Minbook
KO
The Risk Audit, as a Process
Build Logs & SaaS Planned 4 posts

The Risk Audit, as a Process

Pre-deployment risk review for AI workflows lives inside consulting engagements: one to two senior-weeks per workflow, non-standard, not re-runnable. This is the record of moving that review into a 36-cell ontology and a single governed BPMN run. Built as the UiPath AgentHack 2026 Maestro BPMN third-prize project.

About this series

Most enterprises learn where an AI workflow breaks only after it ships. Node-level risk review before deployment does exist, but today it exists as a consulting engagement: one to two senior-weeks per workflow, a deliverable that goes stale, and no way to re-run it when the workflow changes.

This series is the record of moving that review into a re-runnable process. It walks through a 36-cell ontology scoring 12 nodes on 3 risk axes, why the auto-approval node scores highest, and how a BPMN process engine can act as the governance spine rather than a wrapper.

Every source used here is public: the ontology, architecture, run screenshots, and the leads that failed verification, from the project submitted to UiPath AgentHack 2026 that took third prize in the Maestro BPMN track.

4 episodes

  1. 01
  2. 02
  3. 03
  4. 04