An organization wants to develop a comprehensive, tailored set of categories and subcategories from the NIST AI Risk Management Framework to help it manage its AI risks effectively. Which of the following tools should the organization utilize to structure, document, and communicate this tailored set to its stakeholders?
Which artifact is the primary output of the AI‑risk identification phase, recording every risk statement with associated assets, threat sources, vulnerabilities, and an initial severity rating?