AI RISK ASSESSMENT

Make AI risk visible before deciding what to do.

We look at how AI is selected, supplied, used and overseen in your organisation. The result is a view of your actual exposure, rather than a generic list of things that could go wrong.

An AI risk assessment identifies a specific AI use, the people and data it affects, how failure could occur, the controls already in place and the evidence needed to decide whether the remaining risk is acceptable.

Risk depends on context

The same tool can be low-risk in one workflow and consequential in another. Drafting an internal agenda is not equivalent to making an eligibility decision, handling special-category data or producing advice that people will rely upon. The assessment begins with the real use case.

What we look at

  • Purpose and ownership: what the system is for, who approves it and who remains accountable.
  • People and impact: who may be affected and what happens if the output is wrong or unfair.
  • Data: what enters the system, where it goes, retention, confidentiality and lawful handling.
  • Supplier: contractual terms, model changes, access, monitoring and dependency.
  • Human oversight: what reviewers can realistically detect, challenge and stop.
  • Evidence: logs, evaluations, policies, decisions and incidents that make oversight demonstrable.

How this differs from the full governance audit

A risk assessment is usually centred on a defined system or use case. The AI governance audit looks across an agreed organisational scope and considers risk, opportunity, ownership and governance together.

Relevant UK principles

The UK’s principles-led framework asks regulators to consider safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Application depends on the regulator and context. Read the GOV.UK guidance.

This page provides general information, not legal advice. A regulatory conclusion may require legal counsel or a sector specialist.

Useful starting evidence

  • A plain-language description of the intended use.
  • The supplier’s terms, privacy and security information.
  • The data categories involved.
  • Existing approvals, DPIAs, policies or risk registers.
  • Examples of outputs and how people review them.
  • Known incidents, complaints, overrides or near misses.

Tell us what you are considering.

We can help establish whether a focused risk assessment or a wider governance audit is the more useful next step.

Email Mise