Definition
The Applied Ethics Risk and Governance Framework (AERGF) is a structured framework for identifying, evaluating, mitigating, governing, and continuously reviewing ethical risks across institutional and organizational contexts. It integrates moral reasoning, stakeholder analysis, responsibility assignment, operational safeguards, oversight, and adaptive review so that ethical judgments are translated into accountable institutional controls.
Scope clarification. AERGF is not limited to artificial intelligence. AI governance is one important application of the framework, but the same structure can be applied to nonprofit governance, public administration, healthcare, education, research, human resources, procurement, organizational policy, professional practice, technology deployment, and other settings in which institutions must convert ethical analysis into decisions, responsibilities, controls, monitoring, and remediation.
The Problem This Framework Solves
Organizations often acknowledge ethical principles without building them into the structures that actually govern decisions. Ethics can become a mission statement, a compliance exercise, a post hoc review, or a matter left to individual discretion. The resulting gap is not primarily a lack of moral vocabulary. It is a governance failure: ethical concerns are recognized but are not translated into authority, procedures, safeguards, evidence, or accountability.
Across contexts, ethical risk is often:
- Context-dependent, because the same policy, technology, or practice may create different risks in different settings.
- Value-laden, because decisions often involve competing goods, rights, duties, priorities, or conceptions of fairness.
- Organizationally distributed, because responsibility is frequently spread across multiple roles, departments, vendors, or institutions.
- Unevenly imposed, because vulnerable or less powerful stakeholders may bear risks that decision-makers do not experience themselves.
- Difficult to detect early, because harms may emerge only after a policy, system, program, or practice becomes embedded.
AERGF addresses this problem by treating ethics as a governance function rather than as moral aspiration alone. Its purpose is to make ethical reasoning operational.
Core Insight of AERGF
Ethical failures do not require malicious intent. They can arise from unexamined tradeoffs, diffuse responsibility, poorly specified objectives, institutional incentives, inadequate oversight, and the failure to identify who bears the costs of a decision. AERGF makes those factors explicit, assigns responsibility, and converts ethical concerns into institutional controls that can be reviewed and revised.
What AERGF Governs
The object of analysis need not be an AI system. AERGF can be applied whenever an institution is making or implementing a consequential decision that creates foreseeable ethical risk. The object of governance may include:
- A policy, rule, or organizational procedure
- A program or service delivered by a nonprofit, public agency, school, or business
- A hiring, evaluation, disciplinary, or resource-allocation process
- A procurement decision or vendor relationship
- A research protocol or professional practice
- A technology system, including but not limited to artificial intelligence
- A public-facing service, benefits program, or eligibility process
- An organizational response to a recurring ethical problem or institutional failure
Structural Components of AERGF
AERGF operates through five connected governance stages. They provide a logical sequence for initial analysis, but the framework is iterative rather than strictly linear. Review at a later stage may require returning to an earlier stage when new stakeholders, harms, facts, or institutional constraints become visible.
Ethical Risk Identification
Identify foreseeable ethical risks associated with the policy, practice, program, decision, or system under review.
- Potential harms and harm amplification
- Distributional inequity
- Autonomy or consent concerns
- Rights or duty conflicts
- Accountability gaps
- Transparency or explainability failures
- Conflicts of interest
- Risks created by institutional incentives
- Foreseeable effects on vulnerable populations
The aim is to identify ethically relevant risk before it becomes normalized or embedded in institutional practice.
Stakeholder and Value Mapping
Identify who is affected, what values or obligations are in tension, and how power is distributed among stakeholders.
- Affected stakeholders
- Competing moral priorities
- Institutional incentives
- Vulnerable or underrepresented groups
- Decision-makers and beneficiaries
- Those who bear costs, burdens, exposure, or loss of opportunity
- Relevant factual disagreements or uncertainty
This stage helps prevent silent value capture by dominant actors and makes distributive effects visible.
Governance and Responsibility Assignment
Translate ethical responsibility into named institutional roles, authority, and escalation structures.
- Who owns the decision
- Who is accountable for ethical outcomes
- Decision-authority boundaries
- Who may approve, suspend, override, or revise the practice
- Escalation pathways
- Oversight mechanisms
- External responsibilities to regulators, funders, boards, clients, or the public
Ethical responsibility must be assigned rather than assumed. Nominal oversight is insufficient when the designated person lacks authority, information, or competence.
Mitigation and Operational Constraints
Convert ethical requirements into controls that shape what the institution may do and how it must act.
- Policy constraints
- Procedural safeguards
- Design or technical constraints when technology is involved
- Training and competency requirements
- Documentation standards
- Consent or disclosure requirements
- Monitoring protocols
- Independent review or separation-of-duty requirements
- Remediation procedures
This is the stage at which ethical principles become operational controls rather than aspirational statements.
Review, Audit, and Adaptation
Establish mechanisms for determining whether the governance controls are working and whether the ethical risk has changed.
- Ongoing ethical review
- Feedback and complaint mechanisms
- Outcome monitoring
- Audit cycles
- Incident review
- Revision triggers
- Escalation and remediation
- Criteria for suspension, retirement, or termination of a policy, program, system, or practice
Ethical governance is continuous. A defensible decision can become ethically inadequate if circumstances, evidence, impacts, or institutional capacities change.
Inputs to an AERGF Review
- The decision, policy, program, practice, system, or institutional arrangement under review
- Its stated objectives and intended beneficiaries
- The operating context, including legal, professional, financial, and organizational constraints
- Foreseeable harms, failure modes, and unintended consequences
- A stakeholder and vulnerable-population map
- Relevant evidence, uncertainty, and factual disagreement
- Organizational incentives and decision authority
- Existing controls, policies, standards, laws, contracts, and professional obligations
Outputs of an AERGF Review
- An ethical risk register
- A stakeholder and value map
- A record of relevant moral disagreements and factual uncertainties
- An accountability matrix identifying responsible roles and decision authority
- Operational, procedural, policy, or technical controls
- Monitoring and audit plans
- Escalation and remediation procedures
- A documented rationale linking ethical analysis to institutional action
- A defensible governance record that can be reviewed by leadership, boards, regulators, funders, clients, or other relevant stakeholders
Application Contexts
AERGF is designed to travel across institutional domains. Its governing question is ‘How should this institution convert ethically relevant findings into accountable action?’
| Context | Illustrative Uses |
| Nonprofit organizations | Program design, donor restrictions, service eligibility, vulnerable-population impacts, board oversight, volunteer policies, and allocation of scarce resources. |
| Public-sector governance | Administrative policy, benefits systems, procurement, public safety, service delivery, transparency, due process, and accountability to the public. |
| Healthcare | Clinical policy, triage, resource allocation, patient autonomy, informed consent, data governance, and institutional responsibility. |
| Education | Disciplinary systems, assessment practices, student privacy, access, disability accommodation, resource allocation, and technology adoption. |
| Human resources and employment | Hiring, evaluation, promotion, termination, monitoring, workplace policy, and the distribution of decision authority. |
| Research and professional practice | Study design, participant protections, conflicts of interest, evidence standards, professional obligations, and institutional review. |
| Business and organizational governance | Product decisions, customer treatment, supply-chain responsibility, risk allocation, compliance integration, and internal accountability. |
| Technology and AI | Procurement, design, deployment, model or system oversight, automation, data use, monitoring, human authority, audit, and remediation. |
AI as One Application of AERGF
AERGF was originally articulated through AI ethics and governance examples, and AI remains a major application. However, the framework’s governing logic is broader than AI because each of its core functions is institution-level: identify ethical risk, map stakeholders and values, assign responsibility, create constraints and safeguards, and review outcomes over time.
In an AI case, the object under review might be a hiring model, triage system, chatbot, predictive tool, or automated decision process. In a nonprofit case, it might be a service-eligibility rule. In a school, it might be a disciplinary policy. In a hospital, it might be a triage protocol. The object changes, but the governance problem is structurally similar: ethical analysis must be converted into accountable institutional action.
Relationship to Moral Reasoning Frameworks
AERGF does not replace moral reasoning. It operationalizes the results of moral reasoning by converting findings into institutional decisions, responsibilities, controls, monitoring, and remediation.
| Framework | Primary Function | Relationship to AERGF |
| HCBMR | Structures ethical reasoning around concrete cases and decisions. | Provides the case analysis that AERGF can translate into governance action. |
| EMRIM | Explains how intuitions, cognitive tendencies, and empirical moral psychology can shape ethical judgment. | Helps identify why stakeholders may perceive the same risk differently. |
| MDDM | Diagnoses the sources of moral disagreement, including competing priorities, factual assumptions, and evaluative standards. | Clarifies which disagreements must be resolved, managed, or explicitly documented in governance decisions. |
| JWPR | Provides a justice-oriented structure for evaluating distributions of benefits, burdens, access, opportunity, and risk. | Helps identify distributive concerns that AERGF can convert into institutional protections or constraints. |
| AERGF | Applied governance layer. | Converts those findings into accountable institutional controls across multiple contexts. |
Relationship to Traditional Ethical Theories
AERGF is a governance framework, not a stand-alone normative theory. It can incorporate conclusions generated by deontological, consequentialist, virtue-ethical, care-ethical, rights-based, libertarian, professional, or justice-based analysis. The framework’s distinctive function is to ask what institutional structures must follow from those ethical judgments.
- Duties and rights can become non-negotiable policy constraints or procedural protections.
- Consequentialist risk assessments can become mitigation thresholds, monitoring requirements, or decision triggers.
- Justice concerns can become allocation rules, access protections, subgroup review, or burden-sharing requirements.
- Autonomy concerns can become consent, disclosure, opt-out, appeal, or human-override mechanisms.
- Virtue and professional-responsibility concerns can become competency standards, review duties, or institutional norms.
What AERGF Is Not
- It is not a one-time ethics checklist.
- It does not assume that legal or regulatory compliance is sufficient for ethical adequacy.
- It is not limited to technical bias metrics or technology-specific evaluation.
- It does not treat ‘human oversight’ as meaningful unless the designated human has real authority, relevant information, and sufficient competence.
- It does not eliminate ethical risk or guarantee morally correct outcomes.
- It does not resolve every moral disagreement. Some disagreements must instead be made explicit, governed, monitored, and revisited.
- It is not restricted to AI systems. AI is one application domain within a broader institutional governance framework.
Illustrative Cross-Context Examples
Nonprofit service allocation
A nonprofit has insufficient funding to serve every eligible applicant. AERGF identifies risks of inequitable exclusion, maps affected populations and donor constraints, assigns decision authority, establishes allocation criteria and an appeal process, and reviews demographic and outcome data over time.
Human-resources policy
An employer changes its performance-evaluation process. AERGF identifies risks of inconsistent standards, retaliation, hidden bias, or diffuse managerial responsibility, then converts those risks into review procedures, documentation requirements, appeal rights, and named accountability.
Public-sector procurement
A public agency purchases a new decision-support system. The framework evaluates affected stakeholders, vendor incentives, transparency, due-process obligations, responsibility boundaries, procurement safeguards, audit rights, and conditions for suspension or termination.
AI deployment
A hospital considers an AI triage tool. AERGF identifies safety, equity, privacy, and automation-bias risks; maps patients, clinicians, administrators, vendor, and regulators; assigns accountable owners; requires validation, override authority, documentation, and monitoring; and establishes review and remediation triggers.
How AERGF Differs from Narrower Governance Approaches
| Approach | Typical Limitation | AERGF Difference |
| Principles or ethics statements | May remain aspirational or non-binding. | AERGF requires translation into roles, authority, controls, monitoring, and remediation. |
| Compliance checklists | Can reduce ethics to minimum legal requirements. | AERGF distinguishes compliance from broader ethical adequacy. |
| Single-issue audits | May focus narrowly on one risk category. | AERGF integrates stakeholder, value, responsibility, and governance analysis at the institutional level. |
| Technical fixes | Can overlook organizational incentives, authority, and nontechnical harms. | AERGF permits technical controls but situates them inside broader institutional governance. |
| Ad hoc leadership judgment | Can depend on individual discretion and may be difficult to defend or reproduce. | AERGF creates a documented and reviewable governance record. |
Governance Record and Defensibility
AERGF does not promise ethical certainty. Its standard is institutional defensibility: the organization should be able to show what risks it identified, whose interests were considered, which moral disagreements or uncertainties remained, who had decision authority, what safeguards were imposed, what evidence was used, how outcomes were monitored, and what would trigger revision or remediation.
Relationship to the Holcombe Ethics Framework Suite
Within the Holcombe Ethics Framework Suite, AERGF is the applied governance layer. HCBMR structures concrete ethical cases, EMRIM explains stakeholder intuitions and cognitive influences, MDDM diagnoses the sources of moral disagreement, and JWPR evaluates the distribution of benefits, burdens, access, opportunity, and risk. AERGF converts those analytical findings into accountable institutional action across organizational, public-sector, nonprofit, professional, technological, and other applied contexts.
References
Floridi, L., Cowls, J., Beltrametti, M., Chai, F., Chazerand, P., Dignum, V., Luetge, C., Madelin, R., Pagallo, U., Rossi, F., Schafer, B., Valcke, P., & Vayena, E. (2018). AI4People, an ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and Machines, 28(4), 689–707. https://doi.org/10.1007/s11023-018-9482-5
Freeman, R. E. (1984). Strategic management: A stakeholder approach. Pitman.
International Organization for Standardization. (2018). ISO 31000:2018 risk management — Guidelines. ISO.
Jobin, A., Ienca, M., & Vayena, E. (2019). The global landscape of AI ethics guidelines. Nature Machine Intelligence, 1(9), 389–399. https://doi.org/10.1038/s42256-019-0088-2
Mittelstadt, B. D., Allo, P., Taddeo, M., Wachter, S., & Floridi, L. (2016). The ethics of algorithms: Mapping the debate. Big Data & Society, 3(2), 1–21. https://doi.org/10.1177/2053951716679679
Rawls, J. (1971). A theory of justice. Harvard University Press.