Catalogue of Tools & Metrics for Trustworthy AI

These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.

Enterprise-Wide AI Risk Management (EW-AiRM™)



Enterprise-Wide AI Risk Management (EW-AiRM™)

EW-AiRM™ (Enterprise-Wide AI Risk Management) is a comprehensive framework for governing artificial intelligence across an entire organisation. It is the direct successor to HAiPECR, listed in this catalogue since April 2023 [1], and continues a lineage that began with the Global Conduct Risk Paradigm and the Universal Conduct Risk Paradigm, published via the United Nations UNECE Working Party 6 in 2017 [2], and includes ECE/TRADE/486, the UNECE Common Regulatory Arrangement on products embedding AI (2024), applicable across the 56 UNECE member states [3].

Where HAiPECR provides the ethical and conduct-risk lens, EW-AiRM™ provides the full enterprise operating model around it. The framework is structured across three layers: Strategic (board-level governance, risk appetite and accountability), Operational (day-to-day risk identification, assessment, controls and monitoring across the AI lifecycle) and Resilience (incident response, recovery and preparedness for low-probability, high-impact events). Six supporting pillars span governance, risk, controls, culture, assurance and resilience, designed to integrate with existing enterprise risk management rather than sit alongside it.

HAiPECR is embedded as the framework's ethics, conduct and risk dimension. Its seven thematic dimensions are mapped to the ten core principles of UNESCO's 2021 Recommendation on the Ethics of Artificial Intelligence, with the privacy dimension additionally aligned to UNESCO's 2024 Recommendation on the Ethics of Neurotechnology, giving organisations a direct bridge from internationally agreed principles to auditable practice.

EW-AiRM™ is evidence-based and quantified. It incorporates the MIT AI Risk Repository, maintained by the MIT FutureTech team, covering more than 1,700 catalogued AI risks across 7 domains and 24 subdomains, with 831 mapped controls [4]. A master risk-to-controls mapping enables organisations to move from abstract principles to concrete, testable control environments. The framework also defines eight categories of AI Black Swan events (including multi-agent emergence and the quantum cryptographic transition) for tail-risk resilience planning, and five Non-Negotiables setting the minimum governance conditions for any deployment.

Implementation is proportionate through three tiers (Core, Standard and Full), allowing SMEs, corporates, financial institutions, public bodies and NGOs to adopt the same architecture at a depth appropriate to their exposure. Progress is monitored through KXIs (Key X Indicators), an umbrella for performance, risk and control indicators. The framework is published in full as a Wiley Finance book, Enterprise-Wide AI Risk Management [5], and supported by IRM and IOR practitioner training, an online course, an implementation toolkit and assessment tooling, all accessible via the framework website. It is designed to remain interoperable with the EU AI Act, ISO/IEC 42001, the NIST AI RMF and the Council of Europe Framework Convention on AI.

References

[1] HAiPECR, OECD.AI Catalogue of Tools & Metrics: https://oecd.ai/en/catalogue/tools/haipecr

[2] Universal Conduct Risk Paradigm (UCRP), UNECE WP.6 (2017): https://unece.org/fileadmin/DAM/trade/wp6/documents/2017/GRMF2F/2017_02_22_1400_Krebsz_UCRP_-_Draft_version_22_Feb_2017.pdf

[3] ECE/TRADE/486, UNECE Common Regulatory Arrangement on products embedding AI (2024): https://unece.org/trade/publications/ece_trade_486 

[4] MIT AI Risk Repository, MIT FutureTech (CC BY 4.0): https://airisk.mit.edu

[5] Krebsz, M., Enterprise-Wide AI Risk Management, Wiley Finance (ISBN 9781394446476).

Use Cases

There is no use cases for this tool yet.

Would you like to submit a use case for this tool?

If you have used this tool, we would love to know more about your experience.

Add use case
Partnership on AI

Disclaimer: The tools and metrics featured herein are solely those of the originating authors and are not vetted or endorsed by the OECD or its member countries. The Organisation cannot be held responsible for possible issues resulting from the posting of links to third parties' tools and metrics on this catalogue. More on the methodology can be found at https://oecd.ai/catalogue/faq.