"we present recommendations for organizations and governments engaged in establishing thresholds for intolerable AI risks. Our key recommendations include: ✔️ Design thresholds with adequate margins of safety to accommodate uncertainties in risk estimation and mitigation. ✔️Evaluate dual-use capabilities and other capability metrics, capability interactions, and model interactions through benchmarks, red team evaluations, and other best practices. ✔️Identify “minimal” and “substantial” increases in risk by comparing to appropriate base cases. ✔️Quantify the impact and likelihood of risks by identifying the types of harms and modeling the severity of their impacts. ✔️Supplement risk estimation exercises with qualitative approaches to impact assessment. ✔️Calibrate uncertainties and identify intolerable levels of risk by mapping the likelihood of intolerable outcomes to the potential levels of severity. ✔️Establish thresholds through multi-stakeholder deliberations and incentivize compliance through an affirmative safety approach. Through three case studies, we elaborate on operationalizing thresholds for some intolerable risks: ⚠️ Chemical, biological, radiological, and nuclear (CBRN) weapons, ⚠️ Evaluation Deception, and ⚠️ Misinformation. " Nada Madkour, PhD Deepika Raman, Evan R. Murphy, Krystal Jackson, Jessica Newman at the UC Berkeley Center for Long-Term Cybersecurity
Science Risk Assessment Methods
Explore top LinkedIn content from expert professionals.
-
-
BAYESIAN GARCH: WHEN VOLATILITY MEETS UNCERTAINTY 📈 How do you model financial volatility when even your model parameters are uncertain? Traditional GARCH gives you point estimates, but markets demand risk quantification. Bayesian GARCH provides the full uncertainty picture. 🎯 Financial volatility isn't just time-varying—it's fundamentally uncertain. When you estimate α = 0.08 for volatility persistence, classical methods pretend this is the "true" value. But what if it's anywhere between 0.03 and 0.15? That uncertainty matters for risk management and option pricing. The Bayesian framework reveals a powerful insight: your volatility forecasts should reflect both model uncertainty and parameter uncertainty. Instead of a single volatility path, you get thousands of plausible scenarios from the posterior distribution. What's mathematically elegant about this approach: - MCMC sampling navigates complex, non-conjugate posteriors that have no closed-form solutions - Prior regularization prevents overfitting while enforcing economic constraints (stationarity, positivity) - Posterior predictive distributions naturally incorporate all sources of uncertainty - Bayes factors enable principled model comparison between GARCH specifications The implementation challenges are real: likelihood evaluation requires recursive computation of conditional variances, parameter constraints need careful handling through transformations, and MCMC convergence demands proper diagnostics. But the payoff is substantial. Risk managers get robust VaR calculations that account for parameter uncertainty. Derivatives traders get realistic option price distributions. Portfolio managers get dynamic hedging strategies that adapt to regime changes. The key insight? In volatile markets, knowing what you don't know is as valuable as what you do know. 💭 How do you handle parameter uncertainty in your volatility models? Do you question point estimates when making risk-critical decisions? #BayesianEconometrics #GARCH #VolatilityModeling #RiskManagement #QuantitativeFinance #MCMC
-
Physical climate risk data: the more we learn, the less we know? Khalid Azizuddin's recent piece in *Responsible Investor captures well what many practitioners are grappling with today: - asset-level data that remain incomplete or hard to interpret; - physical hazard exposure often disconnected from financial materiality; - little visibility on supply chains or customers; - adaptation and resilience efforts largely ignored; - and a risk of over-simplifying complex realities into a single “score.” Some three years ago, EDHEC Business School set out to address exactly these challenges, working to advance climate risk modelling and make decision-useful for investors, companies, and public authorities. In this work, we have developed: 🔹 a blueprint for a new generation of probabilistic climate scenarios; 🔹 high-resolution geospatial modeling capabilities to allow for geographic and sectoral downscaling, consistent with each scenario; 🔹 an open database of decarbonisation and resilience technologies through the #ClimaTech project, which officially launched this week. While the research is public, the new EDHEC Climate Institute has also been assisting a school-backed venture, Scientific Climate Ratings (SCR), which integrates this research to deliver forward-looking quantification of the #financialmateriality of climate risks for infrastructure companies and investors worldwide. While SCR provides a rating scale for comparability, it avoids the trap of over-simplification. Each rating is backed by probabilistic scenario modelling, analysis of physical and transition risk exposures, and explicit accounting for adaptation measures. The result is a synthesis that remains transparent, interpretable, and anchored in scientific rigour. Together, these initiatives aim to move the discussion from data abundance to decision relevance, equipping practitioners with tools that connect climate science, finance, and strategy.
-
Here’s my take on the recent BIS climate credit risk model "Incorporating physical climate risks into banks’ credit risk models" (July 2025 https://lnkd.in/e4fEezjZ) The approach is clearly designed for a specific application: incorporating physical climate risk into the IRB capital framework. It improves on scalar PD blends by introducing a theoretically motivated adjustment that remains compatible with the Basel formula. But it does so by relying on regulatory-acceptable simplifications that make it operationally feasible at the cost of structural modelling consistency. Conceptually, the model adjusts PD by shifting the implied terminal distribution via a weighted blend of original and stressed states (as in the q-climate adjustment). This is very similar in spirit to a classic Distance-to-Default stress test: rather than modelling asset paths or volatility changes explicitly, it imposes a distribution-level shift to increase the probability of default relative to a fixed debt threshold. ➡️ Key strength: It is easy to implement in the IRB framework. Banks can move beyond simplistic scalar PD adjustments while keeping the regulatory capital formula intact. But there are important limitations: 🔹First, this is not a “jump model” in the classical sense. True jump-diffusion models embed stochastic jumps in the asset-value process itself, impacting path-dependent dynamics and producing fatter-tailed distributions. They preserve structural consistency - market cap as an option on assets. By contrast, the BIS approach imposes an exogenous terminal shift at the distribution level, changing the mean but not the shape. 🔹Second, this means the approach cannot be used for market-consistent pricing. Structural models calibrate asset value and volatility so that the option price matches observed market cap. Any exogenous shift in the terminal distribution would simply be offset in calibration to maintain this consistency, effectively cancelling the adjustment. Regulators ignore this option-price matching in capital frameworks, but this simplification makes the approach unsuitable for pricing applications. 🔹Third, the practical challenge is calibration. While the mechanics of the q and α parameters are straightforward, robust estimation remains an open question. ✅In short: The BIS model is purpose-built for IRB capital calculations. It offers a clear, operationally feasible way to embed physical climate risk in regulatory capital requirements, accepting simplifications that make it incompatible with market-consistent pricing or full structural modelling. It’s not a failure of the approach, but a deliberate trade-off to meet regulatory needs. Importantly, the q and α parameters are central to its implementation, controlling the weight and magnitude of the stressed distribution shift and so require careful design and calibration in practice.
-
Part 8: ICH M7(R2) and ICH Q3E together highlight an important principle in pharmaceutical development: quality should be built through scientific understanding, proactive risk assessment, and well-designed controls across the product lifecycle. ICH M7(R2) provides a framework for identifying, assessing, and controlling DNA-reactive mutagenic impurities in drug substances and drug products to reduce potential carcinogenic risk. ICH Q3E focuses on extractables and leachables chemicals that may arise from packaging materials, container closure systems, manufacturing components, and other product-contact materials. What makes these guidelines especially relevant is their common scientific foundation: • risk-based assessment • exposure-based evaluation • patient-focused decision-making • strong regulatory justification In today’s pharmaceutical systems, risk does not arise only from the synthetic route. It can also emerge from: - reagents, solvents, and intermediates - degradation pathways - packaging and contact materials - storage conditions - dose, duration, and route of administration This is why a lifecycle-based approach is so important. The goal is not only to test for risk at the final stage, but to understand where it may originate, evaluate its significance, and establish suitable controls early in development. When viewed together, ICH M7(R2) and ICH Q3E strengthen a broader quality mindset: one addresses mutagenic impurity risk, while the other addresses material-associated chemical exposure risk. Both support the same objective safe, scientifically justified, and compliant medicines for patients. The earlier risk is understood, the more effectively it can be controlled through process design, material selection, and a robust control strategy. #ICHM7 #ICHM7R2 #ICHQ3E #GenotoxicImpurities #MutagenicImpurities #PharmaceuticalQuality #QualityRiskManagement #DrugSafety #RegulatoryAffairs #AnalyticalRAndD #PharmaCompliance
-
New USP Chapter <1110>: Microbial Contamination Control Strategy Considerations The United States Pharmacopeia (USP) has introduced a new general chapter <1110> titled "Microbial Contamination Control Strategy Considerations." This chapter provides a comprehensive framework for developing and implementing an effective contamination control strategy (CCS) throughout the entire product lifecycle, applicable to both sterile and nonsterile products. This initiative aligns with international regulatory expectations and emphasizes the integration of Quality Risk Management (QRM) principles. It encourages manufacturers to proactively identify, evaluate, and control microbiological risks by establishing a documented and science-based CCS. Key elements of Chapter <1110> include: Facility Design and Cleanroom Classification: The chapter highlights the importance of cleanroom design in accordance with ISO 14644-1 standards. ISO Class 5 conditions are required for aseptic processing areas to ensure minimal contamination. Environmental Monitoring (EM): A robust EM program should monitor both viable (microbiological) and nonviable particles. Data should be reviewed regularly (e.g., quarterly) to identify trends and adjust alert and action limits accordingly. Risk Assessment Methodologies: Tools such as Hazard Analysis and Critical Control Points (HACCP) and Failure Modes and Effects Analysis (FMEA) are recommended to identify critical control points. Risk mitigation strategies must be justified and documented. Ongoing Verification: The CCS should be reviewed periodically, incorporating existing site-specific and global microbial risk assessments to ensure continuous improvement and compliance. Why is Chapter <1110> Important? Chapter <1110> marks a significant step toward unifying standards for microbial contamination control. It promotes a proactive, lifecycle-based approach that enhances product quality and patient safety. The new guidance is also closely aligned with current global regulations, including the EU GMP Annex 1 revisions. The draft chapter was published in Pharmacopeial Forum 51(2) in March 2025, and stakeholders are invited to provide feedback during the public comment period before it is finalized.
-
📌 Risk Assessment: The Foundation of Effective Validation In today's Computer System Validation (CSV) and Computer Software Assurance (CSA) landscape, we are no longer expected to test everything with the same intensity. Instead, we are expected to understand the risk and focus our efforts where they matter most. 1. What is Risk Assessment? Risk Assessment is a systematic process of identifying potential failures, evaluating their impact, and implementing controls to reduce risk to an acceptable level. Risk Assessment helps us focus on what could go wrong before it actually happens. 2. What is Functional Risk Assessment (FRA)? Functional Risk Assessment (FRA) evaluates individual system functions to determine their potential impact on GxP compliance. Rather than asking: "Is the system risky?" We ask: "Which functions within the system are critical?" Examples: 🔴 Audit Trail → High Risk 🔴 Electronic Signature → High Risk 🟡 User Login → Medium Risk 🟢 Dashboard Color Change → Low Risk FRA helps determine where validation and testing efforts should be focused. 3. What is Risk-Based Testing? Risk-Based Testing is an approach where the extent of testing is determined by the level of risk. 🔴 High Risk → Extensive Testing 🟡 Medium Risk → Moderate Testing 🟢 Low Risk → Basic Verification 4. Why is FMEA Used? Failure Mode and Effects Analysis (FMEA) is the most commonly used risk assessment methodology in pharmaceutical computerized systems. Why? ✔ Structured and systematic ✔ Easy to understand and document ✔ Identifies failures before they occur ✔ Accepted by FDA, EMA, ISPE, and GAMP® 5 FMEA evaluates risk using three factors: Severity (S): How serious is the impact? Occurrence (O): How likely is the failure to occur? Detectability (D): How easily can the failure be detected? 5. FMEA Example Function: Audit Trail Failure Mode: Audit trail not captured Potential Effect: Loss of Data Integrity Severity = 10 Occurrence = 3 Detectability = 3 RPN = 10 × 3 × 3 = 90 A higher RPN indicates higher priority for mitigation and testing. Higher RPN indicates greater risk and typically requires stronger controls, mitigation actions, and testing. 💡 Key Takeaway Don't test everything equally. Understand the risk. Prioritize what matters. Validate with confidence. #CSV #CSA #RiskAssessment #FMEA #RiskBasedTesting #ComputerSystemValidation #GAMP5 #Datalntegrity #Validation #PharmaceuticalQuality #GxP #LifeSciences #21CFRPart11 #Annex11
-
𝐋𝐚𝐰𝐬 𝐨𝐟 𝐔𝐧𝐜𝐞𝐫𝐭𝐚𝐢𝐧𝐭𝐲 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 We behave as if certainty is the natural state of the world and Uncertainty is an interruption. In reality the opposite is true. Markets move, technologies evolve, relationships change and even scientific knowledge progresses through revision rather than final answers. Managing uncertainty therefore becomes one of the most important skills in leadership and certain laws can help here. 1. The Law of Incomplete Information No leader, scientist or policymaker may ever see the full picture. Data is always delayed, incomplete or filtered through assumptions. Waiting for perfect knowledge often means missing the moment when action matters most.Decision-makers therefore can shift their thinking. Instead of asking “Do we know everything?” they ask “Do we know enough to act responsibly? Implication: Decisions should be based on sufficient information, not perfect information. 2. The Law of Probabilities Financial markets, climate models, epidemiology, and artificial intelligence all operate through probability distributions rather than guarantees. The best thinkers learn to reason in terms of likelihoods instead of fixed outcomes. Instead of asking “What will happen?” they ask “What are the possible outcomes and how likely is each one?” Implication: Good decision-makers think in scenarios and probabilities & not single predictions. 3. The Law of Reversible Decisions When uncertainty is high, choose decisions that allow correction. In uncertain environments the wisest strategy is to favor decisions that can be reversed or refined as new information appears. Experiments, pilot programs and prototypes exist for this reason. Implication: When the future is unclear, experiment small and adjust quickly. 4. The Law of Adaptation Prediction is valuable but adaptation is survival. The most successful systems are those that adapt fastest when the future unfolds differently. Biological evolution works this way. So do resilient companies and learning organizations. Implication: Build systems and habits that learn, update & adapt continuously. 5.The Law of Humility The deeper the system we study, the greater the uncertainty we can encounter. Physics, economics and social systems all demonstrate that complex realities resist complete understanding. New discoveries often reveal deeper layers of complexity rather than final certainty. Humility therefore becomes a strategic advantage. It allows curiosity, openness to evidence and willingness to revise beliefs. Implication: Treat certainty cautiously and remain intellectually humble and open to revision. “Uncertainty is the only honest condition of knowledge.” — Richard Feynman Do you Know Richard Feynman?
-
Risk assessment is a vital part of pharmaceutical quality systems to ensure product safety and regulatory compliance. ICH Q9: Quality Risk Management Main Guideline for implementing risk assessment and control processes in pharmaceuticals. Focuses on: Risk identification Risk analysis Risk evaluation Risk control Risk review Quality Risk Assessment and Mitigation Plan covering critical areas like labeling, filtration, and packing processes. Each failure mode is assessed for severity, occurrence, and detectability (S, O, D) to determine the Risk Priority Number (RPN). Based on this, mitigation strategies are implemented to control or reduce risk. Row 57: Labeling Container for Individual Identification Failure Mode: Wrong label pasted on ampoules/vials. Effect: High chance of missing product information — serious issue, can lead to market complaints and misidentification. Cause: Wrong product label from store department. Current Controls: Label details are recorded in batch packing record. Verified by production and QA. Labels are checked during issuance as per BPR. RPN: 4 (Low category risk). Post Risk: Adequate control; no recommendation needed. Row 58: Labeling of Container for Dispatch Failure Mode: Wrong product details on packed carton. Effect: Risk of missing correct product info — leads to market complaints. Cause: Wrong product detail impression on carton. Current Controls: Carton is checked by QA. Verification against stereo impression log and BMR. Destroyed stereo and mix-up checks included. RPN: 4 (Low category risk). Post Risk: No additional action required. Row 59: Packing Through Blister Machine Failure Mode: Missing batch coding on blister foil. Effect: Missing product info — leads to complaint. Cause: Roller defect during blistering. Current Controls: Each set of foil is verified by QA. In-process QA and production checks. RPN: 4 Post Risk: No change needed. Row 60: Packing Through Hi-Cart Failure Mode: Missing batch coding on inner carton. Effect: Market complaint due to missing info. Cause: Stereo impression error. Controls: Production + QA verify batch coding. In-process logbook and destroyed stereo monitoring. RPN: 4 Post Risk: Control adequate. Row 61: Packing Process Failure Mode: Packed products get mixed. Effect: Wrong product distribution. Cause: Improper segregation between products. Controls: Segregation followed after every product batch. RPN: 4 Post Risk: No extra action required. Each of these failure modes is associated with a low RPN, indicating controls are effective, and no additional risk mitigation is currently necessary.