Risk records
Page 1 of 2. 172 records.
Browse the catalog · First JSON page
risk
Excessive privilege and wrong assignment of access rights
risk
Abuse of rights, forged rights, and repudiation of actions
risk
Weak account provisioning/de-registration and access review
risk
Unauthorized use of equipment and unauthorized access escalation
risk
Weak authentication and password management
risk
AI accountability gaps and organizational liability
risk
Adversarial attacks, data poisoning and prompt injection
risk
Unauthorized or unsafe autonomous agent actions and tool calls
risk
Harmful AI bias and discrimination against protected groups
risk
Misuse of AI systems for offensive cyber operations or catastrophic harm
risk
Emergent behaviour and unsafe AI system integration
risk
AI endpoint abuse, scraping and model extraction
risk
Environmental footprint of AI training and infrastructure
risk
GPAI transparency, systemic-risk and synthetic-content obligations
risk
Rights harm from biometric-identification AI
risk
Public-safety harm from AI in critical infrastructure
risk
Unfair exclusion by AI in education and training
risk
Discriminatory outcomes from AI in employment
risk
Unlawful denial of essential services by AI
risk
Harm to due process and democratic integrity from AI
risk
Rights violations from AI in law enforcement
risk
Wrongful denial by AI in migration and border control
risk
Inaccurate, unreliable or hallucinated AI outputs
risk
Inappropriate human/AI task allocation and end-of-life risk
risk
Insecure AI-generated code and hallucinated or typosquatted dependencies
risk
Insufficient human oversight and automation complacency
risk
Lack of AI explainability, documentation and disclosure
risk
Model/data drift and inadequate post-deployment monitoring
risk
Insufficient AI resilience and fallback mechanisms
risk
Poor-quality, unrepresentative or mislabeled training data
risk
AI power concentration and erosion of societal trust
risk
AI privacy leakage and re-identification
risk
Deployment of prohibited AI practices (EU AI Act Art.5)
risk
AI safety failures causing physical or psychological harm
risk
Credential and secret leakage through AI inputs, outputs, logs and generated code
risk
AI supply-chain compromise and provider concentration
risk
Aging hardware with no periodic replacement scheme
risk
Incomplete asset inventory and classification
risk
Uncontrolled copying to removable media / unmanaged software installs
risk
Inadequate security awareness and training
risk
No acceptable-use policy for messaging and telecoms
risk
Phishing, spear-phishing and social engineering
risk
Missing role-based and ongoing security/privacy training
risk
User error and mishandling of sensitive information
risk
IT resilience failure — unplanned outage, data loss, slow recovery
risk
Absent or untested business continuity / disaster recovery plan
risk
Single-site / single-region / single-supply concentration
risk
Client suitability, disclosure and fiduciary breaches
risk
Environmental regulatory non-compliance
risk
Improper business or market practices
risk
Intellectual property loss or infringement
risk
Litigation, investigation and enforcement exposure
risk
Lack of independent audit and compliance review
risk
Adverse regulatory or policy change
risk
Sector regulatory non-compliance (financial, healthcare, trade)
risk
Client selection, sponsorship and exposure-limit breaches
risk
Internet-exposed or misconfigured systems
risk
Poor configuration management and insecure baseline drift
risk
Absent or weak change-control procedures
risk
Credentials and sensitive data transmitted in clear text
risk
Compromised or counterfeit certificates / certificate authority
risk
Weak or absent encryption and key management
risk
Attacks by capable, motivated threat actors
risk
Coordinated multi-stage / APT campaigns
risk
Adversary reconnaissance and information gathering
risk
Unauthorized disclosure / breach of sensitive information
risk
Corruption or integrity loss of critical data
risk
Excessive collection, purpose creep and secondary use
risk
Data exfiltration and theft of information by attackers
risk
Undocumented data inventory and unmapped data flows
risk
Privacy harms: distortion, stigmatization, unwarranted restriction
risk
Privacy-program non-compliance (GDPR, CCPA, state laws)
risk
Re-identification and unanticipated revelation from data
risk
Residual data on improperly disposed or re-used media
risk
Unlawful retention or premature deletion of records
risk
Excessive surveillance, appropriation and induced disclosure
risk
Inadequate transparency, notice and deceptive privacy communications
risk
Physical climate risk to facilities and supply chains
risk
Climate transition risk — carbon pricing and stranded assets
risk
ESG disclosure gaps and greenwashing
risk
Social and human-rights failures in operations and supply chain
risk
Measurement and calculation errors (accuracy)
risk
Understatement of liabilities/expenses (completeness)
risk
Money laundering, sanctions and financial-crime program failures
risk
Period cut-off errors
risk
Data-quality and IPE integrity failures in reporting
risk
Overstatement of assets/revenue (existence & occurrence)
risk
Financial-statement fraud and management override
risk
Ineffective ICFR / undisclosed material weakness
risk
Manual journal entries and management-override risk
risk
Presentation and disclosure deficiencies
risk
Revenue-recognition misstatement (fictitious, mis-timed, mis-measured)
risk
Rights, obligations and related-party misstatement
risk
Segregation-of-duties conflicts in financial processes
risk
Tax provision, deferred-tax and uncertain-position misstatement
risk
Valuation and impairment misstatement
risk
Credit and market (rate/FX) risk
risk
Liquidity, capital-structure and refinancing risk
risk
External fraud — third-party theft, forgery, payment and account fraud
risk
Internal fraud — asset misappropriation, embezzlement, forgery