---
title: "Risk source"
description: "Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group."
canonical: https://aigovernanceengineer.com/glossary/risk-source
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Risk source

Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group [1]. Internal sources sit inside the organisation's control; external ones arise outside it and are mostly engineered against and monitored.

- Developed in: [ch. 13, Internal and external risk sources](https://aigovernanceengineer.com/bok/risk-management#internal-and-external-risk-sources)
- Chapters: [ch. 13, Risk Management](https://aigovernanceengineer.com/bok/risk-management)
- Contrast with: [Contributing factor](https://aigovernanceengineer.com/glossary/contributing-factor)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-risk-source

## Sources

[1] Crosswalk: AI RMF (1.0) and ISO/IEC FDIS 23894 (function-to-clause mapping, incl. risk sources). NIST. 2023-01-26. https://www.nist.gov/system/files/documents/2023/01/26/crosswalk_AI_RMF_1_0_ISO_IEC_23894.pdf (verified: primary)
