Product · Governance

The risk you haven't named is a risk you cannot govern.

Zytra AI Governance gives BFSI institutions a living risk atlas, measured control effectiveness, and board-ready residual scoring — so the answer to "how exposed are we?" is a number, not a conversation.

141
AI risks — 77 agentic + 64 foundational — across 11 governance domains
13
Framework crosswalks: NIST, OWASP, MITRE ATLAS, EU AI Act, DORA, RBI
4
Control effectiveness dimensions: coverage, testability, effectiveness, alignment
5
Maturity levels from reactive to governed — most banks sit at Level 2–3
The governance gap

A model risk register tells you what's deployed. It doesn't tell you what could go wrong.

MRM asks: does this model perform as specified on validation data? It does not ask what happens when a RAG pipeline retrieves the right document and still outputs the wrong number — or when an agent acquires capabilities beyond its declared scope.

Model inventory ≠ risk atlas

Knowing which models are in production and when they were last validated tells you nothing about hallucination rates, prompt injection exposure, or fairness gaps in a BFSI context. Those require a separate framework.

Controls without measurement

A control listed in a GRC tool is not a tested control. Design-stage controls that have never been proven to work carry 0% effectiveness — even when they appear in an audit submission as "implemented."

No residual score for the board

The board's question is: after our controls are applied, how exposed are we? A list of 141 risks is not an answer. A domain heat map with residual scores is. Most institutions cannot produce one.

Zytra Risk Atlas v1.0 · August 2026

141 AI risks. 77 agentic, 64 foundational. Every framework a BFSI regulator will ask about.

The atlas is the foundation. 77 agentic and 64 foundational AI risks, each classified by domain, mapped to regulatory frameworks at the clause level, tagged to deployment patterns, linked to controls, and scored for residual exposure after those controls are applied.

Risk taxonomy

Structured catalogue across Model Accuracy, Security, Fairness, Governance, Privacy, Agent Autonomy, Multi-Agent Security, Tool Risk, and more — organized by domain, not by product or model name, so cross-cutting risks don't fall through the gaps.

Framework crosswalks

Each risk mapped to NIST AI RMF, OWASP LLM Top-10, MITRE ATLAS, ISO/IEC 42001, EU AI Act, DORA, and RBI guidelines — at the clause level, not just the framework name. Audit translation work done before the auditor arrives.

Deployment-pattern tagging

Each risk tagged to RAG pipelines, autonomous agents, multi-agent orchestration, document summarization, or classification. Filter the atlas to "risks relevant to my mortgage extraction pipeline" — not a reference document, a deployment checklist.

Control assignments

Each risk linked to specific controls with named owners, implementation status, test evidence, and last-validated date. A control without an owner is a recommendation. A control with a test result and a timestamp is a governance fact.

Evidence levels

Every risk graded as Realized (observed in production), Demonstrated (proven in research), or Theoretical (plausible, unobserved) — so risk management effort is proportional to actual threat evidence, not just regulatory prominence.

Residual scoring

After controls are applied, what exposure remains? Residual risk score = inherent risk × (1 − control effectiveness). The output is a board-ready heat map: which domains are still at High, and where the next investment has the most impact.

Explore the full Risk Atlas → Download Atlas JSON ↓
→ How does the Zytra Risk Atlas compare to MIT, MITRE, NIST, and others? See the benchmark · → Assess your organization's AI risk posture — free, 5-minute tool
AI Risk Maturity

Five levels. Most banks sit at Level 2.

You don't need to reach Level 5 before deploying your first AI system. But you need to know which level you occupy — because the gap between current maturity and deployment ambition is itself a risk.

01

Reactive

Risk knowledge lives in individual engineers. No formal catalogue. Incidents discovered after the fact. Coverage is a function of who happens to know which system.

"We do model validation" — focused on statistical accuracy, not systemic AI risk.
02

Catalogued

Risks have been named. A list exists, probably in a spreadsheet. No consistent domain classification, no framework mapping, no controls assigned. Created once, not updated since.

"We have an AI risk register in Confluence" — hasn't been reviewed in 14 months.
03

Mapped

Risks classified by domain, mapped to regulatory frameworks, linked to controls with assigned owners. The atlas is reviewable by an auditor. This is where Zytra starts.

NIST AI RMF crosswalk complete; controls have owners and live in the GRC tool.
04

Measured

Controls have effectiveness scores. Residual risk is quantified per domain. The atlas answers: "After our controls, what is our actual exposure?" Heat maps drive investment decisions.

Residual risk scores by domain; control testing results on file; backlog derived from gap analysis.
05

Governed

The atlas is a living system. Board-level risk appetite defined against specific domains. Monitoring automated where possible. Regulator inquiries answered with evidence, not policy documents.

Board-approved AI risk appetite statement; continuous monitoring; submissions backed by evidence trails.
Control effectiveness

A control listed in your GRC tool is not a tested control.

Four dimensions determine whether a control actually reduces risk — or just appears to. Zytra measures each one separately before combining them into a residual score.

Coverage

Does the control address the risk comprehensively, or only partially? A hallucination guardrail active in pre-production but not in the production serving path has partial coverage — and partial coverage at the point of exposure is no coverage at all.

Effectiveness

How much does the control actually reduce risk when present? A detection-only control (logging, alerting) has lower effectiveness than one that prevents or blocks. Effectiveness requires empirical testing — it cannot be assumed from design specifications.

Testability

Can you produce evidence that the control works? A policy document is a control. An automated pipeline test that runs daily against adversarial inputs is also a control. They are not equivalent. Testable controls produce audit-ready evidence. Untestable controls produce an argument.

Regulatory alignment

Does the control satisfy the specific clause of the applicable framework? Clause-level alignment is verifiable. Framework-level alignment is marketing. The distinction matters when a regulator asks you to cite the exact provision your control satisfies.

Residual risk formula
Residual Risk = Inherent Risk × (1 − Control Effectiveness)
Control Effectiveness = avg(Coverage, Testability, Effectiveness, Regulatory Alignment) · scaled 0–1
Example: Critical risk (score 12) with 40% control effectiveness → residual score 7.2 (still High). Reaching Low requires either reducing inherent risk or achieving >85% combined effectiveness.
Board visibility

A domain heat map, not a list of 141 risks.

The output the board needs is not a catalogue. It's a signal: where is residual exposure still High after controls, and where has it been adequately reduced?

Agent Autonomy
High
Security
Medium-High
Model Accuracy
Low-Med
Fairness & Bias
Medium
Privacy & Data
Low-Med
Multi-Agent
High

Illustrative residual scores. Your heat map reflects your deployment patterns, control portfolio, and inherent risk assessment — not a generic template.

Deployment

From catalogue to board report in four steps.

01

Map your AI portfolio

Inventory every AI system in production — models, agents, RAG pipelines, document workflows. Tag each to its deployment pattern. Zytra maps each deployment to the relevant risk domains and applicable regulatory frameworks automatically.

02

Assess inherent risk

For each risk in scope, score impact (financial, reputational, regulatory, operational) and likelihood (deployment frequency, capability maturity, threat actor exposure). Inherent risk = impact × likelihood, scored 1–16 across a 4×4 matrix.

03

Measure control effectiveness

Assign controls with named owners, test evidence, and clause-level regulatory alignment. Score each control across coverage, effectiveness, testability, and regulatory alignment. Design-stage controls with no test evidence score 0% — that's the honest starting position.

04

Generate residual scores and the board report

Residual risk = inherent × (1 − effectiveness). The output is a domain heat map showing where exposure remains High after controls, and a gap-analysis backlog ranked by residual impact. Your regulator submission cites evidence — not a policy document.

Regulatory coverage

Mapped to every framework your regulator will ask about.

Clause-level crosswalks — not just framework names — so audit translation is done before the auditor arrives.

RBI & SEBI

AI risk taxonomy aligned to RBI's operational risk and model risk management circulars and SEBI's algorithm oversight guidelines. Control evidence formatted for Indian regulatory submissions.

DPDP Act 2023

Privacy-related AI risks mapped to the Digital Personal Data Protection Act, including data minimisation, consent management, and erasure obligations for AI training and inference pipelines.

EU AI Act

High-risk AI system obligations (Art. 9–15), GPAI requirements (Art. 53–55), and conformity assessment pathways — pre-mapped so the governance team isn't starting from scratch at the deadline.

NIST AI RMF

Full crosswalk across GOVERN, MAP, MEASURE, and MANAGE functions, with specific sub-practice citations for every risk entry. The GenAI profile covered in full.

OWASP & MITRE ATLAS

LLM Top-10 and Agentic Top-10 mapped to the Zytra risk taxonomy, with MITRE ATLAS technique IDs for adversarial ML risks. Security team and risk team speaking the same language.

ISO/IEC 42001 & DORA

AI management system requirements (42001) and ICT risk management obligations (DORA) pre-mapped so the governance framework satisfies both simultaneously, without duplication.

Get started

Answer your regulator before they ask the question.

Every bank that has experienced an AI-related incident has found, in the post-mortem, a failure mode that existed in the literature but was not in their catalogue. Zytra AI Governance is the catalogue — and the measurement system on top of it.