EW-AiRM — Enterprise-Wide AI Risk Management

EW-AiRM — Enterprise-Wide AI Risk Management

EW-AiRM — Enterprise-Wide AI Risk Management — 69% of in-scope requirements covered.

12 requirements · 8 in scope (3 enforced · 5 designed) · 4 out-of-scope (outside KYE’s authority layer). The 69% is weighted over the in-scope base.

Source: Human-AI Institute / Markus Krebsz — Enterprise-Wide AI Risk Management (EW-AiRM); risk-taxonomy substrate: MIT AI Risk Repository (https://airisk.mit.edu/). · License: EW-AiRM is an expert governance framework authored by Markus Krebsz / the Human-AI Institute. The KYE registry paraphrases each requirement's runtime-facing intent and cites the framework for mapping purposes only; it does not reproduce the framework text.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
System approval vs per-action authority (the boundary) 1 1 0 0 0 100%
Non-negotiable — named accountability 1 1 0 0 0 100%
Non-negotiable — no score-averaging over a critical failure 1 1 0 0 0 100%
Non-negotiable — tested human override 1 0 1 0 0 50%
Residual-risk acceptance → runtime condition 1 0 1 0 0 50%
HAiPECR record consumption 1 0 1 0 0 50%
Non-negotiable — named incident route 1 0 1 0 0 50%
Black-Swan resilience — runtime evidence 1 0 1 0 0 50%
Board risk-appetite quantification 1 0 0 0 0 0%
Organisational-readiness assessment 1 0 0 0 0 0%
AI-necessity assessment 1 0 0 0 0 0%
MIT AI Risk Repository taxonomy 1 0 0 0 0 0%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
ewairm.system-approval-not-action-authority An enterprise-wide AI-risk sign-off approves a SYSTEM for use; it does NOT grant per-action authority — every consequential action is still admissibility-checked at the moment it is attempted enforced engines: internal, internal, internal
audit_events: kye.purpose.request.v1, kye.purpose.admissibility.v1
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
ewairm.non-negotiable-named-accountability EW-AiRM non-negotiable: a single, named, accountable owner for the AI system — accountability that cannot be diffused across a committee enforced engines: internal
audit_events: kye.purpose.request.v1
constitution_refs: constitution/00-INDEX.md
ewairm.f-critical-no-averaging-override EW-AiRM F-Critical rule: a critical failure condition cannot be averaged away by strong scores elsewhere — one hard fail fails the whole enforced engines: internal, internal
audit_events: kye.purpose.admissibility.v1
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
ewairm.non-negotiable-tested-human-override EW-AiRM non-negotiable: a tested human override / off-switch on the AI system designed engines: internal, internal
audit_events: kye.purpose.admissibility.v1
constitution_refs: constitution/36-GOVERNEDUI.md
ewairm.residual-risk-acceptance-as-authority-condition The board's accepted residual-risk statement is consumed as a runtime authority CONDITION — actions outside the accepted envelope are denied designed engines: internal
audit_events: kye.purpose.admissibility.v1
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
ewairm.documented-haipecr-consumption The HAiPECR pre-deployment evidence record is consumed as a deploy-gate / action-policy input designed engines: internal
audit_events: kye.purpose.request.v1
constitution_refs: constitution/70-FRAMEWORK-MAPPING-RAIL.md
ewairm.non-negotiable-named-incident-route EW-AiRM non-negotiable: a named incident-escalation and contestability route for the AI system designed engines: internal
audit_events: kye.evidence.decision_map.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/61-RIGHTS-DISPUTES-DISCLOSURE-RAIL.md
ewairm.black-swan-runtime-resilience-evidence Runtime resilience evidence under tail (Black-Swan) conditions — replay-provable behaviour when a dependency or scenario degrades designed engines: internal
audit_events: kye.evidence.pack.v1
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/51-NO-SPOF.md
ewairm.board-risk-appetite-quantification Quantifying the board's AI risk appetite and translating it into risk-tolerance thresholds out-of-scope (no enforcement cited)
ewairm.organisational-readiness-assessment Assessing organisational readiness (people, process, culture, governance maturity) to adopt the AI system out-of-scope (no enforcement cited)
ewairm.ai-necessity-assessment Assessing whether AI is necessary and appropriate for the use-case at all (the necessity / proportionality question) out-of-scope (no enforcement cited)
ewairm.mit-risk-taxonomy-classification Classifying AI risks against the MIT AI Risk Repository taxonomy substrate out-of-scope (no enforcement cited)