The Risk Audit, as a Process
Pre-deployment risk review for AI workflows lives inside consulting engagements: one to two senior-weeks per workflow, non-standard, not re-runnable. This is the record of moving that review into a 36-cell ontology and a single governed BPMN run. Built as the UiPath AgentHack 2026 Maestro BPMN third-prize project.
About this series
Most enterprises learn where an AI workflow breaks only after it ships. Node-level risk review before deployment does exist, but today it exists as a consulting engagement: one to two senior-weeks per workflow, a deliverable that goes stale, and no way to re-run it when the workflow changes.
This series is the record of moving that review into a re-runnable process. It walks through a 36-cell ontology scoring 12 nodes on 3 risk axes, why the auto-approval node scores highest, and how a BPMN process engine can act as the governance spine rather than a wrapper.
Every source used here is public: the ontology, architecture, run screenshots, and the leads that failed verification, from the project submitted to UiPath AgentHack 2026 that took third prize in the Maestro BPMN track.
4 episodes
- 01
- 02
- 03
- 04