title": "Schedule weekly evaluation jobs",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-08",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-011-01",
"riskId": "RISK-011",
"title": "Add confidence explanations",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-07",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-011-02",
"riskId": "RISK-011",
"title": "Train agents on AI limitations",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-07",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-011-03",
"riskId": "RISK-011",
"title": "Require human confirmation for exceptions",
"ownerRole": "Ethics Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-07",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-012-01",
"riskId": "RISK-012",
"title": "Set token budget alerts",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-04",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-012-02",
"riskId": "RISK-012",
"title": "Shorten retrieved context",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-04",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-012-03",
"riskId": "RISK-012",
"title": "Route simple intents to rules",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-04",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-013-01",
"riskId": "RISK-013",
"title": "Minimize payload fields",
"ownerRole": "Security Officer",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-22",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-013-02",
"riskId": "RISK-013",
"title": "Encrypt transit and storage",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-22",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-013-03",
"riskId": "RISK-013",
"title": "Review vendor data processing terms",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-22",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-014-01",
"riskId": "RISK-014",
"title": "Increase test set coverage",
"ownerRole": "Data Scientist",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-26",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-014-02",
"riskId": "RISK-014",
"title": "Add adversarial examples",
"ownerRole": "Data Scientist",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-26",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-014-03",
"riskId": "RISK-014",
"title": "Track confidence intervals",
"ownerRole": "Data Scientist",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-26",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-015-01",
"riskId": "RISK-015",
"title": "Lock initial scope",
"ownerRole": "Product Owner",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-15",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-015-02",
"riskId": "RISK-015",
"title": "Route new use cases to backlog",
"ownerRole": "Product Owner",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-15",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-015-03",
"riskId": "RISK-015",
"title": "Review scope changes in steering committee",
"ownerRole": "Product Owner",
"status": "in_progress",
"completionPercent": 45,
"dueDate": "2026-07-15",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-016-01",
"riskId": "RISK-016",
"title": "Log prompts and responses with redaction",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-06",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-016-02",
"riskId": "RISK-016",
"title": "Link incidents to model versions",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-06",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-016-03",
"riskId": "RISK-016",
"title": "Retain approval history",
"ownerRole": "Security Officer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-06",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-017-01",
"riskId": "RISK-017",
"title": "Pilot with support team leads",
"ownerRole": "Product Owner",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-017-02",
"riskId": "RISK-017",
"title": "Collect agent feedback",
"ownerRole": "Product Owner",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-017-03",
"riskId": "RISK-017",
"title": "Add adoption KPI to dashboard",
"ownerRole": "Product Owner",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-12",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-018-01",
"riskId": "RISK-018",
"title": "Block regulated topics",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-29",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-018-02",
"riskId": "RISK-018",
"title": "Add legal disclaimer templates",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-29",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-018-03",
"riskId": "RISK-018",
"title": "Escalate regulated requests to human team",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-29",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-019-01",
"riskId": "RISK-019",
"title": "Create rollback checklist",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-09",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-019-02",
"riskId": "RISK-019",
"title": "Run staging rollback drill",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-09",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-019-03",
"riskId": "RISK-019",
"title": "Assign rollback approver",
"ownerRole": "MLOps Lead",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-09",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-020-01",
"riskId": "RISK-020",
"title": "Review DPA",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-19",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-020-02",
"riskId": "RISK-020",
"title": "Document data residency",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-19",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-020-03",
"riskId": "RISK-020",
"title": "Restrict provider data retention",
"ownerRole": "Legal Reviewer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-19",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-021-01",
"riskId": "RISK-021",
"title": "Improve chunking strategy",
"ownerRole": "ML Engineer",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-21",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-021-02",
"riskId": "RISK-021",
"title": "Add retrieval relevance tests",
"ownerRole": "ML Engineer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-21",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-021-03",
"riskId": "RISK-021",
"title": "Review top failed queries",
"ownerRole": "ML Engineer",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-07-21",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-022-01",
"riskId": "RISK-022",
"title": "Define incident RACI",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-10",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-022-02",
"riskId": "RISK-022",
"title": "Create severity matrix",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-10",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-022-03",
"riskId": "RISK-022",
"title": "Run tabletop exercise",
"ownerRole": "Project Manager",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-10",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-023-01",
"riskId": "RISK-023",
"title": "Version data transformation scripts",
"ownerRole": "Data Steward",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-16",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-023-02",
"riskId": "RISK-023",
"title": "Record dataset hashes",
"ownerRole": "Data Steward",
"status": "completed",
"completionPercent": 100,
"dueDate": "2026-07-16",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-023-03",
"riskId": "RISK-023",
"title": "Automate pipeline checks",
"ownerRole": "Data Steward",
"status": "in_progress",
"completionPercent": 45,
"dueDate": "2026-07-16",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-024-01",
"riskId": "RISK-024",
"title": "Require evidence package",
"ownerRole": "Executive Sponsor",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-03",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-024-02",
"riskId": "RISK-024",
"title": "Add risk acceptance template",
"ownerRole": "Executive Sponsor",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-03",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
},
{
"id": "MIT-024-03",
"riskId": "RISK-024",
"title": "Record acceptance expiration date",
"ownerRole": "Executive Sponsor",
"status": "planned",
"completionPercent": 0,
"dueDate": "2026-08-03",
"evidence": [],
"verificationMethod": "Owner evidence review and metric retest",
"updatedAt": "2026-07-08"
}
],
"gates": [
{
"id": "GATE-01",
"name": "Needs approval gate",
"lifecycleStageFrom": "LC-01",
"lifecycleStageTo": "LC-02",
"status": "passed",
"decisionDate": "2026-06-07",
"criteria": [
{
"name": "Business objective approved",
"status": "pass"
},
{
"name": "Initial AI suitability reviewed",
"status": "pass"
},
{
"name": "Initial risk scan created",
"status": "pass"
}
],
"approvers": [
"Project Manager",
"Executive Sponsor"
]
},
{
"id": "GATE-02",
"name": "Data readiness gate",
"lifecycleStageFrom": "LC-02",
"lifecycleStageTo": "LC-03",
"status": "passed",
"decisionDate": "2026-06-21",
"criteria": [
{
"name": "Data completeness >= 90",
"status": "pass",
"metricId": "MET-DQ-01"
},
{
"name": "PII exposure rate <= 0.5",
"status": "pass",
"metricId": "MET-DQ-02"
},
{
"name": "Data steward approval",
"status": "pass"
}
],
"approvers": [
"Data Steward",
"Security Officer"
]
},
{
"id": "GATE-03",
"name": "Design approval gate",
"lifecycleStageFrom": "LC-03",
"lifecycleStageTo": "LC-04",
"status": "passed",
"decisionDate": "2026-07-02",
"criteria": [
{
"name": "Architecture approved",
"status": "pass"
},
{
"name": "Human fallback workflow defined",
"status": "pass"
},
{
"name": "Supplier and privacy review started",
"status": "pass"
}
],
"approvers": [
"Solution Architect",
"Project Manager",
"Security Officer"
]
},
{
"id": "GATE-04",
"name": "Model evaluation gate",
"lifecycleStageFrom": "LC-04",
"lifecycleStageTo": "LC-05",
"status": "conditional_pass",
"decisionDate": "2026-07-08",
"criteria": [
{
"name": "Groundedness >= 85",
"status": "pass",
"metricId": "MET-MOD-01"
},
{
"name": "Hallucination rate <= 5",
"status": "pass",
"metricId": "MET-MOD-02"
},
{
"name": "Unsafe answer rate <= 1",
"status": "watch",
"metricId": "MET-MOD-03"
},
{
"name": "Escalation precision >= 88",
"status": "fail",
"metricId": "MET-MOD-04"
}
],
"approvers": [
"ML Engineer",
"Ethics Reviewer",
"Product Owner"
],
"conditions": [
"Complete handoff mitigation",
"Retest unsafe answer rate",
"Attach ethics review evidence"
]
},
{
"id": "GATE-05",
"name": "Deployment readiness gate",
"lifecycleStageFrom": "LC-05",
"lifecycleStageTo": "LC-06",
"status": "blocked",
"decisionDate": null,
"criteria": [
{
"name": "No unaccepted high residual risks",
"status": "fail",
"blockedRiskIds": [
"RISK-001",
"RISK-005",
"RISK-010",
"RISK-018"
]
},
{
"name": "Mitigation completeness >= 80",
"status": "watch",
"metricId": "MET-GOV-01"
},
{
"name": "Monitoring coverage >= 90",
"status": "fail",
"metricId": "MET-OPS-02"
},
{
"name": "Legal review complete",
"status": "pending"
},
{
"name": "Ethical review complete",
"status": "pending"
},
{
"name": "Rollback drill complete",
"status": "pending"
}
],
"approvers": [
"Executive Sponsor",
"Legal Reviewer",
"Ethics Reviewer",
"MLOps Lead"
],
"conditions": [
"Resolve or formally accept high residual risks",
"Reach monitoring coverage target",
"Complete legal and ethical approvals",
"Complete rollback drill"
]
}
],
"supplierAndPartnerManagement": [
{
"id": "SUP-001",
"name": "Primary LLM provider",
"riskLevel": "medium",
"reviewStatus": "legal_review_in_progress",
"controls": [
"Data processing agreement",
"No training on customer data",
"Regional data processing option"
]
},
{
"id": "SUP-002",
"name": "Fallback LLM provider",
"riskLevel": "medium",
"reviewStatus": "planned",
"controls": [
"Outage fallback",
"Restricted payload",
"Contract review"
]
}
],
"humanResourceTracking": [
{
"role": "Support Agent Pilot Group",
"requiredTraining": "AI limitation and escalation training",
"trainingStatus": "planned",
"targetDate": "2026-08-06"
},
{
"role": "Quality Assurance Reviewer",
"requiredTraining": "AI output review rubric",
"trainingStatus": "in_progress",
"targetDate": "2026-07-26"
}
],
"fundingAndFinancialTracking": {
"budgetCurrency": "CAD",
"approvedBudget": 85000,
"spentToDate": 31500,
"forecastAtCompletion": 91000,
"budgetRiskStatus": "watch",
"costDrivers": [
"LLM token consumption",
"QA review effort",
"Security testing",
"Monitoring infrastructure"
]
},
"legalScientificTechnologicalWatch": [
{
"id": "WATCH-001",
"topic": "Privacy and data processing requirements",
"ownerRole": "Legal Reviewer",
"cadence": "monthly",
"lastReviewed": "2026-07-01",
"status": "active"
},
{
"id": "WATCH-002",
"topic": "Prompt injection and RAG security practices",
"ownerRole": "Security Officer",
"cadence": "biweekly",
"lastReviewed": "2026-07-08",
"status": "active"
},
{
"id": "WATCH-003",
"topic": "Model evaluation and hallucination detection",
"ownerRole": "Data Scientist",
"cadence": "biweekly",
"lastReviewed": "2026-07-08",
"status": "active"
}
],
"cosmicFunctionalSizeTracking": {
"status": "placeholder_for_future_measurement",
"notes": "Functional size tracking can be connected to COSMIC measurement once the software functional user requirements are finalized.",
"candidateFunctionalProcesses": [
"Create AI risk",
"Update mitigation status",
"Submit metric value",
"Evaluate gate",
"Sync Trello card",
"Generate executive report"
]
},
"dashboardSummary": {
"projectResidualRiskScore": 23,
"riskCounts": {
"low": 20,
"medium": 0,
"high": 4
},
"blockedRiskIds": [
"RISK-001",
"RISK-005",
"RISK-010",
"RISK-018"
],
"watchRiskIds": [],
"deploymentGateStatus": "blocked",
"mitigationCompletenessPercent": 68,
"monitoringCoveragePercent": 76,
"nextActions": [
"Resolve prompt injection and urgent handoff risks",
"Complete legal, ethical, and security approvals",
"Raise monitoring coverage to at least 90 percent",
"Run rollback drill before deployment gate"
]
},
"trelloBoard": {
"boardName": "COSMIC AI-Risk Management - SupportGenAI",
"workspace": "COSMIC AI-Risk Management",
"lists": [
{
"id": "LIST-01",
"name": "1 Needs and Scope",
"lifecycleStageId": "LC-01"
},
{
"id": "LIST-02",
"name": "2 Data Readiness",
"lifecycleStageId": "LC-02"
},
{
"id": "LIST-03",
"name": "3 Design and Controls",
"lifecycleStageId": "LC-03"
},
{
"id": "LIST-04",
"name": "4 Experiments and Model Development",
"lifecycleStageId": "LC-04"
},
{
"id": "LIST-05",
"name": "5 Testing and Evaluation",
"lifecycleStageId": "LC-05"
},
{
"id": "LIST-06",
"name": "6 Deployment and Monitoring",
"lifecycleStageId": "LC-06"
},
{
"id": "LIST-07",
"name": "Risk Review",
"lifecycleStageId": null
},
{
"id": "LIST-08",
"name": "Done",
"lifecycleStageId": null
}
],
"labels": [
{
"name": "Strategic and organizational risks",
"color": "orange"
},
{
"name": "Technical risks",
"color": "red"
},
{
"name": "Legal and ethical risks",
"color": "purple"
},
{
"name": "High",
"color": "red"
},
{
"name": "Medium",
"color": "yellow"
},
{
"name": "Low",
"color": "green"
},
{
"name": "Gate blocked",
"color": "black"
},
{
"name": "Needs approval",
"color": "blue"
},
{
"name": "Mitigation",
"color": "sky"
}
],
"customFields": [
{
"name": "Risk ID",
"type": "text"
},
{
"name": "Category",
"type": "list",
"options": [
"Strategic and organizational risks",
"Technical risks",
"Legal and ethical risks"
]
},
{
"name": "Governance Dimension",
"type": "list",
"options": [
"Organizational",
"Technical",
"Human",
"Legal and ethical"
]
},
{
"name": "Likelihood",
"type": "number"
},
{
"name": "Impact",
"type": "number"
},
{
"name": "Uncertainty",
"type": "number"
},
{
"name": "Residual Score",
"type": "number"
},
{
"name": "Severity",
"type": "list",
"options": [
"low",
"medium",
"high"
]
},
{
"name": "Approval State",
"type": "list",
"options": [
"pending",
"pending_legal",
"pending_ethics",
"pending_security",
"approved",
"accepted"
]
},
{
"name": "Gate Effect",
"type": "list",
"options": [
"pass",
"watch",
"blocked"
]
}
],
"cards": [
{
"id": "CARD-RISK-001",
"name": "Prompt injection bypasses customer support chatbot safeguards",
"list": "4 Experiments and Model Development",
"due": "2026-07-18",
"labels": [
"Technical risks",
"High",
"Gate blocked",
"Needs approval"
],
"members": [
"Security Officer"
],
"customFields": {
"Risk ID": "RISK-001",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 4,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 64,
"Control Effectiveness": 10,
"Residual Score": 58,
"Severity": "high",
"Approval State": "pending",
"Gate Effect": "blocked"
},
"description": "Risk RISK-001. Residual score 58/100. Gate effect: blocked. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Add prompt injection test suite",
"checked": false
},
{
"name": "Implement retrieval allowlist",
"checked": false
},
{
"name": "Block tool use for untrusted content",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-002",
"name": "Hallucinated refund policy gives incorrect customer advice",
"list": "5 Testing and Evaluation",
"due": "2026-07-24",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"Product Owner"
],
"customFields": {
"Risk ID": "RISK-002",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 4,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 38,
"Control Effectiveness": 58,
"Residual Score": 16,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-002. Residual score 16/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Ground responses in approved policy articles",
"checked": true
},
{
"name": "Add confidence threshold and fallback",
"checked": false
},
{
"name": "Create weekly policy drift review",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-003",
"name": "Personal data leaks through generated summaries",
"list": "4 Experiments and Model Development",
"due": "2026-07-20",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Data Steward"
],
"customFields": {
"Risk ID": "RISK-003",
"Category": "Legal and ethical risks",
"Governance Dimension": "Legal and ethical",
"Likelihood": 3,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 48,
"Control Effectiveness": 62,
"Residual Score": 18,
"Severity": "low",
"Approval State": "pending_legal",
"Gate Effect": "pass"
},
"description": "Risk RISK-003. Residual score 18/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Mask customer identifiers",
"checked": true
},
{
"name": "Add output PII scanner",
"checked": false
},
{
"name": "Store redacted logs only",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-004",
"name": "Bias in response quality across customer segments",
"list": "5 Testing and Evaluation",
"due": "2026-07-28",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Ethics Reviewer"
],
"customFields": {
"Risk ID": "RISK-004",
"Category": "Legal and ethical risks",
"Governance Dimension": "Human",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 4,
"Inherent Score": 38,
"Control Effectiveness": 50,
"Residual Score": 19,
"Severity": "low",
"Approval State": "pending_ethics",
"Gate Effect": "pass"
},
"description": "Risk RISK-004. Residual score 19/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Define segment fairness tests",
"checked": false
},
{
"name": "Review low quality clusters",
"checked": false
},
{
"name": "Add human review for sensitive cases",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-005",
"name": "Human handoff fails for urgent complaints",
"list": "6 Deployment and Monitoring",
"due": "2026-08-02",
"labels": [
"Strategic and organizational risks",
"High",
"Gate blocked",
"Needs approval"
],
"members": [
"Project Manager"
],
"customFields": {
"Risk ID": "RISK-005",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Human",
"Likelihood": 4,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 64,
"Control Effectiveness": 5,
"Residual Score": 61,
"Severity": "high",
"Approval State": "pending",
"Gate Effect": "blocked"
},
"description": "Risk RISK-005. Residual score 61/100. Gate effect: blocked. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Improve escalation classifier",
"checked": false
},
{
"name": "Add manual escalation button",
"checked": false
},
{
"name": "Test urgent complaint workflow",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-006",
"name": "Vendor LLM outage disrupts production support",
"list": "6 Deployment and Monitoring",
"due": "2026-08-05",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"MLOps Lead"
],
"customFields": {
"Risk ID": "RISK-006",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 4,
"Inherent Score": 38,
"Control Effectiveness": 55,
"Residual Score": 17,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-006. Residual score 17/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Configure secondary model provider",
"checked": true
},
{
"name": "Cache approved answers",
"checked": false
},
{
"name": "Create outage runbook",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-007",
"name": "Unclear ownership delays mitigation decisions",
"list": "1 Needs and Scope",
"due": "2026-07-12",
"labels": [
"Strategic and organizational risks",
"Low"
],
"members": [
"Project Manager"
],
"customFields": {
"Risk ID": "RISK-007",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 65,
"Residual Score": 10,
"Severity": "low",
"Approval State": "approved",
"Gate Effect": "pass"
},
"description": "Risk RISK-007. Residual score 10/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Assign accountable risk owners",
"checked": true
},
{
"name": "Create weekly risk review cadence",
"checked": true
},
{
"name": "Document escalation authority",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-008",
"name": "Training data contains outdated product information",
"list": "2 Data Readiness",
"due": "2026-07-17",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"Data Steward"
],
"customFields": {
"Risk ID": "RISK-008",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 4,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 38,
"Control Effectiveness": 60,
"Residual Score": 15,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-008. Residual score 15/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Add source freshness checks",
"checked": true
},
{
"name": "Version approved knowledge base",
"checked": false
},
{
"name": "Retire expired articles",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-009",
"name": "Legal review is incomplete before deployment",
"list": "5 Testing and Evaluation",
"due": "2026-08-01",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Legal Reviewer"
],
"customFields": {
"Risk ID": "RISK-009",
"Category": "Legal and ethical risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 5,
"Uncertainty": 3,
"Inherent Score": 36,
"Control Effectiveness": 35,
"Residual Score": 23,
"Severity": "low",
"Approval State": "pending_legal",
"Gate Effect": "pass"
},
"description": "Risk RISK-009. Residual score 23/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Complete legal review checklist",
"checked": false
},
{
"name": "Record approved use boundaries",
"checked": false
},
{
"name": "Block deployment until signoff",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-010",
"name": "Model monitoring does not detect quality drift",
"list": "6 Deployment and Monitoring",
"due": "2026-08-08",
"labels": [
"Technical risks",
"High",
"Gate blocked",
"Needs approval"
],
"members": [
"MLOps Lead"
],
"customFields": {
"Risk ID": "RISK-010",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 4,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 64,
"Control Effectiveness": 20,
"Residual Score": 51,
"Severity": "high",
"Approval State": "pending",
"Gate Effect": "blocked"
},
"description": "Risk RISK-010. Residual score 51/100. Gate effect: blocked. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Create drift dashboard",
"checked": false
},
{
"name": "Add alert thresholds",
"checked": false
},
{
"name": "Schedule weekly evaluation jobs",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-011",
"name": "Support agents overtrust AI recommendations",
"list": "6 Deployment and Monitoring",
"due": "2026-08-07",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Ethics Reviewer"
],
"customFields": {
"Risk ID": "RISK-011",
"Category": "Legal and ethical risks",
"Governance Dimension": "Human",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 4,
"Inherent Score": 38,
"Control Effectiveness": 45,
"Residual Score": 21,
"Severity": "low",
"Approval State": "pending_ethics",
"Gate Effect": "pass"
},
"description": "Risk RISK-011. Residual score 21/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Add confidence explanations",
"checked": false
},
{
"name": "Train agents on AI limitations",
"checked": false
},
{
"name": "Require human confirmation for exceptions",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-012",
"name": "Cost grows above budget because of token usage",
"list": "6 Deployment and Monitoring",
"due": "2026-08-04",
"labels": [
"Strategic and organizational risks",
"Low",
"Needs approval"
],
"members": [
"Project Manager"
],
"customFields": {
"Risk ID": "RISK-012",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 4,
"Impact": 3,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 50,
"Residual Score": 14,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-012. Residual score 14/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Set token budget alerts",
"checked": false
},
{
"name": "Shorten retrieved context",
"checked": false
},
{
"name": "Route simple intents to rules",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-013",
"name": "API integration exposes excessive customer data to model provider",
"list": "4 Experiments and Model Development",
"due": "2026-07-22",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Security Officer"
],
"customFields": {
"Risk ID": "RISK-013",
"Category": "Legal and ethical risks",
"Governance Dimension": "Technical",
"Likelihood": 3,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 48,
"Control Effectiveness": 55,
"Residual Score": 22,
"Severity": "low",
"Approval State": "pending_security",
"Gate Effect": "pass"
},
"description": "Risk RISK-013. Residual score 22/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Minimize payload fields",
"checked": true
},
{
"name": "Encrypt transit and storage",
"checked": false
},
{
"name": "Review vendor data processing terms",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-014",
"name": "Evaluation dataset is too small for reliable gate decisions",
"list": "5 Testing and Evaluation",
"due": "2026-07-26",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"Data Scientist"
],
"customFields": {
"Risk ID": "RISK-014",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 4,
"Inherent Score": 38,
"Control Effectiveness": 48,
"Residual Score": 20,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-014. Residual score 20/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Increase test set coverage",
"checked": false
},
{
"name": "Add adversarial examples",
"checked": false
},
{
"name": "Track confidence intervals",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-015",
"name": "Project scope expands beyond approved AI use cases",
"list": "3 Design and Controls",
"due": "2026-07-15",
"labels": [
"Strategic and organizational risks",
"Low"
],
"members": [
"Product Owner"
],
"customFields": {
"Risk ID": "RISK-015",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 3,
"Uncertainty": 3,
"Inherent Score": 22,
"Control Effectiveness": 70,
"Residual Score": 7,
"Severity": "low",
"Approval State": "approved",
"Gate Effect": "pass"
},
"description": "Risk RISK-015. Residual score 7/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Lock initial scope",
"checked": true
},
{
"name": "Route new use cases to backlog",
"checked": true
},
{
"name": "Review scope changes in steering committee",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-016",
"name": "Weak audit trail prevents post incident analysis",
"list": "6 Deployment and Monitoring",
"due": "2026-08-06",
"labels": [
"Strategic and organizational risks",
"Low",
"Needs approval"
],
"members": [
"Security Officer"
],
"customFields": {
"Risk ID": "RISK-016",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 42,
"Residual Score": 17,
"Severity": "low",
"Approval State": "pending_security",
"Gate Effect": "pass"
},
"description": "Risk RISK-016. Residual score 17/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Log prompts and responses with redaction",
"checked": false
},
{
"name": "Link incidents to model versions",
"checked": false
},
{
"name": "Retain approval history",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-017",
"name": "Low user adoption reduces business value",
"list": "6 Deployment and Monitoring",
"due": "2026-08-12",
"labels": [
"Strategic and organizational risks",
"Low",
"Needs approval"
],
"members": [
"Product Owner"
],
"customFields": {
"Risk ID": "RISK-017",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Human",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 52,
"Residual Score": 14,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-017. Residual score 14/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Pilot with support team leads",
"checked": false
},
{
"name": "Collect agent feedback",
"checked": false
},
{
"name": "Add adoption KPI to dashboard",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-018",
"name": "Model gives prohibited advice in regulated contexts",
"list": "5 Testing and Evaluation",
"due": "2026-07-29",
"labels": [
"Legal and ethical risks",
"High",
"Gate blocked",
"Needs approval"
],
"members": [
"Legal Reviewer"
],
"customFields": {
"Risk ID": "RISK-018",
"Category": "Legal and ethical risks",
"Governance Dimension": "Legal and ethical",
"Likelihood": 4,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 64,
"Control Effectiveness": 20,
"Residual Score": 51,
"Severity": "high",
"Approval State": "pending_legal",
"Gate Effect": "blocked"
},
"description": "Risk RISK-018. Residual score 51/100. Gate effect: blocked. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Block regulated topics",
"checked": false
},
{
"name": "Add legal disclaimer templates",
"checked": false
},
{
"name": "Escalate regulated requests to human team",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-019",
"name": "Rollback procedure is not tested before launch",
"list": "6 Deployment and Monitoring",
"due": "2026-08-09",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"MLOps Lead"
],
"customFields": {
"Risk ID": "RISK-019",
"Category": "Technical risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 5,
"Uncertainty": 3,
"Inherent Score": 36,
"Control Effectiveness": 40,
"Residual Score": 22,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-019. Residual score 22/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Create rollback checklist",
"checked": false
},
{
"name": "Run staging rollback drill",
"checked": false
},
{
"name": "Assign rollback approver",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-020",
"name": "Supplier terms conflict with privacy requirements",
"list": "3 Design and Controls",
"due": "2026-07-19",
"labels": [
"Legal and ethical risks",
"Low",
"Needs approval"
],
"members": [
"Legal Reviewer"
],
"customFields": {
"Risk ID": "RISK-020",
"Category": "Legal and ethical risks",
"Governance Dimension": "Organizational",
"Likelihood": 2,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 32,
"Control Effectiveness": 50,
"Residual Score": 16,
"Severity": "low",
"Approval State": "pending_legal",
"Gate Effect": "pass"
},
"description": "Risk RISK-020. Residual score 16/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Review DPA",
"checked": false
},
{
"name": "Document data residency",
"checked": false
},
{
"name": "Restrict provider data retention",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-021",
"name": "Knowledge base retrieval returns irrelevant documents",
"list": "4 Experiments and Model Development",
"due": "2026-07-21",
"labels": [
"Technical risks",
"Low",
"Needs approval"
],
"members": [
"ML Engineer"
],
"customFields": {
"Risk ID": "RISK-021",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 4,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 38,
"Control Effectiveness": 55,
"Residual Score": 17,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-021. Residual score 17/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Improve chunking strategy",
"checked": true
},
{
"name": "Add retrieval relevance tests",
"checked": false
},
{
"name": "Review top failed queries",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-022",
"name": "Incident response responsibilities are unclear",
"list": "6 Deployment and Monitoring",
"due": "2026-08-10",
"labels": [
"Strategic and organizational risks",
"Low",
"Needs approval"
],
"members": [
"Project Manager"
],
"customFields": {
"Risk ID": "RISK-022",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 46,
"Residual Score": 16,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-022. Residual score 16/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Define incident RACI",
"checked": false
},
{
"name": "Create severity matrix",
"checked": false
},
{
"name": "Run tabletop exercise",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-023",
"name": "Data preparation pipeline is not reproducible",
"list": "2 Data Readiness",
"due": "2026-07-16",
"labels": [
"Technical risks",
"Low"
],
"members": [
"Data Steward"
],
"customFields": {
"Risk ID": "RISK-023",
"Category": "Technical risks",
"Governance Dimension": "Technical",
"Likelihood": 3,
"Impact": 4,
"Uncertainty": 3,
"Inherent Score": 29,
"Control Effectiveness": 58,
"Residual Score": 12,
"Severity": "low",
"Approval State": "approved",
"Gate Effect": "pass"
},
"description": "Risk RISK-023. Residual score 12/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Version data transformation scripts",
"checked": true
},
{
"name": "Record dataset hashes",
"checked": true
},
{
"name": "Automate pipeline checks",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-RISK-024",
"name": "Executive sponsor accepts risk without sufficient evidence",
"list": "5 Testing and Evaluation",
"due": "2026-08-03",
"labels": [
"Strategic and organizational risks",
"Low",
"Needs approval"
],
"members": [
"Executive Sponsor"
],
"customFields": {
"Risk ID": "RISK-024",
"Category": "Strategic and organizational risks",
"Governance Dimension": "Organizational",
"Likelihood": 2,
"Impact": 5,
"Uncertainty": 4,
"Inherent Score": 32,
"Control Effectiveness": 30,
"Residual Score": 22,
"Severity": "low",
"Approval State": "pending",
"Gate Effect": "pass"
},
"description": "Risk RISK-024. Residual score 22/100. Gate effect: pass. Interpretation: Deployment is blocked when residualScore is 50 or higher unless residual risk is formally accepted by the Executive Sponsor and the required legal, ethical, and security reviews are complete.",
"checklists": [
{
"name": "Mitigations",
"items": [
{
"name": "Require evidence package",
"checked": false
},
{
"name": "Add risk acceptance template",
"checked": false
},
{
"name": "Record acceptance expiration date",
"checked": false
}
]
}
],
"comments": [
{
"authorRole": "Project Manager",
"createdAt": "2026-07-08",
"text": "Review residual score and mitigation evidence before the next gate decision."
}
]
},
{
"id": "CARD-LC-01-DELIVERABLES",
"name": "Identification and analysis of needs deliverables",
"list": "1 Needs and Scope",
"due": "2026-06-07",
"labels": [
"Low"
],
"members": [
"Project Manager"
],
"customFields": {
"Lifecycle Stage": "LC-01",
"Status": "completed"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Problem statement approved",
"checked": true
},
{
"name": "Expected value documented",
"checked": true
},
{
"name": "Initial risk scan completed",
"checked": true
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Project charter",
"checked": true
},
{
"name": "Business objectives",
"checked": true
},
{
"name": "Initial AI risk assessment",
"checked": true
}
]
}
],
"comments": []
},
{
"id": "CARD-LC-02-DELIVERABLES",
"name": "Data collection and preparation deliverables",
"list": "2 Data Readiness",
"due": "2026-06-21",
"labels": [
"Low"
],
"members": [
"Data Steward"
],
"customFields": {
"Lifecycle Stage": "LC-02",
"Status": "completed"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Data quality score at least 80",
"checked": true
},
{
"name": "PII handling approved",
"checked": true
},
{
"name": "Dataset version frozen for baseline",
"checked": true
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Data inventory",
"checked": true
},
{
"name": "Data quality report",
"checked": true
},
{
"name": "PII treatment log",
"checked": true
}
]
}
],
"comments": []
},
{
"id": "CARD-LC-03-DELIVERABLES",
"name": "Design deliverables",
"list": "3 Design and Controls",
"due": "2026-07-02",
"labels": [
"Low"
],
"members": [
"Solution Architect"
],
"customFields": {
"Lifecycle Stage": "LC-03",
"Status": "completed"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Architecture approved",
"checked": true
},
{
"name": "Prompt strategy documented",
"checked": true
},
{
"name": "Human fallback workflow approved",
"checked": true
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Solution architecture",
"checked": true
},
{
"name": "Prompt design specification",
"checked": true
},
{
"name": "Risk control design",
"checked": true
}
]
}
],
"comments": []
},
{
"id": "CARD-LC-04-DELIVERABLES",
"name": "AI model development and training deliverables",
"list": "4 Experiments and Model Development",
"due": "2026-07-22",
"labels": [
"Mitigation"
],
"members": [
"ML Engineer"
],
"customFields": {
"Lifecycle Stage": "LC-04",
"Status": "in_progress"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Baseline experiment completed",
"checked": false
},
{
"name": "Safety controls tested",
"checked": false
},
{
"name": "Model card drafted",
"checked": false
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Experiment logs",
"checked": false
},
{
"name": "Model card",
"checked": false
},
{
"name": "Prompt registry",
"checked": false
},
{
"name": "Evaluation report",
"checked": false
}
]
}
],
"comments": []
},
{
"id": "CARD-LC-05-DELIVERABLES",
"name": "Testing and performance evaluation deliverables",
"list": "5 Testing and Evaluation",
"due": "2026-08-09",
"labels": [
"Mitigation"
],
"members": [
"QA Lead"
],
"customFields": {
"Lifecycle Stage": "LC-05",
"Status": "planned"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Performance thresholds met",
"checked": false
},
{
"name": "Ethical review completed",
"checked": false
},
{
"name": "Legal review completed",
"checked": false
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Test report",
"checked": false
},
{
"name": "Red team report",
"checked": false
},
{
"name": "Bias evaluation",
"checked": false
},
{
"name": "Legal and ethical review evidence",
"checked": false
}
]
}
],
"comments": []
},
{
"id": "CARD-LC-06-DELIVERABLES",
"name": "Deployment, support, and monitoring deliverables",
"list": "6 Deployment and Monitoring",
"due": "2026-09-15",
"labels": [
"Mitigation"
],
"members": [
"MLOps Lead"
],
"customFields": {
"Lifecycle Stage": "LC-06",
"Status": "planned"
},
"description": "Track stage deliverables and exit criteria.",
"checklists": [
{
"name": "Exit criteria",
"items": [
{
"name": "Production monitoring active",
"checked": false
},
{
"name": "Incident playbook tested",
"checked": false
},
{
"name": "Post deployment review completed",
"checked": false
}
]
},
{
"name": "Deliverables",
"items": [
{
"name": "Deployment checklist",
"checked": false
},
{
"name": "Monitoring dashboard",
"checked": false
},
{
"name": "Incident response log",
"checked": false
},
{
"name": "Continuous improvement backlog",
"checked": false
}
]
}
],
"comments": []
}
]
},
"apiSeed": {
"basePath": "/api/v1",
"endpoints": [
{
"method": "POST",
"path": "/projects",
"purpose": "Create AI project"
},
{
"method": "GET",
"path": "/projects/{projectId}",
"purpose": "Read AI project"
},
{
"method": "POST",
"path": "/projects/{projectId}/risks",
"purpose": "Create risk"
},
{
"method": "PATCH",
"path": "/risks/{riskId}",
"purpose": "Update risk status and scoring"
},
{
"method": "POST",
"path": "/risks/{riskId}/mitigations",
"purpose": "Add mitigation action"
},
{
"method": "POST",
"path": "/projects/{projectId}/experiments",
"purpose": "Create experiment record"
},
{
"method": "POST",
"path": "/projects/{projectId}/metrics",
"purpose": "Submit measurement value"
},
{
"method": "POST",
"path": "/projects/{projectId}/gates/{gateId}/evaluate",
"purpose": "Evaluate governance gate"
},
{
"method": "GET",
"path": "/projects/{projectId}/reports/executive",
"purpose": "Generate executive risk report"
},
{
"method": "POST",
"path": "/integrations/trello/sync",
"purpose": "Sync risks and mitigations to Trello cards"
}
]
},
"reporting": {
"executiveSummary": "The SupportGenAI pilot is technically promising but not ready for production deployment. The model evaluation gate is conditionally passed, while the deployment readiness gate is blocked due to high residual risks, incomplete approvals, insufficient monitoring coverage, and rollback readiness gaps.",
"recommendedDecision": "Continue controlled pilot preparation. Do not deploy to production until the deployment gate passes.",
"reportDate": "2026-07-08"
}
}