HARNESS D2.4 Risk Assessment and Management Models - Version 1

Context and MotivationThe rapid expansion of artificial intelligence (AI) and data-intensive technologies has led to a comprehensive framework of European Union regulations, including the AI Act, GDPR, Data Governance Act, Digital Services Act, NIS2, DORA, and the Cyber Resilience Act. Central to all of these overlapping legal instruments is a rigorous, cumulative set of compliance obligations anchored around the continuous identification, assessment, and management of risk. While a parallel body of technical standards (such as ISO 31000, ISO/IEC 23894, and ISO/IEC 42001) has evolved to assist organizations, these standards operate at high levels of abstraction and do not map straightforwardly onto regulatory requirements. Organizations face a substantial "translation problem" trying to bridge the gap between abstract legal mandates and operational practices. Deliverable 2.4 addresses this challenge by leveraging semantic web technologies to provide machine-readable, interoperable, and validatable representations that support automated audit and compliance checking of the risk management obligation in Article 9 of the AI Act. This deliverable builds on deliverable 2.2 (Lecat et al., 2026) of the project, a survey of methods and tools for compliance with European AI and data regulation, by considering its findings on semantic technologies and applying them to create the application profile developed in section 5. Key ContributionsTo answer the core research question of how the risk management requirements in Article 9 of the EU AI Act can be modelled using semantic web technologies, the deliverable makes three primary contributions: 1. Systematic Conceptual Analysis of Risk: The report establishes a clear theoretical distinction between two definitional traditions: the deviation-from-objectives tradition (found in organizational standards like ISO 31000) and the harm-oriented tradition (centric to EU regulations targeting impacts on third parties and protected interests). It maps out the layered ISO/IEC standard architecture and differentiates between risk assessments and impact assessments.2. Evaluation and Selection of Semantic Models: The deliverable performs a structured comparative evaluation of ten existing semantic risk management models against six criteria. Based on this analysis, the Data Privacy Vocabulary is selected as the primary general semantic foundation.3. Development of AI Act Application Profile: Grounded in the LOT (Linked Open Terms) methodology, the report extracts 27 atomic, lifecycle-spanning regulatory requirements directly from Article 9 of the AI Act (governing high-risk AI systems). These requirements are operationalized via corresponding clauses in ISO 31000 and ISO/IEC 23894, translated into DPV concepts, and encoded into SHACL (Shapes Constraint Language) shapes. Practical Impact and Future WorkThe resulting application profile has been made open-source on GitHub and integrated into an interactive web application, allowing practitioners to upload semantic risk management files and automatically check them for regulatory completeness and compliance. As part of the iterative progression of Work Package 2 of the HARNESS project, a future version of this deliverable (slated for late 2027) will expand the application profile to cover adjacent legislation like the GDPR, and provide an application of the resources developed here to case studies.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC