{
  "id": "92d8aaa9-763c-4974-8ab8-c83ae1da857b",
  "rmf_schema_version": "1.0.0",
  "register": {
    "id": "fc124124-519f-496b-8c75-e74377a5a1d6",
    "system": {
      "id": "42565357-74c8-45c5-bfd8-f6e79dd89077",
      "name": "Loan Scoring Model",
      "version": "2.1",
      "purpose": "Automated credit scoring for retail loan applications.",
      "intended_users": [],
      "inputs": [],
      "outputs": [],
      "deployment_context": "",
      "annex_iii_category": "essential_services",
      "annex_iii_self_classification_documented": true,
      "provider_name": "Acme Financial Services (fictional)",
      "provider_contact": "",
      "created_at": "2026-10-04T08:19:15.978644Z",
      "schema_version": "1.0.0"
    },
    "items": [
      {
        "id": "2e699798-4196-4ad7-a797-1f82d5d48895",
        "dimension": "discrimination",
        "title": "Demographic bias in credit scoring outputs",
        "description": "Credit scoring models trained on historical data may encode systemic biases against protected groups (age, gender, ethnicity). Article 9(9) requires consideration of impacts on vulnerable groups.",
        "source": "pattern",
        "likelihood": 3,
        "severity": 4,
        "mitigations": [
          {
            "id": "b12b256a-ee75-4c32-8c23-a5f95d2489ac",
            "description": "Remove postcode feature; block release when demographic parity difference exceeds 0.10",
            "control_type": "preventive",
            "owner": "ML Platform",
            "status": "planned",
            "evidence_refs": [],
            "is_vague": false,
            "article_ref": "",
            "nist_rmf_ref": ""
          }
        ],
        "residual_likelihood": 2,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.684660Z",
        "article_refs": [
          "Art.9(2)(a)",
          "Art.9(9)",
          "Art.10(2)(f)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "MEASURE 2.9",
        "iso42001_ref": "Clause A.7",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "pattern:CREDIT_SCORING_BIAS"
        ],
        "notes": "",
        "risk_score": 12,
        "residual_risk_score": 6,
        "risk_band": "high",
        "residual_risk_band": "medium"
      },
      {
        "id": "aa98503e-50ad-4054-8b49-ccbdb898255e",
        "dimension": "transparency",
        "title": "Lack of explanation for credit decisions",
        "description": "Automated credit decisions must be explainable to affected individuals under GDPR Article 22. The system may not currently provide this.",
        "source": "pattern",
        "likelihood": 3,
        "severity": 3,
        "mitigations": [],
        "residual_likelihood": 3,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.686853Z",
        "article_refs": [
          "Art.13"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "GOVERN 1.7",
        "iso42001_ref": "Clause A.6",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "pattern:CREDIT_SCORING_BIAS"
        ],
        "notes": "",
        "risk_score": 9,
        "residual_risk_score": 9,
        "risk_band": "medium",
        "residual_risk_band": "medium"
      },
      {
        "id": "74b87ef8-7f81-403f-80b1-33f1daef1568",
        "dimension": "health_safety",
        "title": "Could the system's outputs directly influence a clinical, safety, or physical decision without mandatory human review?",
        "description": "Consider decisions about medication dosing, surgical planning, vehicle operation, equipment control, or emergency dispatch.",
        "source": "question_bank",
        "likelihood": 1,
        "severity": 3,
        "mitigations": [],
        "residual_likelihood": 1,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.693290Z",
        "article_refs": [
          "Art.9(2)(a)",
          "Art.14(1)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "MAP 1.5",
        "iso42001_ref": "Clause 6.1",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "HS-001"
        ],
        "notes": "",
        "risk_score": 3,
        "residual_risk_score": 3,
        "risk_band": "low",
        "residual_risk_band": "low"
      },
      {
        "id": "dd03681f-4cff-4659-b879-394199f82f34",
        "dimension": "fundamental_rights",
        "title": "Has a fundamental rights impact assessment (FRIA) been conducted prior to deployment?",
        "description": "Article 9(2)(a) requires identification of known and foreseeable risks to fundamental rights. A FRIA is the standard mechanism for this.",
        "source": "question_bank",
        "likelihood": 3,
        "severity": 4,
        "mitigations": [
          {
            "id": "ce1b82dd-8ef9-4ab0-bb5a-136e8e11605a",
            "description": "Complete a fundamental rights impact assessment before deployment and repeat it for each major model version",
            "control_type": "preventive",
            "owner": "Legal and Compliance",
            "status": "planned",
            "evidence_refs": [],
            "is_vague": false,
            "article_ref": "",
            "nist_rmf_ref": ""
          }
        ],
        "residual_likelihood": 2,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.706495Z",
        "article_refs": [
          "Art.9(2)(a)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "GOVERN 1.1",
        "iso42001_ref": "Clause 6.1",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "FR-001"
        ],
        "notes": "",
        "risk_score": 12,
        "residual_risk_score": 6,
        "risk_band": "high",
        "residual_risk_band": "medium"
      },
      {
        "id": "b3e0a068-251b-4c82-9095-ac161681c378",
        "dimension": "discrimination",
        "title": "Has the training dataset been audited for representation imbalances across protected characteristics (gender, ethnicity,",
        "description": "Biased training data produces biased outputs. Article 10(2)(f) requires data governance measures to address biases.",
        "source": "question_bank",
        "likelihood": 4,
        "severity": 5,
        "mitigations": [
          {
            "id": "314f4f88-a02a-4366-8bbe-5ae4d31c2f96",
            "description": "Commission an independent bias audit of the training data before each retrain; block release on a failed audit",
            "control_type": "preventive",
            "owner": "Model Risk",
            "status": "planned",
            "evidence_refs": [],
            "is_vague": false,
            "article_ref": "",
            "nist_rmf_ref": ""
          }
        ],
        "residual_likelihood": 2,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.721818Z",
        "article_refs": [
          "Art.10(2)(f)",
          "Art.9(2)(a)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "MEASURE 2.9",
        "iso42001_ref": "Clause A.7",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "DI-001"
        ],
        "notes": "",
        "risk_score": 20,
        "residual_risk_score": 6,
        "risk_band": "critical",
        "residual_risk_band": "medium"
      },
      {
        "id": "34effdcf-1637-41e2-bfda-81613c1e2271",
        "dimension": "privacy",
        "title": "Does the system process personal data or special category data (health, biometric, ethnicity, religion)?",
        "description": "Processing of special category data triggers additional obligations under GDPR Article 9 and EU AI Act Article 10(5).",
        "source": "question_bank",
        "likelihood": 3,
        "severity": 4,
        "mitigations": [],
        "residual_likelihood": 3,
        "residual_severity": 4,
        "accepted": true,
        "acceptance_rationale": "Residual within appetite after controls.",
        "identified_at": "2026-10-04T08:19:16.749559Z",
        "article_refs": [
          "Art.10(5)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "GOVERN 1.6",
        "iso42001_ref": "Clause A.8",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "PR-001"
        ],
        "notes": "",
        "risk_score": 12,
        "residual_risk_score": 12,
        "risk_band": "high",
        "residual_risk_band": "high"
      },
      {
        "id": "627f04c6-48cd-419b-98aa-787cf0a7daad",
        "dimension": "transparency",
        "title": "Are users notified that they are interacting with or being assessed by an AI system?",
        "description": "Article 13 requires providers to ensure a sufficient level of transparency to enable users to interpret the system's output. Notification is a baseline.",
        "source": "question_bank",
        "likelihood": 3,
        "severity": 3,
        "mitigations": [],
        "residual_likelihood": 3,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.770620Z",
        "article_refs": [
          "Art.13(1)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "GOVERN 1.7",
        "iso42001_ref": "Clause A.6",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "TR-001"
        ],
        "notes": "",
        "risk_score": 9,
        "residual_risk_score": 9,
        "risk_band": "medium",
        "residual_risk_band": "medium"
      },
      {
        "id": "c5f45bf9-acd2-45bf-b2b6-dd91966b2898",
        "dimension": "human_oversight",
        "title": "Can a human operator override or stop the AI system's output in real time without significant technical barriers?",
        "description": "Article 14(4)(e) requires the ability to intervene on or interrupt AI system operation. This must be technically implemented, not just policy-stated.",
        "source": "question_bank",
        "likelihood": 2,
        "severity": 4,
        "mitigations": [],
        "residual_likelihood": 2,
        "residual_severity": 4,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.794310Z",
        "article_refs": [
          "Art.14(4)(e)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "MANAGE 1.1",
        "iso42001_ref": "Clause A.9",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "HO-001"
        ],
        "notes": "",
        "risk_score": 8,
        "residual_risk_score": 8,
        "risk_band": "medium",
        "residual_risk_band": "medium"
      },
      {
        "id": "1641d6e8-c737-404e-847d-48c6d1f71d86",
        "dimension": "robustness",
        "title": "Has the system been tested against out-of-distribution inputs, edge cases, and adversarial perturbations?",
        "description": "Article 9(7) and Article 15 require testing of AI systems against the intended purpose and reasonably foreseeable misuse.",
        "source": "question_bank",
        "likelihood": 3,
        "severity": 4,
        "mitigations": [],
        "residual_likelihood": 3,
        "residual_severity": 4,
        "accepted": true,
        "acceptance_rationale": "Residual within appetite after controls.",
        "identified_at": "2026-10-04T08:19:16.826947Z",
        "article_refs": [
          "Art.9(7)",
          "Art.15"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "MEASURE 2.5",
        "iso42001_ref": "Clause A.9",
        "regulatory_status": "settled",
        "knowledge_gap": false,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "RO-001"
        ],
        "notes": "",
        "risk_score": 12,
        "residual_risk_score": 12,
        "risk_band": "high",
        "residual_risk_band": "high"
      },
      {
        "id": "7a141cbf-1ec5-43e4-9669-ce337a790310",
        "dimension": "data_governance",
        "title": "Is the provenance of all training, validation, and test datasets documented (source, collection date, license, version)?",
        "description": "Article 10(2) requires data governance practices including documentation of dataset provenance. TraceForge can automate this.",
        "source": "question_bank",
        "likelihood": 2,
        "severity": 3,
        "mitigations": [],
        "residual_likelihood": 2,
        "residual_severity": 3,
        "accepted": false,
        "acceptance_rationale": "",
        "identified_at": "2026-10-04T08:19:16.843400Z",
        "article_refs": [
          "Art.10(2)",
          "Art.10(3)"
        ],
        "nist_rmf_refs": [],
        "iso42001_refs": [],
        "nist_rmf_ref": "GOVERN 1.7",
        "iso42001_ref": "Clause A.8",
        "regulatory_status": "settled",
        "knowledge_gap": true,
        "knowledge_gap_reason": "",
        "source_ref": "",
        "tags": [
          "DG-001"
        ],
        "notes": "",
        "risk_score": 6,
        "residual_risk_score": 6,
        "risk_band": "medium",
        "residual_risk_band": "medium"
      }
    ],
    "risk_appetite_threshold": 9,
    "assessor_name": "Alice Chen",
    "assessor_role": "AI Governance Lead",
    "assessment_date": "2026-10-04T08:19:16.679033Z",
    "review_date": "2027-09-29T08:19:16.679037Z",
    "question_bank_version": "1.0.0",
    "schema_version": "1.0.0"
  },
  "test_requirements": [
    {
      "id": "559ce2af-6c28-4cd6-aee7-0d9fb03dc2e1",
      "risk_item_id": "2e699798-4196-4ad7-a797-1f82d5d48895",
      "description": "Validate 'Demographic bias in credit scoring outputs' via demographic_parity measurement. Target: <= 0.10.",
      "metric_type": "demographic_parity",
      "threshold_range": "<= 0.10",
      "article_ref": "Art.9(7)",
      "nist_rmf_ref": ""
    },
    {
      "id": "c6fd44a3-c25e-4733-b77b-719e2833ac31",
      "risk_item_id": "aa98503e-50ad-4054-8b49-ccbdb898255e",
      "description": "Validate 'Lack of explanation for credit decisions' via explanation_coverage measurement. Target: >= 0.90.",
      "metric_type": "explanation_coverage",
      "threshold_range": ">= 0.90",
      "article_ref": "Art.13",
      "nist_rmf_ref": ""
    },
    {
      "id": "89215b22-2f4c-4598-bcea-8ab11b7efa82",
      "risk_item_id": "dd03681f-4cff-4659-b879-394199f82f34",
      "description": "Validate 'Has a fundamental rights impact assessment (FRIA) been conducted prior to deployment?' via fundamental_rights_impact_score measurement. Target: = 0.",
      "metric_type": "fundamental_rights_impact_score",
      "threshold_range": "= 0",
      "article_ref": "Art.9(2)(a)",
      "nist_rmf_ref": ""
    },
    {
      "id": "286120ae-7ea4-46bf-8b5d-3bd0fa209a84",
      "risk_item_id": "b3e0a068-251b-4c82-9095-ac161681c378",
      "description": "Validate 'Has the training dataset been audited for representation imbalances across protected characteristics (gender, ethnicity,' via demographic_parity measurement. Target: <= 0.10.",
      "metric_type": "demographic_parity",
      "threshold_range": "<= 0.10",
      "article_ref": "Art.9(7)",
      "nist_rmf_ref": ""
    },
    {
      "id": "805b7c1a-fc84-4276-bbe7-07bb56c6fdff",
      "risk_item_id": "34effdcf-1637-41e2-bfda-81613c1e2271",
      "description": "Validate 'Does the system process personal data or special category data (health, biometric, ethnicity, religion)?' via pii_leakage_rate measurement. Target: = 0.00.",
      "metric_type": "pii_leakage_rate",
      "threshold_range": "= 0.00",
      "article_ref": "Art.9(7)",
      "nist_rmf_ref": ""
    },
    {
      "id": "a6c9bbe5-557e-4926-ba1e-89df2d6903ca",
      "risk_item_id": "627f04c6-48cd-419b-98aa-787cf0a7daad",
      "description": "Validate 'Are users notified that they are interacting with or being assessed by an AI system?' via explanation_coverage measurement. Target: >= 0.90.",
      "metric_type": "explanation_coverage",
      "threshold_range": ">= 0.90",
      "article_ref": "Art.13",
      "nist_rmf_ref": ""
    },
    {
      "id": "897c7814-1f7c-4b90-998d-0ef9fb7e3ade",
      "risk_item_id": "1641d6e8-c737-404e-847d-48c6d1f71d86",
      "description": "Validate 'Has the system been tested against out-of-distribution inputs, edge cases, and adversarial perturbations?' via faithfulness measurement. Target: >= 0.85.",
      "metric_type": "faithfulness",
      "threshold_range": ">= 0.85",
      "article_ref": "Art.9(7)",
      "nist_rmf_ref": ""
    },
    {
      "id": "5a117e09-3e7a-436e-9483-d6f2f1d66e14",
      "risk_item_id": "7a141cbf-1ec5-43e4-9669-ce337a790310",
      "description": "Validate 'Is the provenance of all training, validation, and test datasets documented (source, collection date, license, version)?' via data_quality_score measurement. Target: >= 0.95.",
      "metric_type": "data_quality_score",
      "threshold_range": ">= 0.95",
      "article_ref": "Art.10",
      "nist_rmf_ref": ""
    }
  ],
  "cross_references": [
    {
      "article_ref": "Art.9(2)(a)",
      "risk_item_ids": [
        "2e699798-4196-4ad7-a797-1f82d5d48895",
        "74b87ef8-7f81-403f-80b1-33f1daef1568",
        "dd03681f-4cff-4659-b879-394199f82f34",
        "b3e0a068-251b-4c82-9095-ac161681c378"
      ],
      "nist_rmf_ref": "MEASURE 2.9",
      "iso42001_ref": "Clause A.7"
    },
    {
      "article_ref": "Art.9(9)",
      "risk_item_ids": [
        "2e699798-4196-4ad7-a797-1f82d5d48895"
      ],
      "nist_rmf_ref": "MEASURE 2.9",
      "iso42001_ref": "Clause A.7"
    },
    {
      "article_ref": "Art.10(2)(f)",
      "risk_item_ids": [
        "2e699798-4196-4ad7-a797-1f82d5d48895",
        "b3e0a068-251b-4c82-9095-ac161681c378"
      ],
      "nist_rmf_ref": "MEASURE 2.9",
      "iso42001_ref": "Clause A.7"
    },
    {
      "article_ref": "Art.13",
      "risk_item_ids": [
        "aa98503e-50ad-4054-8b49-ccbdb898255e"
      ],
      "nist_rmf_ref": "GOVERN 1.7",
      "iso42001_ref": "Clause A.6"
    },
    {
      "article_ref": "Art.14(1)",
      "risk_item_ids": [
        "74b87ef8-7f81-403f-80b1-33f1daef1568"
      ],
      "nist_rmf_ref": "MAP 1.5",
      "iso42001_ref": "Clause 6.1"
    },
    {
      "article_ref": "Art.10(5)",
      "risk_item_ids": [
        "34effdcf-1637-41e2-bfda-81613c1e2271"
      ],
      "nist_rmf_ref": "GOVERN 1.6",
      "iso42001_ref": "Clause A.8"
    },
    {
      "article_ref": "Art.13(1)",
      "risk_item_ids": [
        "627f04c6-48cd-419b-98aa-787cf0a7daad"
      ],
      "nist_rmf_ref": "GOVERN 1.7",
      "iso42001_ref": "Clause A.6"
    },
    {
      "article_ref": "Art.14(4)(e)",
      "risk_item_ids": [
        "c5f45bf9-acd2-45bf-b2b6-dd91966b2898"
      ],
      "nist_rmf_ref": "MANAGE 1.1",
      "iso42001_ref": "Clause A.9"
    },
    {
      "article_ref": "Art.9(7)",
      "risk_item_ids": [
        "1641d6e8-c737-404e-847d-48c6d1f71d86"
      ],
      "nist_rmf_ref": "MEASURE 2.5",
      "iso42001_ref": "Clause A.9"
    },
    {
      "article_ref": "Art.15",
      "risk_item_ids": [
        "1641d6e8-c737-404e-847d-48c6d1f71d86"
      ],
      "nist_rmf_ref": "MEASURE 2.5",
      "iso42001_ref": "Clause A.9"
    },
    {
      "article_ref": "Art.10(2)",
      "risk_item_ids": [
        "7a141cbf-1ec5-43e4-9669-ce337a790310"
      ],
      "nist_rmf_ref": "GOVERN 1.7",
      "iso42001_ref": "Clause A.8"
    },
    {
      "article_ref": "Art.10(3)",
      "risk_item_ids": [
        "7a141cbf-1ec5-43e4-9669-ce337a790310"
      ],
      "nist_rmf_ref": "GOVERN 1.7",
      "iso42001_ref": "Clause A.8"
    }
  ],
  "generated_at": "2026-10-04T08:19:20.633413Z",
  "sha256_hash": "13a4f7fa2fc8b5864e07e14c664afb50c3797850c0d0a8309157ee103ff880b5",
  "signed_by": "",
  "audit_entry_hash": "98ba8ac91e7732647f047d072ec8590156d68dfeab9725005073fc54861f3505",
  "disclosure": "This document was produced using RiskForge v1.1.3, question bank version 1.0.0. It represents the team's documented risk assessment and has not been reviewed by a qualified legal professional. It does not constitute legal advice under the EU AI Act or any other regulation."
}