Versatile AI Risk Assessment

The primary sources behind the verified relations

The catalogue backs every relation with a locator in a primary document. The bars show how many references fall to each source entry, grouped by publisher. Selecting an entry shows its version, licence, link and the threats that refer to it.

Who it is for: For assessors, internal audit and anyone judging how solid a source is

Evidence base

486 references to 21 source entries from 7 publishers. Most used: Regulation (EU) 2024/1689 (Artificial Intelligence Act), authentic Official Journal text with 110.

21source entries
12distinct documents
7publishers
486references from the threats

European Union (EUR-Lex) 119 references

National Institute of Standards and Technology (NIST) 119 references

Berryville Institute of Machine Learning (BIML) 67 references

Bundesamt für Sicherheit in der Informationstechnik (BSI) 61 references

OWASP Foundation 60 references

MITRE 57 references

European Data Protection Board (EDPB) 3 references

Select a source entry to see its version, licence, locators and the threats that refer to it.

Framework mappingsThe framework mappings show which reference belongs to which topic group.

The file shows the current state including any filters and carries the note, catalogue version and source.

The number counts references from the threats to the source entry, not the size or the weight of the document. Several entries can belong to the same document when they point to different places within it; the locator is then shown before the title.

Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.

Checking frameworks and evidence

The same data, a different question

Which provision applies, what it does not reach and which primary source the catalogue relies on.

  1. Preview of the analysis: Framework mappings Framework mappings Where is this anchored professionally and legally? For compliance, legal, internal audit and assurance
  2. Preview of the analysis: Coverage gaps Coverage gaps What does my framework not reach? For anyone choosing a framework or already committed to one
Understanding threats
Placing your own system
Planning mitigations

Overview of all ten analyses

Related
Threat catalogue

All 52 threats in full: description, impact, example, mitigations and verified sources.

To the catalogue
EU AI Act quick check

Four short sections along the EU AI Act for a first, non‑binding orientation of your system.

To the quick check
Assess it yourself

The full assessment with system context, threat selection and evidence tracking, free of charge in the browser.

To the live demo