Versatile AI Risk Assessment

Who it is for Expert witnesses and assessors

Traceable foundations for an expert opinion

An expert opinion needs traceable sources, assumptions and assessment steps. The application helps you investigate AI threats systematically and document your findings. Learn how to review sources and record the catalogue version you used.

The starting point

An expert opinion needs three things software can supply: a stated basis, a statement that leads back to that basis, and a result that stays the same for the same input. What software cannot supply is the judgement a specific case calls for; that remains with the expert.

The catalogue behind this application is therefore built so that every mapping carries its reference. Without a reference no entry is created. The catalogue version and the legal status appear on every output, so that it remains visible later which state an opinion was based on.

What software cannot supply is the judgement a specific case calls for. It supplies a stated basis, a statement that leads back to it, and a result that stays the same for the same input.

Assessments step by step (3)

Each step links to the relevant features and information.

  1. State the basis Catalogue version, legal status and the frameworks the opinion rests on.
  2. Assess Rule-based assessment across system context, threats and mitigations.
  3. Weigh the evidence base Read off for each threat how many references it carries and from which frameworks.

Questions and answers (7)

Answers with sources and links for further review.

What do the assessments in the threat catalogue rest on?

On 486 documented mappings drawn from 21 primary sources across seven frameworks: the EU AI Act, the GDPR, the risk management framework of the US standards institute, the priority list of the OWASP Foundation, the MITRE ATLAS knowledge base, the publications of the German federal office for information security, and the architectural analyses of the Berryville Institute. Each of the 52 threats lists its mappings individually.

Does the same input lead to the same result?

Yes. The assessment follows fixed rules across system context, threat selection and mitigations; no language model and no random component enters the result. Anyone assessing the same system context twice receives the same result twice, including on a different machine.

How can I tell which state a result is based on?

Every output carries the catalogue version and the legal status. The catalogue currently stands at version 2026.07.17.3, the legal status is Regulation (EU) 2026/1744, in force since 27 July 2026. Both appear on the pages and in the generated documents, so that an older opinion can be placed in context later.

Which frameworks does the catalogue not cover?

The catalogue holds seven frameworks. Management system standards for artificial intelligence are not among them, nor are sector-specific rules such as those for medical devices or financial services. Every framework page states explicitly which threats that framework does not reach.

How solid is the evidence base for a single threat?

This can be read off for each threat. The evidence-base analysis shows how many references a threat carries and which frameworks they come from. Threats with a single reference are identifiable as such and should carry different weight in an opinion than those supported across several frameworks.

Can I cite an entry from the catalogue?

Yes. Every threat page and every term page carries a suggested citation at the end, with title, work, version and address. The addresses of the entries are permanent and do not change, so that a reference from an opinion still holds later.

What does the application explicitly not do for an expert opinion?

It does not judge the individual case and replaces no expert opinion. Nor does it judge whether a measure is appropriate in a specific case. It is certified against no standard and carries no management system standard for artificial intelligence. And it says nothing about whether a result will hold up in court; that is for the court to decide.

Limits of the application (4)

These tasks require additional tools or professional review.

Tasks outside the application

  • It does not judge the individual case and replaces no expert opinion.
  • It is certified against no standard and carries no management system standard for artificial intelligence.
  • It says nothing about whether a result will hold up in court.
  • The catalogue covers no sector-specific rules, for example for medical devices or financial services.

Suitable editions

€2,490 once

Professional Offline

For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.

Open
free of charge

Live demo to get to know it

The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.

Open

Compare the features, licence terms and prices of the Community, Professional and Enterprise editions. Compare editions

Other audiences (7)

Guidance for other responsibilities within your organisation or your clients’ organisations.

← Back to the overview