An AI risk matrix supports triage and priority. It does not determine whether a system is lawful, safe or in a regulatory category. Use it to decide how much evidence, review and oversight a case requires.

Assess impact on people and the organization, likelihood under real conditions, exposed scale, reversibility and a person’s ability to understand, correct or appeal.

Low-risk cases are reversible and limited, but still need an owner, basic tests and monitoring. Medium-risk cases require documented evaluation and proportional privacy, security and human review. High-impact, low-reversibility or hard-to-contest cases require specialists, leadership approval and stronger controls.

A critical signal overrides an average score. Escalate potential severe harm or prohibited use even when other dimensions are low. Confirm legal obligations with qualified professionals.

Record the result in the AI system inventory and apply the governance checklist.

[ PRACTICAL RESOURCES ]

Use these resources

[ CONTINUE EXPLORING ]

AI Governance

Turn responsible AI principles into operational decisions, controls and evidence.

Primary sources