AI risk assessment for business systems
An AI risk assessment asks what could go wrong, who could be harmed and which controls are needed before use. Paul Okhrem's method records the system's purpose, likely failure paths, evidence and accountable owners. The score is a prioritization aid, not a legal classification, safety certificate or permission to deploy.
Define the system before scoring it
Describe the actual workflow, not just the model. Record inputs, users, connected systems, outputs and permitted actions. Include affected people who do not use the system themselves.
A document summarizer and a credit-decision tool may use the same model but need different assessments. A changed data source, tool permission or intended use can require a new review.
A six-step AI risk assessment method
- Map the use case. Record purpose, owners, data flows, users, decisions and excluded uses.
- Identify harm scenarios. Consider error, bias, privacy, security, misuse, outages and harmful automated actions.
- Assess likelihood and impact. State assumptions, uncertainty and the period being assessed.
- Select controls. Define prevention, detection, human review and recovery. Assign an owner to each control.
- Test and assess remaining risk. Collect evidence that controls work, then document what they do not address.
- Make and record the decision. Approve, limit, delay or stop the use case. Set review triggers and escalation.
The NIST AI RMF provides a broader structure for ongoing risk work. This six-step method is a practical worksheet, not an official NIST checklist.
How the 1-to-5 scoring aid works
Rate likelihood from 1 (unlikely in the defined conditions) to 5 (expected or frequent). Rate impact from 1 (limited and reversible) to 5 (severe harm or disruption). Multiply them to help prioritize review.
| Score | Illustrative treatment | Decision limit |
|---|---|---|
| 1–6 | Record controls and normal review | Not automatic approval |
| 8–12 | Require a documented control plan and owner review | Resolve material evidence gaps |
| 15–25 | Escalate before release; restrict or stop until addressed | Executive and specialist review as appropriate |
Only certain products are possible with whole-number inputs from 1 to 5. The bands cover those products. These are ordinal judgments, not calculated probabilities or a universal standard. Severe, prohibited or poorly understood harm can require escalation regardless of the total score.
Example: AI that drafts customer refunds
A support tool reads a case and suggests a refund. Risks include the wrong customer, an invented policy exception, excessive access to payment data and duplicate refunds.
Limit the tool to approved records. Require a person to approve the refund. Validate the amount outside the model. Use an idempotent payment process and retain an audit record. Test unusual cases and unavailable dependencies.
After controls, the risk owner still decides whether the remaining risk is acceptable. This is an illustrative assessment, not a claim about a client outcome.
Risk assessment versus impact assessment
A risk assessment considers failure scenarios and their treatment. An impact assessment considers effects on people, organizations and society. Legal assessments, such as a data protection impact assessment or an applicable fundamental-rights assessment, have specific requirements.
This worksheet does not replace them. Ask qualified privacy and legal advisers which assessments apply. Use the EU AI Act checklist to organize role and classification questions.
Download the AI risk register
Download the free AI risk assessment CSV. Record one row per harm scenario. Link to tests and decisions in a controlled workspace; do not place personal data or secrets in a shared register.
Review on an agreed schedule, such as quarterly, and after a material change, incident or new requirement. High-risk or fast-changing systems may need more frequent review.
Paul Okhrem's AI governance consulting helps teams connect assessments to release decisions. See the governance framework for ownership and agentic governance for action controls.
Questions about ai risk assessment for business systems
Is a low risk score enough to release an AI system?
No. The owner must review the evidence, uncertainty, legal duties and remaining risk. A low numerical score cannot authorize a prohibited use or excuse missing controls.
Who should complete the assessment?
The business and technical owners should work with security, privacy, legal and affected operational teams. Use independent specialist review where the risk requires it.
When should an AI risk assessment be repeated?
Review it after material changes, incidents, new evidence or new requirements, as well as on the planned schedule. A model or permission change can invalidate earlier results.
Change log
- : Reviewed copy, source boundaries and supporting resources.
Send a private brief to Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.
Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.