Framework
OSRA
The Operational Substrate Risk Audit. An open four-phase methodology for finding where AI operational risk converges beneath the governance layer, in the infrastructure substrate that no existing framework audits.
The gap
Governance frameworks audit what should happen. OSRA audits what the system actually depends on.
Twelve major AI governance frameworks were analysed for this work, among them NIST AI RMF, ISO 42001, the EU AI Act and DORA. None achieves full coverage on infrastructure dependency mapping, infrastructure-level failure mode analysis, trust verification, or convergence risk. All of them operate at the governance and policy layer, and none systematically addresses the infrastructure substrate that AI systems actually depend on to function. Fifteen existing risk methodologies were surveyed alongside them, and none provides a unified approach that maps infrastructure dependencies, failure modes per dependency, unverified trust signals, and the places where all three converge into compound risk.
Meanwhile the regulatory landscape has started creating enforceable liability for AI operational failures: EU AI Act penalties reaching 7% of global turnover, mandatory resilience testing under DORA, personal accountability under the UK’s SM&CR, and AI liability law emerging at US state level. Organizations now carry liability for AI failures without a method for identifying where those failures will originate at the infrastructure level.
OSRA fills that gap. It sits beneath existing governance and complements it, providing the infrastructure visibility those frameworks assume but do not verify.
Four phases, four artefacts, one convergence risk summary
Phase 1, Substrate Mapping. What does this AI system actually depend on to function? The artefact is the Substrate Map.
Phase 2, Failure Surface Analysis. For each dependency, what does failure look like, and who would notice? The artefact is the Failure Surface Register.
Phase 3, Trust Surface Audit. Where is the organization trusting a signal it has not verified? The artefact is the Trust Surface Register.
Phase 4, Convergence Mapping. Where do substrate risks, undetected failures and unverified trust overlap? The artefact is the Convergence Risk Summary.
One methodology, three altitudes
Each artefact translates to a different reader.
Boards and non-executive directors get the convergence risk summary: the three to five points where the AI deployment is most exposed, the regulatory liability at each point, and what to do about it. It is the document that answers the DORA Article 15 question.
CISOs get the full four-phase methodology with integration into existing risk management, vendor assessment and compliance evidence. It reads as a programme of work: what to fix first, and how to report it upward.
CTOs get infrastructure dependency maps, detection gap analysis and engineering remediation priorities. What to build, what to monitor, what to renegotiate, and in what order.
Scoring
Convergence is scored on six factors: regulatory exposure weighted at 1.5, detection deficit, trust depth, blast radius weighted at 1.5, remediation complexity, and materialisation horizon. Scoring is calibrated across five sectors: finance, healthcare, digital services, logistics and energy.
Findings fall into four categories, each with its own clock.
- Critical Convergence, all three conditions met, remediation within 30 days.
- Convergence Point, two of three conditions met, remediation within 90 days.
- Concentration Risk, a single point of dependency at high severity, exit strategy within six months.
- Monitored Risk, one of three conditions or low severity, handled on the standard risk cycle.
The remediation catalogue
Findings map to 22 structured remediation actions in four categories: detection gap actions D1 to D6, trust verification actions V1 to V6, substrate resilience actions R1 to R5, and governance integration actions G1 to G6. An assessment does not end with a list of problems, it ends with a sequenced set of actions drawn from a published catalogue.
Integration with existing frameworks
OSRA does not replace existing governance. It supplies the substrate layer they are missing.
- NIST AI RMF. Phase 1 feeds the Map function. Phase 2 extends Measure to the infrastructure level.
- ISO 42001. Phase 1 provides the infrastructure detail Annex A.9 requires but does not specify. Phase 3 strengthens certification evidence.
- EU AI Act. Phase 1 fulfils Annex IV documentation at genuine depth. Phase 4 provides Article 9 risk management evidence.
- DORA. Phase 1 extends Article 6 asset documentation. Phase 2 provides Article 25 and 26 resilience scenarios. Phase 4 answers Article 15 directly.
- MITRE ATLAS. Phase 2 incorporates the ATLAS threat model and extends it from adversarial to operational resilience.
Evidence base
OSRA rests on documented work rather than assertion: 12 governance frameworks analysed with clause-level gap assessment, 15 existing methodologies surveyed to validate novelty, global regulatory liability mapped across more than 10 jurisdictions, 11 incident case studies documenting infrastructure-level AI failures, and 25 convergence points scored across 5 sector scenarios for calibration.
Take it and run it
OSRA v1.1. The methodology, the fillable practitioner templates for all four phases, the action catalogue and the scoring calibration are published in full on GitHub under CC BY-SA 4.0. Use it, adapt it, improve it, and give credit.
The worked example is a complete run of all four phases against EuroBank Sentinel, a fraud detection system at a DORA-regulated bank, including the findings the quarterly board report would have kept showing as green.