A comparative assessment of four leading AI risk frameworks across five governance dimensions — evaluated against publicly available documentation.
No single framework leads across all five dimensions. Security-origin frameworks (MITRE, OWASP) score well on taxonomy depth and operational controls but show limited coverage for BFSI-specific harms and enterprise governance workflows. Zytra Risk Atlas is the only framework in this benchmark built explicitly for financial services, leading on BFSI specificity, operational controls, and enterprise governance.
| Dimension | What it measures |
|---|---|
| 1Taxonomy depth | Named, classified risks with deployment context tags — not broad categories. Specificity and ontological precision weighted over raw count. |
| 2Agentic AI coverage | Explicit treatment of autonomous agents, multi-agent orchestration, MCP tool risks, memory manipulation, and goal-proxy attacks. |
| 3BFSI specificity | Named financial-services harm categories and clause-level mapping to RBI, SEBI, DORA, or EU AI Act. Generic mentions excluded. |
| 4Operational controls | Each risk paired with an implementable control — defined owner, evidence type, and validation cadence. Gap between risk coverage and control coverage scored. |
| 5Enterprise governance | Support for residual risk calculation, board-level heat map output, control effectiveness scoring, and GRC platform integration. |
Bar length encodes relative strength within each dimension. Scores derived from public documentation; sources listed in Appendix A.
| Framework | Type | Taxonomy Depth |
Agentic Coverage |
BFSI Specificity |
Operational Controls |
Enterprise Governance |
|---|---|---|---|---|---|---|
| Zytra Risk Atlas | Enterprise Product | Highest | Highest | Highest | ||
| MIT AI Risk Repository | Research | |||||
| NIST AI RMF | Standards | |||||
| MITRE ATLAS | Threat Taxonomy | |||||
| OWASP LLM/Agentic Top 10 | Security Reference |
All scores are independent assessments based on public documentation as of August 2026. Corrections welcomed — email the research team via the website.
Clause-level regulatory mapping · Residual risk scoring · Board-ready heat maps