S0059RS1-T03-S0059-Z · Full risk code

Opaque Decisions Obstructing Accountability

黑箱決策阻礙問責追溯

Verification & Validation
Risk Description

When after a system makes a decision that causes harm, the organization invests resources in analysis but cannot determine the cause; due to unmitigated control gaps, it can neither explain the outcome to those affected nor guarantee that similar problems will not recur, and can only respond through after-the-fact compensation while the underlying issue persists, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.86
ISO/IEC 42001Annex A.6.2.8、A.8.2
NIST AI RMFMEASURE 2.9、MANAGE 4.1
ISO/IEC 5338驗證與確效
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Deploy decision audit trails from system build, fully retaining inputs, model versions and intermediate bases so decisions can be reconstructed; Prefer more interpretable models or pair with explanation tooling for high-impact uses, making opacity a selection criterion; Establish root-cause procedures so harm events without identified causes are escalated rather than closed with compensation alone