← All resourcesRisk assessment

AI risk assessment template

6 min read

Download: AI risk assessment template (PDF) — a printable worksheet you can fill in per use case.

Why consistency matters more than complexity

An AI risk assessment doesn't need to be a 40-page document. It needs to be consistent, explainable, and repeatable — so two people assessing similar use cases reach similar conclusions, and so you can defend the result later. Gut-feel ratings don't survive an audit; a simple rule-based tier does.

The factors that drive AI risk

For each use case, assess:

  • Data sensitivity — does it involve personal, regulated, or highly confidential data?
  • Decision impact — does the AI advise a human, or drive a decision that affects people (employment, credit, access to services)?
  • Automation level — advisory, human-in-the-loop, human-on-the-loop, or fully automated?
  • Autonomy & reach — how many people or decisions does it touch, and how reversible are its actions?
  • Vendor & data handling — does the tool train on your inputs? What are its retention and security terms?

A simple tiering model

Map the factors to a tier — for example:

  • Low — no personal data, advisory only, easily reversible.
  • Moderate — involves personal data, or informs decisions with human review.
  • High — affects individuals materially, sensitive data, or high automation.
  • Prohibited — falls into a category your organization does not permit.

Take the highest triggered tier across all factors, and record *which rules fired and why*. That explainability is what makes the assessment defensible.

A template structure

A reusable assessment captures:

  1. Use case, owner, and tool.
  2. Data categories (and whether personal/regulated).
  3. Decision impact and automation level.
  4. Human oversight in place.
  5. Triggered risk factors and the resulting tier.
  6. Required safeguards and the next review date.

Use the PDF worksheet as the paper version of that structure. It is a snapshot, not a compliance certificate.

Make it live, not a document

The biggest failure mode is a template that's filled in once and forgotten. Risk assessments should be versioned and re-run when the use case changes, and snapshotted so you can prove what was assessed and when.

That's exactly how AI Assurance Hub's risk engine works — versioned rules produce explainable, snapshotted tiers automatically. See it in a live demo, or read the NIST AI RMF checklist for the wider program.

Put this into practice.

Inventory, assess, approve, and evidence every AI use case in one place.

Stay ahead of AI governance.

Get new guides and product updates in your inbox. Occasional, no spam.