[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83640-en":3,"doc-seo-83640-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83640,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","The Eticas AI Risk Taxonomy Open Infrastructure for Operationalizing AI Audits","Rapid deployment of AI in high-stakes domains has intensified demand for standardized evaluation, yet AI auditing remains fragmented across competing risk taxonomies that catalog risks without showing how audits are actually executed. At least 74 taxonomies exist, but operationalizing a risk—turning it into executable tests, measured metrics, calibrated severity, and defensible grades—is the key challenge. The work presents Eticas’ operationalization layer, demonstrates it end-to-end on PII leakage using a public benchmark, and scales via an open taxonomy with formal mappings to external frameworks.","arXiv :2607 .0220 1v 1 [ cs .CY] 2 Jul 2026  \nThe Eticas AI Risk Taxonomy: Open Infrastructure for Operationalizing AI Audits  \nGemma Galdon Clavell Pablo Accuosto Usman Gohar  \n[Eticas.ai](Eticas.ai)  \nTaxonomy version 2.0.0 | Paper draft: July 2026  \nAbstract  \nThe rapid deployment of AI systems across high-stakes domains has created urgent demand for standardized evaluation, yet the field remains fragmented across competing risk taxonomies that catalog risks without showing how an audit is actually executed. At least 74 AI risk taxonomies now exist; and almost all stop at the catalog. The hard part of auditing is not naming a risk but operationalizing it: turning a named risk into a test run against a real system, a measured value, a calibrated severity, and a defensible grade. This paper leads with that bridge. We present the operationalization layer Eticas has built and run, shown end to end on a single risk (PII leakage) against a public benchmark, and then the open taxonomy that makes the method scale. On GPT-4-0314, the same disclosure risk that seven external frameworks require be controlled is measured at 0%, 51%, and 84% disclosure as adversarial conditioning increases, mapping through calibrated severity bands to a subcategory grade of E with a SYSTEMIC pattern. Around this worked example, the Eticas AI Risk Taxonomy v2.0.0 organizes 76 active subcategories across 10 categories and 20 sub-groups, with formal mappingsto 18 external frameworks across compliance, reference, and academic tiers. Its category and sub-group layer is published under CC BY 4.0 as open semantic infrastructure with stable URIsand SKOS/JSON-LD distributions, and a worked subcategory example is published to show the operational layer down to its severity thresholds. The contribution is the demonstrated bridge from concept to graded finding, anchored by a clean ontological separation of risks from the mechanisms by which they surface (the published seam at which any operationalization attaches), and framed by an open-core model in which the conceptual scaffold is open and the methodology calibration is the practitioner layer. This is the infrastructure the AI auditing field needs: shared, open, and demonstrably operable.  \nKeywords: AI risk taxonomy, algorithmic auditing, AI evaluation, operationalization, agentic AI, EU AI Act, open infrastructure  \n1 Introduction  \nArtificial intelligence systems now mediate consequential decisions across employment, credit, healthcare, criminal justice, and public services. With generative AI and LLMs, they also mediate access to and production of information (Bender et al., 2021) . This deployment velocity has catalyzed regulatory responses worldwide: the European Union’s AI Act (Regulation 2024/1689) entered into force in August 2024 with full application phased to 2027; the United States published the NIST AI Risk Management Framework in January 2023, followed by a Generative AI Profile in July 2024; China released version 2.0 of its TC260 AI Safety Governance Framework in September 2025; and the Council of Europe opened the first binding international AI treaty for  \nsignature in September 2024 . These frameworks mandate risk assessment, impact evaluation, and ongoing monitoring, yet they provide categories at abstraction levels poorly suited to operational implementation.  \nConsider the EU AI Act’s obligation for providers of high-risk AI to establish quality management systems ensuring compliance across data governance, technical documentation, transparency, human oversight, accuracy, robustness, and cybersecurity (Articles 9 to 15) . Or ISO/IEC 42001:2023’s requirement that organizations assess and treat AI-related risks through systematic impact assessment (Annex A.5) . These obligations presuppose that evaluators can decompose “accuracy” or “fairness” into measurable assessment criteria, yet the regulations offer limited guidance on how to structure that decomposition.  \nThe field’s response has been","cbCaifTG2QtEuT6A","https://ap.wps.com/l/cbCaifTG2QtEuT6A","pdf",696257,2,1,26,"English","en",105,"# Introduction\n## AI systems in high-stakes domains\n## Regulatory demands and abstraction gaps\n## Fragmentation caused by heterogeneous taxonomies\n## The missing bridge: from risk naming to executed audits\n# Approach and operationalization layer\n## Inductive end-to-end audit chain demonstration\n## Mapping calibrated severity to graded findings\n## Open taxonomy infrastructure and external framework alignments","[{\"question\":\"What problem does the paper identify in current AI risk taxonomies?\",\"answer\":\"Most taxonomies catalog and classify risks, but they do not explain how a named risk becomes an executed audit test, a measurable metric, a calibrated severity, and a defensible grade.\"},{\"question\":\"How does the paper operationalize the taxonomy for an audit?\",\"answer\":\"It builds an operationalization layer that converts a selected risk into test design, execution, measurement, and graded judgment, then demonstrates this end-to-end on a specific worked example (PII leakage).\"},{\"question\":\"How is the taxonomy scaled and linked to external standards?\",\"answer\":\"The taxonomy version v2.0.0 organizes active subcategories across multiple categories and sub-groups, publishing the category/sub-group layer as open semantic infrastructure with stable URIs and SKOS/JSON-LD distributions, and providing formal mappings to external frameworks.\"}]",1784189441,66,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"the-eticas-ai-risk-taxonomy-open-infrastructure-for-operationalizing-ai-audits","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/the-eticas-ai-risk-taxonomy-open-infrastructure-for-operationalizing-ai-audits/83640/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper identify in current AI risk taxonomies?","Question",{"text":75,"@type":76},"Most taxonomies catalog and classify risks, but they do not explain how a named risk becomes an executed audit test, a measurable metric, a calibrated severity, and a defensible grade.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper operationalize the taxonomy for an audit?",{"text":80,"@type":76},"It builds an operationalization layer that converts a selected risk into test design, execution, measurement, and graded judgment, then demonstrates this end-to-end on a specific worked example (PII leakage).",{"name":82,"@type":73,"acceptedAnswer":83},"How is the taxonomy scaled and linked to external standards?",{"text":84,"@type":76},"The taxonomy version v2.0.0 organizes active subcategories across multiple categories and sub-groups, publishing the category/sub-group layer as open semantic infrastructure with stable URIs and SKOS/JSON-LD distributions, and providing formal mappings to external frameworks.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]