Risk
Outdated Risk Assessment
Description
Security testing and risk evaluation are not updated after major model, data, tool, or prompt changes, leaving new vulnerabilities undetected.
Example
Retrained model or updated prompt introduces a previously fixed jailbreak or bias issue
Assets Affected
Model files
Pipeline Job
Mitigation
- Define triggers for re-assessment
- Require automated regression and red-team testing after significant changes
- Update risk analysis regularly
Standards Mapping
- ISO 42001: A.5.2, A.6.2.4
- NIST AI RMF: MEASURE 3.1, GOVERN 1.5