AI risk assessment template
6 min read
Download: AI risk assessment template (PDF) — a printable worksheet you can fill in per use case.
Why consistency matters more than complexity
An AI risk assessment doesn't need to be a 40-page document. It needs to be consistent, explainable, and repeatable — so two people assessing similar use cases reach similar conclusions, and so you can defend the result later. Gut-feel ratings don't survive an audit; a simple rule-based tier does.
The factors that drive AI risk
For each use case, assess:
- Data sensitivity — does it involve personal, regulated, or highly confidential data?
- Decision impact — does the AI advise a human, or drive a decision that affects people (employment, credit, access to services)?
- Automation level — advisory, human-in-the-loop, human-on-the-loop, or fully automated?
- Autonomy & reach — how many people or decisions does it touch, and how reversible are its actions?
- Vendor & data handling — does the tool train on your inputs? What are its retention and security terms?
A simple tiering model
Map the factors to a tier — for example:
- Low — no personal data, advisory only, easily reversible.
- Moderate — involves personal data, or informs decisions with human review.
- High — affects individuals materially, sensitive data, or high automation.
- Prohibited — falls into a category your organization does not permit.
Take the highest triggered tier across all factors, and record *which rules fired and why*. That explainability is what makes the assessment defensible.
A template structure
A reusable assessment captures:
- Use case, owner, and tool.
- Data categories (and whether personal/regulated).
- Decision impact and automation level.
- Human oversight in place.
- Triggered risk factors and the resulting tier.
- Required safeguards and the next review date.
Use the PDF worksheet as the paper version of that structure. It is a snapshot, not a compliance certificate.
Make it live, not a document
The biggest failure mode is a template that's filled in once and forgotten. Risk assessments should be versioned and re-run when the use case changes, and snapshotted so you can prove what was assessed and when.
That's exactly how AI Assurance Hub's risk engine works — versioned rules produce explainable, snapshotted tiers automatically. See it in a live demo, or read the NIST AI RMF checklist for the wider program.
Put this into practice.
Inventory, assess, approve, and evidence every AI use case in one place.