The risk loop on the stack
The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register.
Text alternative
Identify (MAP 1 to 5, GOVERN 5): Layer 02 Inventory & Transparency gives every risk an object, with a registry id, owner, tier and affected stakeholders. Assess (MAP 5.1, MEASURE 1 to 2): Layer 03 Evals & Red Teaming as Evidence measures likelihood and finds risks nobody listed. Treat (MANAGE 1 to 3): Layer 01 Govern-as-Code holds appetite, tolerance, scales and tier rules as data and blocks what exceeds them, and Layer 04 Runtime Controls & Observability treats at runtime. Monitor (MEASURE 3 to 4, MANAGE 4): Layer 04 detects a risk becoming real, and Layer 05 Assurance & Continuous Compliance records, re-rates and reports. GOVERN applies across the whole process. The loop returns from monitor to identify, and every step writes to the risk register, whose history, signed acceptances and review log are the evidence.
Download
Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.
Reuse and credit
The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:
“The risk loop on the stack” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/risk-loop-stack), v0.5.0. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).
Embed with HTML
<figure>
<img src="https://aigovernanceengineer.com/downloads/figures/risk-loop-stack-v0.5.0-light-1600.png" alt="The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register." width="800" height="1031" loading="lazy">
<figcaption>
<a href="https://aigovernanceengineer.com/figures/risk-loop-stack">The risk loop on the stack</a> by Jorge García Aibar,
aigovernanceengineer.com, v0.5.0.
Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
</figcaption>
</figure> Embed with Markdown

*[The risk loop on the stack](https://aigovernanceengineer.com/figures/risk-loop-stack) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*