An AI risk assessment should help an owner decide whether a use case is acceptable, which controls it requires, and what evidence must exist before operation.
Describe the decision context
Document the intended users, affected people, business process, autonomy, data, external exposure, reversibility, and worst credible failure. Separate advisory output from automated action.
Assess key risk dimensions
- Business and human impact
- Data sensitivity, quality, and permitted use
- Reliability and performance variation
- Explainability and contestability
- Security, misuse, and third-party dependency
- Human oversight and operational fallback
Link findings to controls
Each material risk should map to prevention, detection, response, and ownership. Examples include data restrictions, test thresholds, approval, output validation, transaction limits, logging, monitoring, and shutdown procedures.
Keep the assessment alive. Revisit it when data, models, prompts, integrations, autonomy, or intended use changes.
Assess a real AI use case.
Create a proportionate control plan and evidence path.
