AI Risk Assessment
Use factual, versioned evidence where available. State assumptions and gaps explicitly. This template does not determine legal, regulatory, safety, or compliance outcomes.
1. System context
- System ID and name:
- Intended purpose:
- Primary users and affected parties:
- In-scope decisions or actions:
- Explicitly prohibited uses:
- Autonomy and human-review boundary:
- Models, retrieval sources, tools, and permission scope:
2. Data and lifecycle context
- Data categories and provenance:
- Retention and access boundary:
- Model/configuration version:
- Deployment environment:
- Change triggers requiring reassessment:
3. Risk identification
| Risk | Cause / scenario | Affected party | Potential impact | Existing controls | Evidence gap |
|---|---|---|---|---|---|
Consider safety, reliability, privacy, security, fairness, accessibility, misuse, model/tool failure, prompt injection, data leakage, and operational accountability where relevant.
4. Evaluation and residual risk
| Risk | Likelihood | Impact | Residual tier | Acceptance / mitigation decision | Accountable owner |
|---|---|---|---|---|---|
| low / medium / high | low / medium / high | low / medium / high |
5. Monitoring and response
- Signals to monitor:
- Thresholds and escalation triggers:
- Incident owner and response path:
- Rollback / disable path:
- Next review date: