The risk loop on the stack

The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register.

The risk loop on the stack The four steps of the risk loop, each with its NIST AI RMF functions and the stack layers that do the work, inside GOVERN, looping back from monitor to identify and writing to one risk register. One loop, run on the five layers GOVERN: across the whole loop Identify MAP 1–5 · GOVERN 5 Layer 02 Inventory & Transparency Assess MAP 5.1 · MEASURE 1–2 Layer 03 Evals & Red Teaming as Evidence Treat MANAGE 1–3 Layer 01 Govern-as-Code Layer 04 Runtime Controls & Observability Monitor MEASURE 3–4 · MANAGE 4 Layer 04 Runtime Controls & Observability Layer 05 Assurance & Continuous Compliance Risk register History, signed acceptances, review log
The risk loop on the stack The four steps of the risk loop with the NIST AI RMF functions each covers and the stack layers that do its work, all under GOVERN and all writing to one risk register. Find the step your function skips, then build the layer that does its work. Drawn from chapter 13.

Text alternative

Identify (MAP 1 to 5, GOVERN 5): Layer 02 Inventory & Transparency gives every risk an object, with a registry id, owner, tier and affected stakeholders. Assess (MAP 5.1, MEASURE 1 to 2): Layer 03 Evals & Red Teaming as Evidence measures likelihood and finds risks nobody listed. Treat (MANAGE 1 to 3): Layer 01 Govern-as-Code holds appetite, tolerance, scales and tier rules as data and blocks what exceeds them, and Layer 04 Runtime Controls & Observability treats at runtime. Monitor (MEASURE 3 to 4, MANAGE 4): Layer 04 detects a risk becoming real, and Layer 05 Assurance & Continuous Compliance records, re-rates and reports. GOVERN applies across the whole process. The loop returns from monitor to identify, and every step writes to the risk register, whose history, signed acceptances and review log are the evidence.

Download

Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.

The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register.
The PNG, light, 1600 px wide, as it downloads (shown here as a lighter copy).

Reuse and credit

The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:

“The risk loop on the stack” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/risk-loop-stack), v0.5.0. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Embed with HTML

<figure>
  <img src="https://aigovernanceengineer.com/downloads/figures/risk-loop-stack-v0.5.0-light-1600.png" alt="The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register." width="800" height="1031" loading="lazy">
  <figcaption>
    <a href="https://aigovernanceengineer.com/figures/risk-loop-stack">The risk loop on the stack</a> by Jorge García Aibar,
    aigovernanceengineer.com, v0.5.0.
    Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
  </figcaption>
</figure>

Embed with Markdown

![The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register.](https://aigovernanceengineer.com/downloads/figures/risk-loop-stack-v0.5.0-light-1600.png)

*[The risk loop on the stack](https://aigovernanceengineer.com/figures/risk-loop-stack) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*