KROG
🇳🇴

CWA 18398 · assessment rubric

E.3 Risk Management

← All competences

Level e-2

From role 1.4 Data Engineer · EQF EQF6

Support safe and responsible AI system operations by identifying, describing, and documenting technical, operational, ethical, and privacy risks in accordance with organisational policies and standard monitoring tools.

  1. 5.1 Identify common AI system risks, including bias, model drift, and data privacy issues, by referring to organisational policies and guidelines in operational AI systems.

    Assessed by Written report or checklist evaluating identification of common AI risks in a sample operational system, including bias, model drift, and data privacy issues; observation of correct reference to and application of organisational policies and guidelines.

  2. 5.2 Describe AI system behaviours and operational characteristics using standard monitoring tools and templates in deployed AI applications.

    Assessed by Review of standardized system behaviour logs or monitoring templates, assessed for completeness, accuracy, and correct description of AI system behaviours and operational characteristics in deployed AI applications.

  3. 5.3 Record AI risk incidents and observations in standardized registers within organisational AI workflows.

    Assessed by Inspection of risk incident registers documenting AI incidents, anomalies, and observations, graded for clarity, correctness, completeness, and fit with standardized organisational AI workflows.

  4. 5.4 Recognize ethical and compliance-related considerations in the use of AI systems in predictable operational contexts such as customer support or data processing tasks.

    Assessed by Short case-study assignment or quiz assessing recognition of ethical and compliance-related considerations in predictable operational AI contexts such as customer support or data processing tasks.

  5. 5.5 Apply basic AI risk documentation techniques to support supervisors or team members in operational decision-making.

    Assessed by Submission of operational risk documentation, reviewed for structure, clarity, traceability, and usefulness for supervisors or team members in operational decision-making.

Level e-3

From role 1.2 Data Curation Lead · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities.

  1. 4.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness and methodological correctness; assessed for systematic identification of risks related to data quality, integrity, lineage, and governance, and for appropriate application of risk assessment methods and justification of findings.

  2. 4.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, and alignment with organisational objectives; evaluated for prioritisation of risks, clarity of assumptions, and linkage to data curation processes and operational context.

  3. 4.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, and alignment with defined project boundaries; evaluated for effectiveness of proposed mitigation measures, integration with data governance frameworks, and ability to address risks across the data lifecycle.

  4. 4.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of risk findings, and stakeholder engagement; assessed for ability to explain risk scenarios, justify mitigation decisions, and adapt communication to technical and non-technical stakeholders.

  5. 4.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis; evaluated for accuracy of risk detection, depth of analysis, and ability to relate observed behaviour to underlying data quality and governance issues.

  6. 4.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned and adherence to organisational standards; assessed for completeness, traceability of changes, and effectiveness in improving ongoing risk management practices.

From role 2.1 AI Architect · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities.

  1. 7.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 7.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 7.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 7.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 7.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 7.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 2.11 AI Incident Response & Reporting Lead · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 4.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 4.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 4.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 4.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 4.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 4.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 2.12 AI Platform Engineer · EQF EQF6

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 6.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 6.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 6.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 6.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 6.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 6.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 2.6 AI Quality & Evaluation Specialist · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 6.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 6.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 6.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 6.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 6.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 6.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 2.9 AI Reliability Engineer · EQF EQF6

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 4.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 4.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 4.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 4.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 4.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 4.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 3.1 AI Security Specialist · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 5.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks in project or service contexts.

  2. 5.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the operational environment of AI deployments.

  3. 5.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application of mitigation measures, and alignment with defined project, product, or service boundaries.

  4. 5.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings and mitigation plans, and suitability for team members and stakeholders in project or organisational settings.

  5. 5.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks and analysis, assessed for detection of model drift, data anomalies, or other emerging AI risks.

  6. 5.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 3.4 AI Advisor · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities.

  1. 5.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 5.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 5.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 5.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 5.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 5.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 3.5 AI Safety Specialist · EQF EQF6

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 7.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

  2. 7.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

  3. 7.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

  4. 7.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

  5. 7.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

  6. 7.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

From role 3.8 Human-AI Interaction Lead · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 7.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 7.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 7.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 7.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 7.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 7.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 4.4 AI Manager · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 4.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 4.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 4.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 4.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 4.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 4.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 4.6 AI Operations Manager · EQF EQF6

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 6.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 6.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 6.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 6.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 6.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 6.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 4.7 AI Project Manager · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 5.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 5.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 5.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 5.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 5.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 5.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 5.2 AI Compliance Officer · EQF EQF7

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 5.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 5.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 5.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 5.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 5.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 5.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies.

From role 5.4 AI Auditor · EQF EQF6

Mitigate AI-related risks in projects or services by analysing potential technical, operational, ethical, and regulatory hazards and applying governance frameworks to propose and implement effective solutions aligned with organisational priorities

  1. 5.1 Analyse AI systems for potential technical, operational, ethical, and regulatory risks using structured risk assessment methods in project or service contexts.

    Assessed by Written AI risk assessment report evaluated against completeness, methodological correctness, and coverage of technical, operational, ethical, and regulatory risks.

  2. 5.2 Assess the impact and likelihood of AI risks by considering organisational objectives and the operational environment of AI deployments.

    Assessed by Risk impact and likelihood matrix graded for accuracy, logical reasoning, alignment with organisational objectives, and consideration of the AI deployment environment.

  3. 5.3 Propose mitigation measures and apply them to reduce AI-related risks within defined projects, products, or service boundaries.

    Assessed by Mitigation plan submission assessed for feasibility, relevance, application to reduce AI- related risks, and alignment with defined project, product, or service boundaries.

  4. 5.4 Communicate AI risk findings and mitigation plans effectively to team members and stakeholders in project or organisational settings.

    Assessed by Oral presentation or report evaluated for clarity, communication of AI risk findings, mitigation plans, and stakeholder engagement in project or organisational settings.

  5. 5.5 Monitor AI system performance to detect emerging risks such as model drift or data anomalies.

    Assessed by Review of AI system performance logs, annotated with identified emerging risks such as model drift or data anomalies and supporting analysis.

  6. 5.6 Review and update risk documentation in line with organisational policies and lessons learned from previous incidents.

    Assessed by Updated risk documentation evaluated for incorporation of lessons learned, adherence to organisational standards, and alignment with organisational policies. Annex D (informative) Role profile template

Level e-4

From role 4.2 Chief AI Officer (CAIO) · EQF EQF8

Strengthen organisational AI risk strategies by evaluating multi-dimensional AI system risks and designing governance processes that integrate operational, ethical, legal, and third-party considerations while recommending improvements.

  1. 7.1 Evaluate AI system risks considering technical, operational, legal, ethical, and third-party dimensions in organisational contexts.

    Assessed by Comprehensive AI risk evaluation report graded for depth, contextual reasoning, and coverage of technical, operational, legal, ethical, and third-party AI system risks.

  2. 7.2 Design and monitor AI governance processes that address multi-factor AI risks in enterprise or institutional environments.

    Assessed by Submission of AI governance framework design evaluated for process completeness, scalability, monitoring approach, and alignment with organisational needs in enterprise or institutional environments.

  3. 7.3 Recommend improvements to AI risk strategies to enhance compliance, resilience, and responsible AI adoption in organisational practice.

    Assessed by Strategic recommendations document assessed for practicality, impact, and contribution to compliance, resilience, and responsible AI adoption in organisational practice.

  4. 7.4 Coordinate cross-functional activities to ensure consistent application of AI risk management practices across teams or departments.

    Assessed by Cross-functional coordination report evaluated for documentation of collaborative activities and consistent application of AI risk management practices across teams or departments.

  5. 7.5 Analyse organisational policies to align AI risk governance processes with strategic objectives and regulatory requirements.

    Assessed by Policy alignment analysis assessed for clarity, alignment with regulatory requirements, and integration of AI risk governance processes with organisational strategy.

From role 5.1 AI Governance Officer · EQF EQF8

Strengthen organisational AI risk strategies by evaluating multi-dimensional AI system risks and designing governance processes that integrate operational, ethical, legal, and third-party considerations while recommending improvements.

  1. 6.1 Evaluate AI system risks considering technical, operational, legal, ethical, and third-party dimensions in organisational contexts.

    Assessed by Comprehensive AI risk evaluation report graded for depth, contextual reasoning, and coverage of technical, operational, legal, ethical, and third-party AI system risks.

  2. 6.2 Design and monitor AI governance processes that address multi-factor AI risks in enterprise or institutional environments.

    Assessed by Submission of AI governance framework design evaluated for process completeness, scalability, monitoring approach, and alignment with organisational needs in enterprise or institutional environments.

  3. 6.3 Recommend improvements to AI risk strategies to enhance compliance, resilience, and responsible AI adoption in organisational practice.

    Assessed by Strategic recommendations document assessed for practicality, impact, and contribution to compliance, resilience, and responsible AI adoption in organisational practice.

  4. 6.4 Coordinate cross-functional activities to ensure consistent application of AI risk management practices across teams or departments.

    Assessed by Cross-functional coordination report evaluated for documentation of collaborative activities and consistent application of AI risk management practices across teams or departments.

  5. 6.5 Analyse organisational policies to align AI risk governance processes with strategic objectives and regulatory requirements.

    Assessed by Policy alignment analysis assessed for clarity, alignment with regulatory requirements, and integration of AI risk governance processes with organisational strategy.

From role 5.3 AI Risk Manager · EQF EQF7

Strengthen organisational AI risk strategies by evaluating multi-dimensional AI system risks and designing governance processes that integrate operational, ethical, legal, and third-party considerations while recommending improvements

  1. 5.1 Evaluate AI system risks considering technical, operational, legal, ethical, and third-party dimensions in organisational contexts.

    Assessed by Comprehensive AI risk evaluation report graded for depth, contextual reasoning, and coverage of technical, operational, legal, ethical, and third-party AI system risks.

  2. 5.2 Design and monitor AI governance processes that address multi-factor AI risks in enterprise or institutional environments.

    Assessed by Submission of AI governance framework design evaluated for process completeness, scalability, monitoring approach, and alignment with organisational needs in enterprise or institutional environments.

  3. 5.3 Recommend improvements to AI risk strategies to enhance compliance, resilience, and responsible AI adoption in organisational practice.

    Assessed by Strategic recommendations document assessed for practicality, impact, and contribution to compliance, resilience, and responsible AI adoption in organisational practice.

  4. 5.4 Coordinate cross-functional activities to ensure consistent application of AI risk management practices across teams or departments.

    Assessed by Cross-functional coordination report evaluated for documentation of collaborative activities and consistent application of AI risk management practices across teams or departments.

  5. 5.5 Analyse organisational policies to align AI risk governance processes with strategic objectives and regulatory requirements.

    Assessed by Policy alignment analysis assessed for clarity, alignment with regulatory requirements, and integration of AI risk governance processes with organisational strategy.