Risk source

Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group 1. Internal sources sit inside the organisation's control; external ones arise outside it and are mostly engineered against and monitored.

Developed in
ch. 13, Internal and external risk sources
Chapters
ch. 13, Risk Management
Contrast with
Contributing factor
Source
1 numbered reference, listed below

Where it is used

2 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Sources

  1. [1] Crosswalk: AI RMF (1.0) and ISO/IEC FDIS 23894 (function-to-clause mapping, incl. risk sources). NIST. 2023-01-26. https://www.nist.gov/system/files/documents/2023/01/26/crosswalk_AI_RMF_1_0_ISO_IEC_23894.pdf (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Risk source. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/risk-source. CC BY 4.0

BibTeX

@misc{aige2026risksource,
  author  = {Jorge García Aibar},
  title   = {{Risk source}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/risk-source}
}