THE FRAMEWORK

EW-AiRM™: Enterprise-wide AI Risk Management, in three deliberate layers.

Traditional ERM was built for risk that behaves deterministically, with failures that leave a traceable causal chain. AI breaks both assumptions. EW-AiRM™ is the layer that closes the gap, built to augment what you already run, not replace it.

ARCHITECTURE

Three layers. Each does a job the others cannot.

Most AI risk frameworks pick a level and stay there: EW-AiRM™ deliberately spans three layers, because the strategic questions cannot be answered with operational tools alone, and the operational layer cannot anticipate Black Swans. And the HAiPECRTM ethical filter running across all of them. With a AI controls library drawn from over 800 evidence-based mitigations, not just asserted from first principles.

LAYER 1

Strategic

Six pillars. Necessity, readiness, maturity, tolerance, governance and accountability, through-the-lifecycle monitoring. Sets the conditions any AI deployment has to meet before it goes live.

Can also be applied retrospectively, as part of an enterprise's AI maturity assessment.

Complemented by HAiPECRTM, the ethical filter: the same seven questions asked at every significant AI decision, across all three layers, aligned to UNESCO's 2021 Recommendation.

LAYER 2

Operational

MIT AI Risk Repository (CC BY 4.0): more than 1,000 risks across 7 domains and 24 subdomains.

Mapped to 831 controls in 4 quadrants (Governance & Oversight, Technical & Security, Operational Process, Transparency & Accountability).

For control mappings in Primary, Secondary, and Tertiary tiers.

This layer does not ask organisations to build an AI risk taxonomy from scratch; it gives practitioners the evidence base and the tools to apply it.

LAYER 3

Resilience

Eight AI Black Swan categories -governed, governed through Robust Foundations, Continuous Sensing, Adaptive Response.  

Includes multi-agent emergence and the quantum cryptographic transition (NIST FIPS 203/204/205).
For risks that do not fit the operational taxonomy.

The response to unknown unknows is resilience, not prediction.

FLOOR CONDITIONS : The 5 Non-Negotiables

Five things every tier must do.

1

Named accountability for every deployed AI system

2

HAIPECR run as a pre-deployment filter, documented

3

Human override capability tested with a 4-hour SLA

4

Documented board or executive risk acceptance

5

Incident reporting pathway, with named recipient

STRATEGIC LAYER

The six pillars.

Each pillar is a question the organisation must answer in writing before a system can be deployed, and a check that must hold across the deployment lifecycle.

P-I

Strategic Alignment
+ Necessity Assessment


Is AI the right tool for this problem at all? If a deterministic system would do the job, AI is the wrong answer.

P-II

Organisational Readiness

Does the organisation have the people, the controls, and the decision rights to deploy this responsibly?

P-III

Technological Maturity

Is the underlying model, vendor, and integration pattern ready for this use case at this risk level?

P-IV

Risk Tolerance

Has the board signed off on the residual risk, and is the tolerance documented at the right level of granularity?

P-V

Governance & Accountability

Who owns the decision, and who owns the incident? Named, not implied.

P-VI

Through-the-Lifecycle Monitoring
+ Adaptability


What changes trigger a re-review? Who runs the re-review? What is the kill-switch SLA?

ETHICAL OVERLAY

HAIPECR: seven dimensions, mapped to UNESCO.

HAIPECR is the ethical filter that runs across all three layers. Mapped to the UNESCO 2021 Recommendation on the Ethics of AI (10 core principles, not 9). Listed on the OECD AI Policy Observatory since April 2023.

H

Human oversight - Named accountability, override tested.

A

Accountability - mapped to UNESCO P5.

i

Inclusivity - an embedded prerequisite,
not a pillar. (Hence, the lowercase "i").

P

Privacy - Data protection, safety, security.

E

Ethics - Explainability, Transparency, fairness, non-discrimination.

C

Conduct - based on the Universal Conduct Risk Paradigm (UCRP).

R

Resilience - Sustainability, intergenerational rights.

UNESCO MAPPING: H → P7 Human Oversight A → P5 Accountability i → P4 Multi-stakeholder Governance + P9 Awareness & Literacy P → P3 Privacy + P2 Safety & Security (+ 2024 UNESCO Neurotech) E → P6 Transparency & Explainability + P10 Fairness C → P1 Proportionality / Do No Harm R → P8 Sustainability

RESILIENCE LAYER

Eight AI Black Swan categories.

EW-AiRM identifies eight distinct AI Black Swan categories.
Each has discrete characteristics, a distinct reason for unpredictability, and a separate governance response.

The categories are not mutually exclusive: multiple categories can interact, amplifying each other’s effects in ways that make the combined event more severe than any category alone:

Cat 1 — Emergent capability AI Black Swan

Characteristic:

Foundation models exhibit unexpected capabilities not explicitly trained or designed into the system. These capabilities emerge from the complex interactions of billions of parameters in ways that are not predictable from the model’s specification.


Why unpredictable:

Models have billions of parameters; behaviour emerges from complex parameter interactions that cannot be fully predicted even by the engineers who built the system. Capability emerges at scale thresholds that are themselves unpredictable.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 2 — Systemic concentration AI Black Swan

Characteristic:

Failure of a central AI infrastructure element (most prominently a major foundation model provider, but also cloud GPU providers, AI accelerator providers, and vector database providers as the AI stack matures) cascades across thousands of dependent applications simultaneously, creating economy-wide disruption rather than isolated organizational failures.


Why unpredictable:

The scale of dependency across the ecosystem is unknown until failure occurs. Individual organizations assess their own dependency, but no single governance actor has visibility into the aggregate dependency across the entire financial system, healthcare system, or other critical sector.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 3 — Alignment failure AI Black Swan

Characteristic:

A model pursues its specified objectives in ways that are harmful because the optimization process has found a path to the objective that was not anticipated by the system designers. The model does exactly what it was optimized to do. But the optimization produced unintended consequences.


Why unpredictable:

It is difficult to anticipate all the ways in which an optimization process could find a path to an objective that causes harm. The optimization is mathematically correct; the problem is the gap between the specified objective and the intended one. Frontier AI safety research from Anthropic, OpenAI, Google DeepMind, and the UK and US AI Safety Institutes has documented that this gap widens rather than narrows as model capability increases, making alignment failure a structurally growing risk rather than a problem that improves with technical maturity.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.


Cat 4 — Multi-modal integration AI Black Swan

Characteristic:

Unexpected and harmful behaviours emerge from the combination of text, image, audio, and other AI modalities in a system, where the individual modalities have been individually assessed as acceptable, but their combination creates compound effects that were not present in either alone.


Why unpredictable:

The interactions between modalities are difficult to predict from analysis of individual modalities. Biases that are individually manageable may compound in ways that produce qualitatively more severe harm when modalities interact.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 5 — Adversarial breakthrough AI Black Swan

Characteristic:

A novel attack technique is discovered that defeats existing AI defences across the industry: not just one organization’s defences, but the fundamental approaches that all major systems have implemented.


Why unpredictable:

The attack surface of AI models is enormous, and new attack angles are always possible. When a new attack technique is discovered that exploits a fundamental property of the model architecture (for example, the next-token-prediction objective that all language models share, or the gradient-based optimization that all neural networks use), it may work against all models with that architecture regardless of individual defensive measures.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 6 — Supply chain vulnerability AI Black Swan

Characteristic:

Failure or attack in the AI supply chain (training data, model libraries, compute infrastructure, or data annotation services) propagates downstream and compromises all systems built on that supply chain component.

Foundation model provider risk is treated separately as Category 2 (Systemic Concentration); Category 6 covers the upstream and infrastructure layers of the AI supply chain.


Why unpredictable:

Supply chains are complex and their vulnerabilities are hidden until exploited. Malicious actors who understand the supply chain can introduce vulnerabilities at points that affect hundreds of downstream systems simultaneously.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 7 — Multi-agent emergence AI Black Swan

Characteristic:

Failure or harmful behaviour emerges from the interaction between two or more AI systems acting on each other’s outputs, where each system was individually evaluated as acceptable, but the interaction produces compound effects, cascading authority transfer, or coordinated behaviour that no single system was designed to produce. The failure is a property of the interaction, not of any individual agent.


Why unpredictable:

Multi-agent interactions create a combinatorial space that cannot be exhaustively pre-evaluated. Each agent’s behaviour is bounded; each agent’s interaction with another agent is bounded; the combination of N agents interacting across M tools and K decision points produces a behaviour space that exceeds practical evaluation capacity. Emergent behaviours, including coordination, deception, and goal drift, have been documented in research environments and are increasingly observed in production agentic deployments. Traditional safety evaluation evaluates one agent at a time; multi-agent emergent failure is invisible to that evaluation methodology by construction.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

Cat 8 — Quantum cryptographic transition AI Black Swan

Characteristic:

A cryptographically relevant quantum computer becomes available (either 

through gradual capability development or a discontinuous breakthrough), and the cryptographic foundations of AI infrastructure become simultaneously vulnerable: standard cryptographic surfaces (TLS, API authentication) and AI-specific cryptographic dependencies (model weight integrity verification, audit trail signing, supply-chain attestation through model signing) across the entire deployed AI estate.


Separately, previously-exfiltrated encrypted data (acquired via the HNDL attack) becomes decryptable retroactively.


Why unpredictable:

The Q-Day timeline is bounded but uncertain. Expert estimates from the Global Risk Institute Quantum Threat Timeline Report (Mosca and Piani 2024) and equivalent sources cluster around 2034–2036 with considerable tail risk extending from the late 2020s into the 2040s. A breakthrough in quantum error correction, a new qubit modality reaching scale, or a classical algorithmic attack on post-quantum schemes could shift the timeline discontinuously.


Governance response:

Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.

WHERE THIS COMES FROM

The framework lineage.

EW-AiRM™ is grounded in publicly licensed standards: the MIT AI Risk Repository (CC BY 4.0), the UNESCO 2021 Recommendation on the Ethics of AI, NIST AI RMF, ISO 31000 (general risk), ISO 42001 (AI risk management systems), and the UNECE (ECE/TRADE/486, 2024). HAIPECR was originated by Prof. Markus Krebsz and has been listed on the OECD AI Policy Observatory since April 2023.

Here's a comparsion of EW-AiRMTM with those other frameworks and the EU AI Act:

DimensionEW-AiRM™NIST AI RMFISO 42001COSO ERMEU AI Act
UNECE-groundedYes
(ECE/TRADE/486)
NoNoNoNo
Primary scope Enterprise-wide AI
Risk Governance
framework
& approach
AI Risk
Management
AI
Management
System
(Traditional)
Enterprise
Risk 
Management
AI Regulation
Target audienceBoards,
Risk functions,
CTOs, CISO,
Risk community
US Federal &
Enterprise
Any
organisation
CFO, Board,
ERM teams
Operators &
Providers (EU)
Layers Strategic,
Operational,
Resilience
+ HAiPECR
Govern, 
Map,
Measure,
Manage
Plan,
Do,
Check,
Act
Strategy,
Performance
Prohibited,
High-risk,
GPAI
CertifiableNo
(Open framework)
No
(Voluntary)
Yes
(ISO audit)
No
(Guidance)
Public, EU-wide
Regulation
Open / free Yes
(CC BY 4.0 base)
YesPaid 
standard
Paid
guidance
Public 
regulation
UNESCO-alignedYes (HAiPECR)NoPartialNoPartial (GPAI)

Want the practical version?

The framework is the conceptual picture. The three-tier comparison shows what it looks like in deployment.