These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.
Deployer AI Risk Register (DARR)

The Deployer AI Risk Register (DARR) is an open, citable catalogue of AI risks for organisations that deploy AI systems rather than develop them. Developed by MindXO, it contains 82 canonical risks and 61 security sub-risks, consolidated from the MIT AI Risk Repository, ISO/IEC standards, MITRE ATLAS and the EU AI Act. It gives deployers a ready-made starting point for building their AI risk management, governance and security programmes.
The register was built in stages. It began with 1 835 risk entries from the MIT AI Risk Repository. Filters were then applied to keep only risks a deployer can observe, measure and act on, and duplicates were removed. Coverage was then expanded using ISO/IEC 23894 and 42001, the EU AI Act and the GPAI Code of Practice, and MITRE ATLAS, which adds technique-level security sub-risks. Finally, six further taxonomies, including the IBM AI Risk Atlas, NIST AI 600-1 and the OWASP Top 10, were mapped entry by entry against the register. None of their 271 entries required a new risk.
Risks are grouped into seven families, such as model and system behaviour, security and adversarial, and regulatory compliance. Each family aligns with a domain that existing enterprise risk, compliance or security functions already manage, so AI risk fits into established frameworks. Each risk has a permanent identifier (MR-001 to MR-082) and mappings to external standards. Organisations add ownership and treatment details to adapt the register to their own deployments. The data is downloadable in CSV and JSON under a CC BY 4.0 licence.
About the tool
You can click on the links to see the associated tools
Developing organisation(s):
Tool type(s):
Objective(s):
Impacted stakeholders:
Purpose(s):
Target sector(s):
Country/Territory of origin:
Lifecycle stage(s):
Type of approach:
Maturity:
Usage rights:
License:
Target groups:
Target users:
Stakeholder group:
Validity:
People involved:
Technology platforms:
Tags:
- ai governance
- ai risk management
- ai compliance
- eu ai act
- nist ai rmf
- ai risk register
- iso42001
- mitre-atlas
- owasp
Github stars:
- 4
Use Cases
Would you like to submit a use case for this tool?
If you have used this tool, we would love to know more about your experience.
Add use case




























