Issue 22·7 min read·Board Members  ·  C-Suite  ·  Senior Risk Leaders
This week: An insurer's taxonomy has no category for AI model risk. The actuarial team has been filing it under 'technology,' the compliance team under 'regulatory,' and the product team hasn't been logging it at all. Why emerging risks expose taxonomy gaps faster than any other force. The classification protocol for new risk types. One version check.
01THE SIGNAL

Sharp. Not sentimental.

AI Model Risk. Filed in Three Different Places. Managed Nowhere.

An insurer introduced AI-driven pricing models across four product lines over eighteen months. The risk function tracked the programme. What they didn't do was agree on where AI model risk belonged in the taxonomy.

By the time a regulatory inquiry arrived asking for the organisation's aggregate AI model risk exposure, the answer required pulling from three different registers, under three different classification labels, with three different assessment methodologies. The actuarial team had filed it under technology risk. Compliance had filed the regulatory exposure under regulatory risk. The product team had largely not logged it at all, treating it as a project risk that would close when the implementation completed.

The regulatory inquiry was satisfied eventually. The process took six weeks and two external consultants. The aggregate position, when finally assembled, was materially different from what any individual register had shown.

02THE PATTERN

Honest. Not accusatory.

Emerging Risks Expose Taxonomy Gaps Because They Don't Fit Anywhere That Existed Before.

Every significant new risk type — AI governance, climate physical risk, geopolitical supply chain disruption, crypto-asset exposure — arrives without a natural home in taxonomies built before it existed. The taxonomy was designed for the risks of a previous era.

The immediate response is usually pragmatic and individually rational: file it in the nearest available category. AI model risk goes under technology. Climate risk goes under property. Geopolitical risk goes under supply chain. Each filing makes sense in isolation. Together they produce an organisation that cannot aggregate its exposure to any of the most consequential new risk types.

The problem compounds over time. As more items are filed in adjacent categories, the categories become contaminated. Technology risk now contains both server outage exposure and AI model bias risk — events with completely different characteristics, drivers, and governance responses. The taxonomy becomes progressively less useful for the things that matter most.

The most dangerous risks are the ones that don't fit the taxonomy. Not because the taxonomy missed them, but because nobody updated it when they arrived.
03THE MODEL

Simple. Not simplistic.

The Classification Protocol for New Risk Types: Three Steps Before Filing.

Before any new risk type is filed in an existing category, three questions should be answered. The answers determine whether the existing taxonomy can absorb it or whether the taxonomy needs to be extended.

STEPQUESTIONIF YESIF NO
1 — Event testCan the new risk type be described as a specific event with a clear boundary — something that either happens or doesn't?Proceed to Step 2.The risk type is not yet defined precisely enough to classify. Spend more time on definition before filing.
2 — Class testDoes an existing class in the taxonomy cover risks with the same underlying event, regardless of the domain or technology involved?Assign to the existing class. Add the new risk type as a sub-class or attribute.The existing taxonomy does not cover this risk type. A new class entry is required.
3 — Boundary testCan three risk professionals independently classify the same event into the same class without discussion?The classification is sound. Document it and apply it consistently.The class boundary is ambiguous. Write a boundary rule before classifying any events.

AI model risk, for example, fails Step 2 for most existing taxonomies: no existing class covers risks arising specifically from model drift, algorithmic bias, or training data contamination as distinct events. The nearest class — technology risk — covers infrastructure failures, not model behaviour. A new sub-class is required, not a filing decision.

This three-step protocol takes twenty minutes to apply to any new risk type. It prevents six weeks of regulatory inquiry reconstruction.

04THE MOVE

Practical. Not obvious.

Apply the Three-Step Protocol to Your Most Recent Emerging Risk.

Pick the risk type that has emerged most recently in your sector — AI governance, climate, geopolitical supply chain, or any other.

Run the three steps: Can you describe it as a specific event? Does an existing class cover the same underlying event? Can three people independently classify the same incident into the same class? Note where it fails.

A failure at Step 1 means the risk is not yet defined precisely enough to govern. A failure at Step 2 means the taxonomy needs a new class. A failure at Step 3 means the class needs a boundary rule.

Each failure is a specific, fixable design decision. None of them requires a taxonomy rebuild. They require deliberate choices made before the regulatory inquiry arrives.

05THE INVITATION

Open. Not pushy.

FRAMEWORK DOWNLOAD

The Integrated Risk Taxonomy Starter Framework

Includes the taxonomy evolution protocol — the triggers, the owner, and the cycle that prevent emerging risks from being silently misclassified for years.

Access here →
DIAGNOSTIC SESSION

Book a 45-Minute Decision Architecture Conversation

If the three-step protocol revealed a new risk type that your taxonomy cannot classify cleanly, that's the right conversation to have. Bring the risk type. We'll trace where the classification decision needs to be made.

Book a diagnostic session →

That's The Decision Layer for this week.

The insurer's six-week reconstruction was avoidable. Twenty minutes of protocol applied when the AI model risk first arrived would have prevented it. The protocol is not expensive. The reconstruction is.

Forward this to a risk leader who is currently watching a new risk type arrive in their sector and wondering where to file it. The answer is: don't file it yet. Define it first.