EW-AiRM — Enterprise-Wide AI Risk Management
EW-AiRM — Enterprise-Wide AI Risk Management
EW-AiRM — Enterprise-Wide AI Risk Management — 69% of in-scope requirements covered.
12 requirements · 8 in scope (3 enforced · 5 designed) · 4 out-of-scope (outside KYE™’s authority layer). The 69% is weighted over the in-scope base.
Source: Human-AI Institute / Markus Krebsz — Enterprise-Wide AI Risk Management (EW-AiRM); risk-taxonomy substrate: MIT AI Risk Repository (https://airisk.mit.edu/). · License: EW-AiRM is an expert governance framework authored by Markus Krebsz / the Human-AI Institute. The KYE™ registry paraphrases each requirement's runtime-facing intent and cites the framework for mapping purposes only; it does not reproduce the framework text.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| System approval vs per-action authority (the boundary) | 1 | 1 | 0 | 0 | 0 | 100% |
| Non-negotiable — named accountability | 1 | 1 | 0 | 0 | 0 | 100% |
| Non-negotiable — no score-averaging over a critical failure | 1 | 1 | 0 | 0 | 0 | 100% |
| Non-negotiable — tested human override | 1 | 0 | 1 | 0 | 0 | 50% |
| Residual-risk acceptance → runtime condition | 1 | 0 | 1 | 0 | 0 | 50% |
| HAiPECR record consumption | 1 | 0 | 1 | 0 | 0 | 50% |
| Non-negotiable — named incident route | 1 | 0 | 1 | 0 | 0 | 50% |
| Black-Swan resilience — runtime evidence | 1 | 0 | 1 | 0 | 0 | 50% |
| Board risk-appetite quantification | 1 | 0 | 0 | 0 | 0 | 0% |
| Organisational-readiness assessment | 1 | 0 | 0 | 0 | 0 | 0% |
| AI-necessity assessment | 1 | 0 | 0 | 0 | 0 | 0% |
| MIT AI Risk Repository taxonomy | 1 | 0 | 0 | 0 | 0 | 0% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
ewairm.system-approval-not-action-authority |
An enterprise-wide AI-risk sign-off approves a SYSTEM for use; it does NOT grant per-action authority — every consequential action is still admissibility-checked at the moment it is attempted | enforced | engines: internal, internal, internalaudit_events: kye.purpose.request.v1, kye.purpose.admissibility.v1constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
ewairm.non-negotiable-named-accountability |
EW-AiRM non-negotiable: a single, named, accountable owner for the AI system — accountability that cannot be diffused across a committee | enforced | engines: internalaudit_events: kye.purpose.request.v1constitution_refs: constitution/00-INDEX.md |
ewairm.f-critical-no-averaging-override |
EW-AiRM F-Critical rule: a critical failure condition cannot be averaged away by strong scores elsewhere — one hard fail fails the whole | enforced | engines: internal, internalaudit_events: kye.purpose.admissibility.v1constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
ewairm.non-negotiable-tested-human-override |
EW-AiRM non-negotiable: a tested human override / off-switch on the AI system | designed | engines: internal, internalaudit_events: kye.purpose.admissibility.v1constitution_refs: constitution/36-GOVERNEDUI.md |
ewairm.residual-risk-acceptance-as-authority-condition |
The board's accepted residual-risk statement is consumed as a runtime authority CONDITION — actions outside the accepted envelope are denied | designed | engines: internalaudit_events: kye.purpose.admissibility.v1constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
ewairm.documented-haipecr-consumption |
The HAiPECR pre-deployment evidence record is consumed as a deploy-gate / action-policy input | designed | engines: internalaudit_events: kye.purpose.request.v1constitution_refs: constitution/70-FRAMEWORK-MAPPING-RAIL.md |
ewairm.non-negotiable-named-incident-route |
EW-AiRM non-negotiable: a named incident-escalation and contestability route for the AI system | designed | engines: internalaudit_events: kye.evidence.decision_map.v1constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/61-RIGHTS-DISPUTES-DISCLOSURE-RAIL.md |
ewairm.black-swan-runtime-resilience-evidence |
Runtime resilience evidence under tail (Black-Swan) conditions — replay-provable behaviour when a dependency or scenario degrades | designed | engines: internalaudit_events: kye.evidence.pack.v1constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/51-NO-SPOF.md |
ewairm.board-risk-appetite-quantification |
Quantifying the board's AI risk appetite and translating it into risk-tolerance thresholds | out-of-scope | (no enforcement cited) |
ewairm.organisational-readiness-assessment |
Assessing organisational readiness (people, process, culture, governance maturity) to adopt the AI system | out-of-scope | (no enforcement cited) |
ewairm.ai-necessity-assessment |
Assessing whether AI is necessary and appropriate for the use-case at all (the necessity / proportionality question) | out-of-scope | (no enforcement cited) |
ewairm.mit-risk-taxonomy-classification |
Classifying AI risks against the MIT AI Risk Repository taxonomy substrate | out-of-scope | (no enforcement cited) |