AIGO — AI Risk Assessment Example
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-003
Document Type: Implementation Example
Example Type: AI Risk Assessment
Related Framework: AIGO AI Governance Operating Framework
1. Purpose
This document provides an illustrative example of how an AI risk assessment can be performed using the AIGO AI Governance Operating Framework. The example demonstrates how an organization can:- identify AI-related risks;
- understand the context in which an AI system operates;
- assess potential harms;
- evaluate likelihood and impact;
- determine inherent risk;
- identify existing controls;
- assess control effectiveness;
- determine residual risk;
- define risk treatment;
- assign accountable owners;
- establish monitoring requirements;
- determine risk acceptance;
- maintain traceable evidence.
2. Example Organization
For this example, the organization is ExampleCorp, a fictional organization operating an internal AI-enabled recruitment process. ExampleCorp has implemented AIGO and uses a formal AI risk management process.3. AI System Under Assessment
System Name: Candidate Assessment Assistant AI System ID:AI-HR-001
Business Function: Human Resources
Intended Purpose: Support recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations.
Decision Authority: Human recruitment personnel.
Autonomous Decision: No.
Governance Classification: High-Risk AI System.
4. Assessment Objective
The objective is to determine:- what risks the system presents;
- who may be affected;
- how severe potential harms could be;
- how likely those harms are;
- which controls are required;
- whether existing controls are effective;
- what residual risk remains;
- whether the residual risk is acceptable;
- what additional treatment is required.
5. Assessment Scope
The assessment covers:- system purpose;
- data;
- model behavior;
- recruitment workflow;
- human oversight;
- security;
- privacy;
- fairness;
- transparency;
- explainability;
- operational risks;
- supplier risks;
- change risks;
- monitoring;
- incident management.
6. Assessment Context
The AI system processes candidate information and produces recommendations that may influence whether candidates proceed in a recruitment process. The system therefore has potential effects on individuals. The assessment considers both:- direct effects produced by the AI system; and
- indirect effects arising from human use of AI outputs.
7. Risk Assessment Principles
AIGO applies the following principles:- risk must be assessed in context;
- risks should be assessed across the AI lifecycle;
- potential harm must be considered;
- affected stakeholders must be identified;
- existing controls must be considered;
- residual risk must be explicitly documented;
- risk ownership must be assigned;
- treatment decisions must be traceable;
- significant risks require appropriate governance escalation.
8. Assessment Lifecycle
9. Step 1 — Define the AI System Context
The assessment begins by documenting the system and its operating environment.10. Business Context
The organization receives a large number of applications. The AI system is intended to help recruitment personnel manage application volume. The system is not intended to replace human recruitment decisions.11. Stakeholder Identification
Relevant stakeholders include:12. Affected Persons
The primary affected persons are job applicants. Potential impacts include:- reduced employment opportunity;
- unfair prioritization;
- discriminatory outcomes;
- incorrect assessment;
- lack of transparency;
- inability to challenge an AI-supported recommendation.
13. AI Lifecycle Scope
Risk assessment covers the complete lifecycle.14. Risk Categories
The assessment uses the following risk categories:- Governance
- Strategic
- Legal and regulatory
- Fairness
- Human rights / individual impact
- Privacy
- Security
- Safety
- Accuracy
- Reliability
- Robustness
- Transparency
- Explainability
- Human oversight
- Operational
- Supplier / third-party
- Model change
- Data quality
- Reputational
- Financial
15. Risk Identification Method
Risks are identified using:- system documentation;
- stakeholder workshops;
- process analysis;
- data-flow analysis;
- model documentation;
- technical testing;
- historical incidents;
- control reviews;
- legal and regulatory analysis;
- expert assessment;
- monitoring results.
16. Risk Statement Format
Each risk is documented using the following structure: Cause → Event → Consequence Example:Incomplete or biased training data may cause the AI system to produce systematically different recommendations for certain groups, potentially resulting in unfair or discriminatory recruitment outcomes.This structure helps distinguish the underlying cause from the event and resulting harm.
17. Risk Scoring Model
AIGO uses a risk scoring approach based on: Likelihood × Impact The organization may adapt the scoring methodology to its risk management framework.18. Likelihood Scale
19. Impact Scale
20. Risk Score
The inherent risk score is calculated as: Risk Score = Likelihood × Impact The resulting score is then mapped to the organization’s risk categories.21. Example Risk Matrix
22. Example Risk Bands
The actual thresholds should be approved by the organization’s risk governance framework.
23. Inherent Risk
Inherent risk represents the risk before considering existing controls. It answers:What level of risk would exist if the identified controls were not considered?
24. Example Inherent Risk Register
25. Risk R-001 — Biased Candidate Ranking
25.1 Risk Description
The AI system may produce systematically biased candidate rankings because of limitations in training data, features, model behavior, or implementation.25.2 Potential Consequence
Potential consequences include:- unequal opportunity;
- systematic disadvantage;
- discrimination concerns;
- regulatory exposure;
- reputational damage.
25.3 Inherent Risk
Likelihood: 4 — Likely Impact: 5 — Severe Score: 20 Level: Critical26. Risk R-001 — Existing Controls
Existing controls include:- data-quality assessment;
- fairness testing;
- model validation;
- human review;
- monitoring;
- incident escalation.
27. Risk R-001 — Control Effectiveness
28. Risk R-001 — Residual Risk
After considering existing controls: Likelihood: 2 — Unlikely Impact: 5 — Severe Residual Score: 10 Residual Level: High Residual risk remains because statistical testing and human oversight cannot completely eliminate the possibility of unfair outcomes.29. Risk R-001 — Treatment
Additional treatment:- increase fairness monitoring frequency;
- introduce additional review thresholds;
- monitor outcome disparities;
- conduct periodic independent testing;
- review material model changes.
30. Risk R-002 — Discriminatory Outcome
30.1 Risk Description
The AI system may contribute to discriminatory recruitment outcomes.30.2 Inherent Risk
Likelihood: 3 Impact: 5 Score: 15 Level: High30.3 Controls
- fairness assessment;
- restricted features;
- human review;
- monitoring;
- complaint handling;
- incident management.
30.4 Residual Risk
Likelihood: 2 Impact: 5 Score: 10 Level: High30.5 Treatment
- enhanced fairness testing;
- review of affected populations;
- escalation of material findings;
- temporary suspension if serious concerns arise.
31. Risk R-003 — Incorrect Candidate Exclusion
31.1 Risk Description
The system may produce an inaccurate recommendation that contributes to a candidate being incorrectly deprioritized.31.2 Inherent Risk
Likelihood: 3 Impact: 4 Score: 12 Level: High31.3 Controls
- model validation;
- performance testing;
- human review;
- minimum information requirements;
- override capability.
31.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium31.5 Treatment
- maintain mandatory human review;
- monitor false-negative indicators;
- periodically validate model performance.
32. Risk R-004 — Privacy Violation
32.1 Risk Description
Personal information may be processed beyond the approved purpose or exposed through unauthorized access.32.2 Inherent Risk
Likelihood: 2 Impact: 5 Score: 10 Level: High32.3 Controls
- data minimization;
- access control;
- retention requirements;
- privacy assessment;
- logging;
- security monitoring.
32.4 Residual Risk
Likelihood: 1 Impact: 5 Score: 5 Level: Medium32.5 Treatment
- periodic access review;
- privacy monitoring;
- security testing;
- incident response readiness.
33. Risk R-005 — Unauthorized Access
33.1 Risk Description
Unauthorized users may gain access to candidate data or AI system functionality.33.2 Inherent Risk
Likelihood: 2 Impact: 5 Score: 10 Level: High33.3 Controls
- identity management;
- role-based access;
- privileged access management;
- audit logging;
- security monitoring.
33.4 Residual Risk
Likelihood: 1 Impact: 5 Score: 5 Level: Medium34. Risk R-006 — Automation Bias
34.1 Risk Description
Human users may place excessive reliance on AI recommendations and fail to exercise independent judgment.34.2 Inherent Risk
Likelihood: 4 Impact: 4 Score: 16 Level: High34.3 Controls
- mandatory human decision;
- user training;
- override capability;
- decision documentation;
- monitoring of override rates.
34.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium35. Risk R-007 — Model Drift
35.1 Risk Description
Changes in candidate populations, recruitment patterns, data, or system conditions may reduce model performance over time.35.2 Inherent Risk
Likelihood: 3 Impact: 4 Score: 12 Level: High35.3 Controls
- performance monitoring;
- periodic validation;
- drift detection;
- change management.
35.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium36. Risk R-008 — Supplier Model Change
36.1 Risk Description
A third-party provider may modify the underlying model or service without sufficient organizational awareness.36.2 Inherent Risk
Likelihood: 3 Impact: 4 Score: 12 Level: High36.3 Controls
- supplier agreements;
- change notification;
- supplier monitoring;
- contractual requirements;
- reassessment.
36.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium37. Risk R-009 — Insufficient Explainability
37.1 Risk Description
Recruitment personnel may be unable to understand the basis or limitations of an AI recommendation.37.2 Inherent Risk
Likelihood: 3 Impact: 4 Score: 12 Level: High37.3 Controls
- system documentation;
- user guidance;
- output rationale where available;
- human review;
- training.
37.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium38. Risk R-010 — Inaccurate Recommendation
38.1 Risk Description
The system may produce incorrect recommendations because of model limitations, poor data, or unusual candidate circumstances.38.2 Inherent Risk
Likelihood: 3 Impact: 4 Score: 12 Level: High38.3 Controls
- validation;
- performance thresholds;
- human review;
- exception handling;
- monitoring.
38.4 Residual Risk
Likelihood: 2 Impact: 4 Score: 8 Level: Medium39. Consolidated Risk Register
40. Risk Treatment Prioritization
Treatment priority is determined by:- severity;
- potential impact on individuals;
- regulatory significance;
- likelihood;
- control effectiveness;
- detectability;
- reversibility;
- organizational risk tolerance.
41. Treatment Priority
42. Risk Treatment Plan
43. Control-to-Risk Relationship
44. Control Effectiveness Assessment
Controls are assessed using:- design effectiveness;
- implementation status;
- operating effectiveness;
- evidence quality;
- monitoring results.
45. Control Effectiveness Scale
46. Example Control Assessment
47. Residual Risk Evaluation
Residual risk is evaluated after:- controls are implemented;
- control effectiveness is assessed;
- monitoring information is considered;
- known incidents are reviewed.
48. Residual Risk Decision Model
49. Risk Acceptance Criteria
Risk acceptance should consider:- organizational risk appetite;
- potential impact on affected persons;
- legal and regulatory requirements;
- control effectiveness;
- evidence quality;
- reversibility;
- ability to detect harm;
- availability of safer alternatives.
50. Example Acceptance Decision
The organization determines that the residual risks are manageable only under specific conditions. Conditions include:- mandatory human oversight;
- enhanced fairness monitoring;
- periodic risk reassessment;
- incident escalation;
- formal change management;
- independent assurance.
51. Risk Acceptance Record
52. Risks That Must Not Be Accepted Automatically
Certain situations may require escalation rather than ordinary risk acceptance. Examples include:- uncontrolled critical risks;
- unlawful processing;
- serious discriminatory effects;
- inability to maintain required human oversight;
- material security compromise;
- unknown critical model behavior;
- failure of mandatory controls.
53. Risk Escalation
54. Risk Monitoring
Risk monitoring tracks:- changes in risk level;
- control effectiveness;
- incidents;
- complaints;
- model performance;
- fairness indicators;
- changes in context;
- regulatory developments;
- supplier changes.
55. Risk Indicators
Example indicators include:56. Trigger Conditions
A risk reassessment is triggered when:- the intended purpose changes;
- affected persons change;
- data changes materially;
- model changes materially;
- supplier changes;
- performance deteriorates;
- significant incidents occur;
- new legal requirements apply;
- monitoring identifies material anomalies.
57. Risk Reassessment Flow
58. Example Trigger Event
A model provider releases a new underlying model version. ExampleCorp receives notification that the model architecture has changed. Because the underlying model may affect system behavior, the organization treats the change as potentially material.59. Change-Related Risk Assessment
The organization evaluates:- performance;
- fairness;
- data behavior;
- explainability;
- security;
- human oversight;
- new failure modes.
60. Evidence Requirements
The risk assessment must be supported by evidence. Examples include:- completed risk assessment;
- stakeholder records;
- risk register;
- scoring rationale;
- control assessment;
- test results;
- monitoring reports;
- incident records;
- treatment plans;
- approval records;
- risk acceptance records.
61. Risk Evidence Chain
62. Risk Assessment Traceability
Every significant risk should be traceable to:- the AI system;
- its purpose;
- its lifecycle stage;
- affected stakeholders;
- applicable controls;
- accountable owner;
- evidence;
- treatment;
- residual risk;
- decision.
63. Example Traceability Record
64. Relationship to AIGO Lifecycle
The assessment operates throughout the AIGO lifecycle.65. Risk Assessment Frequency
Risk assessments should be performed:- before deployment;
- after material changes;
- after significant incidents;
- when risk context changes;
- at defined periodic intervals;
- when monitoring identifies material concerns.
66. Management Review
Management review should consider:- high and critical risks;
- overdue treatments;
- residual risk;
- incidents;
- control effectiveness;
- monitoring trends;
- assurance findings;
- emerging risks;
- regulatory changes.
67. Example Management Review Decision
Management reviews the risk register and determines: Decision: Continue operation with enhanced controls. Conditions:- complete outstanding fairness monitoring;
- complete supplier change assessment;
- perform quarterly risk review;
- report material incidents immediately.
68. Risk Assessment Completion Criteria
The assessment is considered complete when:- context is documented;
- stakeholders are identified;
- risks are identified;
- risks are analyzed;
- risks are evaluated;
- controls are identified;
- treatment is defined;
- residual risks are calculated;
- owners are assigned;
- evidence is available;
- acceptance or escalation is documented.
69. Assessment Quality Review
Before approval, an independent reviewer checks:- completeness;
- consistency;
- scoring rationale;
- evidence;
- control relationships;
- residual risk;
- treatment adequacy;
- ownership;
- approval authority.
70. Example Assessment Review
71. Final Risk Assessment Decision
The assessment concludes: Overall Inherent Risk: High / Critical Overall Residual Risk: Medium / High Governance Decision: Conditional approval Required Conditions:- enhanced monitoring;
- human oversight;
- periodic fairness assessment;
- formal change management;
- independent assurance.
72. Example Risk Assessment Summary
73. Lessons From the Example
This assessment demonstrates several AIGO principles.73.1 Risk Is Contextual
The same technology may present different risks depending on its purpose and environment.73.2 Risk Is Lifecycle-Based
Risks can change as an AI system moves from development to operation.73.3 Controls Do Not Eliminate Risk
Controls reduce risk but may leave residual exposure.73.4 Evidence Matters
Risk decisions should be supported by evidence rather than assumptions.73.5 Human Oversight Is a Control
Human involvement must be meaningful and capable of challenging AI outputs.73.6 Monitoring Is Essential
Risk assessments must be updated when operating conditions change.74. AIGO Risk Assessment Model
The complete model can be summarized as:75. Minimum Risk Assessment Record
AIGO implementations should maintain, at minimum:- AI system identifier;
- intended purpose;
- lifecycle stage;
- classification;
- affected stakeholders;
- risk category;
- risk statement;
- likelihood;
- impact;
- inherent risk;
- existing controls;
- control effectiveness;
- residual risk;
- treatment;
- risk owner;
- control owner;
- evidence;
- acceptance decision;
- review date;
- reassessment triggers.
76. Relationship to AIGO Procedures
This example should be implemented through the applicable AIGO procedures, particularly:- AI Governance Procedure;
- AI System Registration Procedure;
- AI Risk Assessment Procedure;
- AI Classification Procedure;
- AI Control Assessment Procedure;
- AI Approval Procedure;
- AI Change Management Procedure;
- AI Incident Management Procedure;
- AI Monitoring Procedure;
- AI Assurance Procedure;
- AI Risk Acceptance Procedure;
- Continuous Improvement Procedure.
77. Relationship to AIGO Controls
The risk assessment provides the foundation for determining which AIGO controls are required.78. Relationship to ISO/IEC 42001
The example demonstrates risk-management activities that may support an AI management system aligned with ISO/IEC 42001. Relevant areas include:- organizational context;
- risk and opportunity management;
- operational planning;
- AI system lifecycle controls;
- performance evaluation;
- management review;
- continual improvement.
79. Relationship to NIST AI RMF
The example can also be mapped to the four NIST AI RMF Functions.80. Final Assessment Record
AI System: Candidate Assessment Assistant AI System ID:AI-HR-001
Classification: High-Risk
Assessment Type: Initial AI Risk Assessment
Assessment Status: Conditionally Approved
Overall Inherent Risk: High / Critical
Overall Residual Risk: Medium / High
Human Oversight: Mandatory
Monitoring: Enhanced
Assurance: Required
Next Review: Quarterly or upon material trigger
81. Document Status
Document: AIGO — AI Risk Assessment Example Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-EXAMPLE-003
Document Type: Implementation Example
Example Type: AI Risk Assessment
This document provides an illustrative example of how AI risk assessment can be performed and governed within the AIGO Framework.
82. End of Example Document
AIGO — AI Risk Assessment Example Document ID:AIGO-EXAMPLE-003
Version: 0.1
Status: Draft
End of Document