S0101RS1-T02-S0101-Z · Full risk code

Insufficient Transparency Undermining Oversight

透明度不足導致監管失效

Operation & Monitoring
Risk Description

When the technical documentation an organization submits is formally complete and passes review, but the reviewing body lacks the capability to verify its substance; due to unmitigated control gaps, a gap exists between the system's actual behavior and the documented description, and that gap cannot be detected under the existing review mechanism, triggering compliance exposure and operational reputational costs.

Framework Mappings

ISO/IEC 42001Annex A.6.2.7
NIST AI RMFGOVERN 1.1
ISO/IEC 23894§6.7
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 6

Risk Treatment & Implementation Guidance

Adopt standardized audit methods and verifiable documentation formats enabling substantive rather than formal review; Provide reviewers reproducible test environments or verification tools evidencing that documentation matches actual system behavior; Periodically self-check documentation against system behavior and proactively update filings