Sharp. Not sentimental.
AI Model Risk. Filed in Three Different Places. Managed Nowhere.
An insurer introduced AI-driven pricing models across four product lines over eighteen months. The risk function tracked the programme. What they didn't do was agree on where AI model risk belonged in the taxonomy.
By the time a regulatory inquiry arrived asking for the organisation's aggregate AI model risk exposure, the answer required pulling from three different registers, under three different classification labels, with three different assessment methodologies. The actuarial team had filed it under technology risk. Compliance had filed the regulatory exposure under regulatory risk. The product team had largely not logged it at all, treating it as a project risk that would close when the implementation completed.
The regulatory inquiry was satisfied eventually. The process took six weeks and two external consultants. The aggregate position, when finally assembled, was materially different from what any individual register had shown.
Honest. Not accusatory.
Emerging Risks Expose Taxonomy Gaps Because They Don't Fit Anywhere That Existed Before.
Every significant new risk type — AI governance, climate physical risk, geopolitical supply chain disruption, crypto-asset exposure — arrives without a natural home in taxonomies built before it existed. The taxonomy was designed for the risks of a previous era.
The immediate response is usually pragmatic and individually rational: file it in the nearest available category. AI model risk goes under technology. Climate risk goes under property. Geopolitical risk goes under supply chain. Each filing makes sense in isolation. Together they produce an organisation that cannot aggregate its exposure to any of the most consequential new risk types.
The problem compounds over time. As more items are filed in adjacent categories, the categories become contaminated. Technology risk now contains both server outage exposure and AI model bias risk — events with completely different characteristics, drivers, and governance responses. The taxonomy becomes progressively less useful for the things that matter most.
Simple. Not simplistic.
The Classification Protocol for New Risk Types: Three Steps Before Filing.
Before any new risk type is filed in an existing category, three questions should be answered. The answers determine whether the existing taxonomy can absorb it or whether the taxonomy needs to be extended.
| STEP | QUESTION | IF YES | IF NO |
|---|---|---|---|
| 1 — Event test | Can the new risk type be described as a specific event with a clear boundary — something that either happens or doesn't? | Proceed to Step 2. | The risk type is not yet defined precisely enough to classify. Spend more time on definition before filing. |
| 2 — Class test | Does an existing class in the taxonomy cover risks with the same underlying event, regardless of the domain or technology involved? | Assign to the existing class. Add the new risk type as a sub-class or attribute. | The existing taxonomy does not cover this risk type. A new class entry is required. |
| 3 — Boundary test | Can three risk professionals independently classify the same event into the same class without discussion? | The classification is sound. Document it and apply it consistently. | The class boundary is ambiguous. Write a boundary rule before classifying any events. |
AI model risk, for example, fails Step 2 for most existing taxonomies: no existing class covers risks arising specifically from model drift, algorithmic bias, or training data contamination as distinct events. The nearest class — technology risk — covers infrastructure failures, not model behaviour. A new sub-class is required, not a filing decision.
This three-step protocol takes twenty minutes to apply to any new risk type. It prevents six weeks of regulatory inquiry reconstruction.
Practical. Not obvious.
Apply the Three-Step Protocol to Your Most Recent Emerging Risk.
Pick the risk type that has emerged most recently in your sector — AI governance, climate, geopolitical supply chain, or any other.
A failure at Step 1 means the risk is not yet defined precisely enough to govern. A failure at Step 2 means the taxonomy needs a new class. A failure at Step 3 means the class needs a boundary rule.
Each failure is a specific, fixable design decision. None of them requires a taxonomy rebuild. They require deliberate choices made before the regulatory inquiry arrives.
Open. Not pushy.
The Integrated Risk Taxonomy Starter Framework
Includes the taxonomy evolution protocol — the triggers, the owner, and the cycle that prevent emerging risks from being silently misclassified for years.
Access here →Book a 45-Minute Decision Architecture Conversation
If the three-step protocol revealed a new risk type that your taxonomy cannot classify cleanly, that's the right conversation to have. Bring the risk type. We'll trace where the classification decision needs to be made.
Book a diagnostic session →That's The Decision Layer for this week.
The insurer's six-week reconstruction was avoidable. Twenty minutes of protocol applied when the AI model risk first arrived would have prevented it. The protocol is not expensive. The reconstruction is.
Forward this to a risk leader who is currently watching a new risk type arrive in their sector and wondering where to file it. The answer is: don't file it yet. Define it first.
