# RiskForge

> EU AI Act Article 9 Risk Management System builder: 30 minutes to a signed, audit-trailed Risk Management File.

Source: https://aiexponent.com/docs/riskforge · Content verified 2026-10-04

Guided 8-dimension risk assessment CLI with 37 questions drawn from EU AI Act Article 9 requirements, Annex III pattern matching, and SHA-256 hash-chained audit trail. Produces a Risk Management File (JSON + PDF) suitable for inclusion in your Annex IV technical documentation pack; not a substitute for notified-body conformity assessment. Approximately 30 minutes per assessment instead of weeks of consulting work.

- EU AI Act: Article 9 (Risk Management)
- PyPI package: `riskforge` v1.1.3
- Source: https://github.com/aiexponent/riskforge
- Licence: Apache License 2.0

## Quick start

```bash
pip install riskforge
```

```bash
# 1. Register your AI system
riskforge init \
  --name "Loan Scoring Model" \
  --sys-version "2.1" \
  --purpose "Automated credit scoring for retail loan applications." \
  --provider "Acme Financial Services" \
  --category essential_services

# 2. Record the Article 6(2) self-classification (required before export)
riskforge system classify <system-id> --confirm

# 3. Run the guided 8-dimension risk assessment
riskforge assess <system-id> \
  --assessor-name "Alice Chen" \
  --assessor-role "AI Governance Lead"

# 4. Mitigate or accept each high or critical risk (list them with: riskforge risk list <system-id>)
riskforge risk accept <system-id> <risk-id> --rationale "Residual within appetite after controls."

# 5. Check completeness before export (8 validation gates)
riskforge validate <system-id>

# 6. Export your Article 9 Risk Management File
riskforge export <system-id> --format pdf --output rmf.pdf
riskforge export <system-id> --format json --output rmf.json

# 7. Verify the file has not been changed
riskforge verify --file rmf.json
```

Full command reference: https://github.com/aiexponent/riskforge/tree/main/docs

## For coding agents

Install riskforge from PyPI into a virtual environment (Python 3.11 or newer). Run `riskforge init --name <system name> --sys-version <version> --purpose "<one sentence>" --provider <organisation> --category <Annex III category>` and note the printed System ID. Then run `riskforge system classify <system-id> --confirm` and `riskforge assess <system-id> --assessor-name <name> --assessor-role <role> --answers answers.yaml` (the answers format is in the docs; without a terminal, assess needs the file). Mitigate or accept each high or critical risk shown by `riskforge risk list <system-id>`, run `riskforge validate <system-id>`, export with `riskforge export <system-id> --format json --output rmf.json`, and check it with `riskforge verify --file rmf.json`. Docs: https://aiexponent.com/docs/riskforge.md

### Running without a terminal

`riskforge assess` asks its questions interactively and needs a terminal; in a script or agent session pass `--answers answers.yaml`. Each answer is keyed by question ID; one answer per risk dimension lets gate G1 (all 8 dimensions covered) pass. This file is the credit-scoring example shipped with riskforge 1.1.3:

```yaml
add_patterns: true
answers:
  HS-001: { applies: yes, likelihood: 1, severity: 3 }
  FR-001: { applies: yes, likelihood: 3, severity: 4 }
  DI-001: { applies: yes, likelihood: 4, severity: 5 }
  PR-001: { applies: yes, likelihood: 3, severity: 4 }
  TR-001: { applies: yes, likelihood: 3, severity: 3 }
  HO-001: { applies: yes, likelihood: 2, severity: 4 }
  RO-001: { applies: yes, likelihood: 3, severity: 4 }
  DG-001: { applies: unknown }
```

Replace the likelihood and severity scores (1 to 5) with the user's own judgement; the values above are an example, not an assessment.

Gate G3 needs every high or critical risk mitigated or accepted. Risk IDs are the 8-character IDs shown by `riskforge risk list <system-id>`; `<system-id>` is the full ID printed by `init`. To record a control instead of accepting the risk (`-c` takes the control type, for example preventive or detective):

```bash
riskforge risk mitigate <system-id> <risk-id> -m "<a specific control>" -c preventive \
  --owner "<team>" --residual-likelihood 2 --residual-severity 3
```

Gate G8 flags vague mitigations (words such as "monitor" or "review"), so name the control and its threshold.

Do not use `riskforge export --force`: it skips validation, and `riskforge verify` checks only that the file is unchanged, not that it is complete.

Run every command from the folder where you ran `riskforge init`; the project state lives in `riskforge.yaml` and `.riskforge/` there.

## Features

- 8 risk dimensions derived across Articles 9, 10, 13, 14 and 15, mapped to Article 9 obligations with 37 guided questions
- Annex III pattern matching pre-populates risk items for known high-risk scenarios (credit scoring, hiring, facial recognition, medical diagnosis)
- 5×5 likelihood × severity scoring matrix with automatic risk band classification
- 8 pre-export validation gates (dimension coverage, vulnerable groups, vague mitigation detection)
- SHA-256 hash-chained audit trail: tamper-evident, verifiable with `riskforge verify` (exits code 2 on corruption)
- JSON, PDF (WeasyPrint), and Markdown export formats
- Integration adapters for rag-benchmarking and TraceForge: import evidence directly
- Cross-framework mapping: NIST AI RMF and ISO/IEC 42001 (per-question references in every export)
- Zero outbound network calls in CLI mode, enforced by pytest-socket CI gate

## Regulatory foundation

### Article 9: Risk management system

Status: UPCOMING. Applies from 2 Dec 2027 · deferred (statutory date before the Digital Omnibus: 2026-08-02).

> 1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.
>
> 2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:
>
> (a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
>
> (b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;
>
> […]
>
> (d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).
>
> […]
>
> 6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.

Paragraphs quoted: 9(1), 9(2)(a), 9(2)(b), 9(2)(d), 9(6). Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 (retrieved 2026-10-04).

- Omitted 9(2)(c): Post-market monitoring evaluation per Article 72 is out of scope for RiskForge; addressed by TraceForge (in development).
- Omitted 9(3)–(8): Test-data, documentation, and testing provisions live in Art. 9(3) to 9(8). They are covered structurally by the Risk Management File output rather than quoted here.

Penalty: Up to €15M or 3% of global annual turnover, whichever is higher (Article 99(4), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689).

Article 9 applies from 2 December 2027 for high-risk AI systems. Regulation (EU) 2026/1744, the Digital Omnibus on AI (in force since 27 July 2026), deferred that date from 2 August 2026. What the article requires is a documented, lifecycle-long risk management system, not a one-time assessment. Failure to maintain it routes through the Article 16 provider obligations and is sanctionable up to €15M or 3% of global annual turnover under Article 99(4). The operational consequence: risk management must produce versioned, reviewable artefacts mapped to identified hazards, with testing evidence sufficient to defend the residual-risk judgement.

How RiskForge addresses this:

- 9(1): Generates a versioned risk-management-system file: hazard register, risk owners, review cadence, change history
- 9(2)(a): Structured hazard identification across health, safety and fundamental-rights dimensions with intended-purpose framing
- 9(2)(b): Reasonably-foreseeable-misuse scenario library with likelihood × severity scoring and mitigation linkage
- 9(2)(d): Maps each identified risk to a targeted mitigation control and tracks residual-risk acceptance with sign-off trail
- 9(6): Test-plan generator tying each hazard to a measurable test, with prior-defined metrics and probabilistic thresholds (Art. 9(8))

## FAQ

### What does EU AI Act Article 9 require?

A documented, lifecycle-long risk management system for high-risk AI systems, not a one-time assessment. It must identify foreseeable risks to health, safety, and fundamental rights; estimate and evaluate them under intended use and reasonably foreseeable misuse; adopt targeted mitigation measures; and produce testing evidence sufficient to defend the residual-risk judgement. Source: Regulation (EU) 2024/1689 Article 9(1)–(2)(a)–(b)(d), 9(6).

### When does Article 9 become enforceable?

Article 9 obligations for high-risk AI systems apply from 2 December 2027, deferred from the original 2 August 2026 statutory date by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which was published in the Official Journal on 24 July 2026 and has been in force since 27 July 2026. Source: Regulation (EU) 2024/1689 Article 113, as amended by Regulation (EU) 2026/1744.

### How long does a complete Risk Management File take with RiskForge?

Approximately 30 minutes for an interactive 8-dimension assessment with 37 guided questions, depending on the complexity of the system being assessed. The output is a JSON + PDF Risk Management File suitable for inclusion in your Annex IV technical documentation pack, not a substitute for notified-body conformity assessment.

### Is RiskForge a notified-body conformity assessment?

No. RiskForge produces documented evidence supporting an Article 9 risk management system. Conformity assessment by a notified body, where required, is a separate process performed by accredited entities. RiskForge output is one input to that process, not a replacement for it.

### What scoring methodology does RiskForge use?

A 5×5 likelihood × severity matrix with automatic risk-band classification, applied per identified risk. Annex III pattern matching pre-populates risk items for known high-risk scenarios (credit scoring, hiring, facial recognition, medical diagnosis).

### Does RiskForge cross-map to NIST AI RMF and ISO/IEC 42001?

Yes. Each risk-management dimension carries per-question references to NIST AI RMF GOVERN/MAP/MEASURE/MANAGE categories and ISO/IEC 42001 controls, emitted in every export. A single assessment produces evidence reusable across both frameworks.

### What is the penalty for Article 9 non-compliance?

Up to €15M or 3% of global annual turnover, whichever is higher, under Article 99(4). The Article 16 provider obligation chain routes Article 9 failures through this penalty band.

### Is RiskForge free?

Yes. Apache 2.0 licensed, free for any use including commercial. No telemetry: outbound network calls are blocked at CI level via pytest-socket.

### Can I customize the question bank for sector-specific risks?

Yes. The question bank is plug-in based via Python entry points. The core 8 dimensions cover the regulatory baseline; sector-specific additions (medical devices, financial services) are extensible through user-supplied bank YAML files.

### How is the audit trail tamper-evident?

Every change is recorded with a SHA-256 hash chained to the previous entry. `riskforge verify` recomputes the chain and exits with code 2 if any link is broken, making tampering or partial deletion CI-detectable.

## Known limitations

- Produces documented evidence for Article 9 compliance. It does not substitute for qualified legal counsel or notified body conformity assessment.
- Question bank covers 37 questions across 8 risk dimensions; specialised sector questions (e.g. medical devices) may require custom additions.
- Interactive assessment requires a terminal; CI/CD integration uses the engine layer directly.
- PDF export via WeasyPrint: some complex layouts may require HTML/CSS customisation.
- Apache 2.0 licensed; no warranty of legal compliance.

## Contributing

Issues: https://github.com/aiexponent/riskforge/issues · Contributing guide: https://github.com/aiexponent/riskforge/blob/main/CONTRIBUTING.md

---

Not legal advice. Not a notified body. The tools produce evidence, not conformity assessment.
All docs as Markdown: https://aiexponent.com/llms.txt · Guide for coding agents: https://aiexponent.com/agents.md
