> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 03 AIGO AI Risk Assessment Example v0.1

# AIGO — AI Risk Assessment Example

## AIGO — AI Governance Operating Framework

**Version:** 0.1
**Status:** Draft
**Working Name:** AIGO
**Full Name:** AI Governance Operating Framework
**Document Identifier:** `AIGO-EXAMPLE-003`
**Document Type:** Implementation Example
**Example Type:** AI Risk Assessment
**Related Framework:** AIGO AI Governance Operating Framework

***

## 1. Purpose

This document provides an illustrative example of how an AI risk assessment can be performed using the AIGO AI Governance Operating Framework.

The example demonstrates how an organization can:

* identify AI-related risks;
* understand the context in which an AI system operates;
* assess potential harms;
* evaluate likelihood and impact;
* determine inherent risk;
* identify existing controls;
* assess control effectiveness;
* determine residual risk;
* define risk treatment;
* assign accountable owners;
* establish monitoring requirements;
* determine risk acceptance;
* maintain traceable evidence.

This document is an example and does not constitute legal, regulatory, technical, or professional advice.

***

# 2. Example Organization

For this example, the organization is **ExampleCorp**, a fictional organization operating an internal AI-enabled recruitment process.

ExampleCorp has implemented AIGO and uses a formal AI risk management process.

***

# 3. AI System Under Assessment

**System Name:** Candidate Assessment Assistant

**AI System ID:** `AI-HR-001`

**Business Function:** Human Resources

**Intended Purpose:** Support recruitment personnel by analyzing candidate information and generating candidate prioritization recommendations.

**Decision Authority:** Human recruitment personnel.

**Autonomous Decision:** No.

**Governance Classification:** High-Risk AI System.

***

# 4. Assessment Objective

The objective is to determine:

1. what risks the system presents;
2. who may be affected;
3. how severe potential harms could be;
4. how likely those harms are;
5. which controls are required;
6. whether existing controls are effective;
7. what residual risk remains;
8. whether the residual risk is acceptable;
9. what additional treatment is required.

***

# 5. Assessment Scope

The assessment covers:

* system purpose;
* data;
* model behavior;
* recruitment workflow;
* human oversight;
* security;
* privacy;
* fairness;
* transparency;
* explainability;
* operational risks;
* supplier risks;
* change risks;
* monitoring;
* incident management.

The assessment does not constitute a complete technical security assessment or privacy impact assessment unless those assessments are separately performed.

***

# 6. Assessment Context

The AI system processes candidate information and produces recommendations that may influence whether candidates proceed in a recruitment process.

The system therefore has potential effects on individuals.

The assessment considers both:

* direct effects produced by the AI system; and
* indirect effects arising from human use of AI outputs.

***

# 7. Risk Assessment Principles

AIGO applies the following principles:

* risk must be assessed in context;
* risks should be assessed across the AI lifecycle;
* potential harm must be considered;
* affected stakeholders must be identified;
* existing controls must be considered;
* residual risk must be explicitly documented;
* risk ownership must be assigned;
* treatment decisions must be traceable;
* significant risks require appropriate governance escalation.

***

# 8. Assessment Lifecycle

```text theme={null}
Define Context
      ↓
Identify AI Risks
      ↓
Analyze Risks
      ↓
Evaluate Risks
      ↓
Select Treatment
      ↓
Implement Controls
      ↓
Assess Residual Risk
      ↓
Accept / Escalate / Treat
      ↓
Monitor
      ↓
Review
```

***

# 9. Step 1 — Define the AI System Context

The assessment begins by documenting the system and its operating environment.

| Field            | Assessment Record                     |
| ---------------- | ------------------------------------- |
| AI System ID     | `AI-HR-001`                           |
| System Name      | Candidate Assessment Assistant        |
| Owner            | Head of Talent Technology             |
| Business Owner   | Chief People Officer                  |
| Risk Owner       | Enterprise Risk Manager               |
| Purpose          | Recruitment decision support          |
| Users            | Authorized recruitment personnel      |
| Affected Persons | Job applicants                        |
| Data             | Candidate application information     |
| Lifecycle Stage  | Pre-deployment / Controlled Operation |
| Classification   | High-Risk                             |

***

# 10. Business Context

The organization receives a large number of applications.

The AI system is intended to help recruitment personnel manage application volume.

The system is not intended to replace human recruitment decisions.

***

# 11. Stakeholder Identification

Relevant stakeholders include:

| Stakeholder             | Potential Interest / Impact |
| ----------------------- | --------------------------- |
| Applicants              | Potential decision impact   |
| Recruitment Staff       | Operational users           |
| Hiring Managers         | Decision users              |
| HR Leadership           | Business accountability     |
| AI Governance Authority | Governance oversight        |
| Risk Function           | Risk management             |
| Privacy Function        | Personal-data protection    |
| Security Function       | Security                    |
| Legal / Compliance      | Regulatory obligations      |
| Assurance Function      | Independent review          |

***

# 12. Affected Persons

The primary affected persons are job applicants.

Potential impacts include:

* reduced employment opportunity;
* unfair prioritization;
* discriminatory outcomes;
* incorrect assessment;
* lack of transparency;
* inability to challenge an AI-supported recommendation.

***

# 13. AI Lifecycle Scope

Risk assessment covers the complete lifecycle.

```text theme={null}
Design
  ↓
Data Preparation
  ↓
Development
  ↓
Validation
  ↓
Approval
  ↓
Deployment
  ↓
Operation
  ↓
Monitoring
  ↓
Change
  ↓
Retirement
```

***

# 14. Risk Categories

The assessment uses the following risk categories:

1. Governance
2. Strategic
3. Legal and regulatory
4. Fairness
5. Human rights / individual impact
6. Privacy
7. Security
8. Safety
9. Accuracy
10. Reliability
11. Robustness
12. Transparency
13. Explainability
14. Human oversight
15. Operational
16. Supplier / third-party
17. Model change
18. Data quality
19. Reputational
20. Financial

Not every category will apply equally to every AI system.

***

# 15. Risk Identification Method

Risks are identified using:

* system documentation;
* stakeholder workshops;
* process analysis;
* data-flow analysis;
* model documentation;
* technical testing;
* historical incidents;
* control reviews;
* legal and regulatory analysis;
* expert assessment;
* monitoring results.

***

# 16. Risk Statement Format

Each risk is documented using the following structure:

**Cause → Event → Consequence**

Example:

> Incomplete or biased training data may cause the AI system to produce systematically different recommendations for certain groups, potentially resulting in unfair or discriminatory recruitment outcomes.

This structure helps distinguish the underlying cause from the event and resulting harm.

***

# 17. Risk Scoring Model

AIGO uses a risk scoring approach based on:

**Likelihood × Impact**

The organization may adapt the scoring methodology to its risk management framework.

***

# 18. Likelihood Scale

| Score | Level          | Description                    |
| ----: | -------------- | ------------------------------ |
|     1 | Rare           | Highly unlikely                |
|     2 | Unlikely       | Could occur occasionally       |
|     3 | Possible       | May occur                      |
|     4 | Likely         | Expected to occur periodically |
|     5 | Almost Certain | Expected to occur frequently   |

***

# 19. Impact Scale

| Score | Level         | Description                                      |
| ----: | ------------- | ------------------------------------------------ |
|     1 | Insignificant | Minimal consequence                              |
|     2 | Minor         | Limited consequence                              |
|     3 | Moderate      | Material but manageable consequence              |
|     4 | Major         | Serious consequence                              |
|     5 | Severe        | Very serious or potentially systemic consequence |

***

# 20. Risk Score

The inherent risk score is calculated as:

**Risk Score = Likelihood × Impact**

The resulting score is then mapped to the organization's risk categories.

***

# 21. Example Risk Matrix

| Likelihood \ Impact |  1 |  2 |  3 |  4 |  5 |
| ------------------- | -: | -: | -: | -: | -: |
| 5 Almost Certain    |  5 | 10 | 15 | 20 | 25 |
| 4 Likely            |  4 |  8 | 12 | 16 | 20 |
| 3 Possible          |  3 |  6 |  9 | 12 | 15 |
| 2 Unlikely          |  2 |  4 |  6 |  8 | 10 |
| 1 Rare              |  1 |  2 |  3 |  4 |  5 |

***

# 22. Example Risk Bands

| Score | Risk Level | General Treatment                |
| ----: | ---------- | -------------------------------- |
|   1–4 | Low        | Manage through normal controls   |
|   5–9 | Medium     | Treatment normally required      |
| 10–16 | High       | Enhanced treatment and oversight |
| 17–25 | Critical   | Immediate governance attention   |

The actual thresholds should be approved by the organization's risk governance framework.

***

# 23. Inherent Risk

Inherent risk represents the risk before considering existing controls.

It answers:

> What level of risk would exist if the identified controls were not considered?

***

# 24. Example Inherent Risk Register

| ID    | Risk                          | Likelihood | Impact | Score | Level    |
| ----- | ----------------------------- | ---------: | -----: | ----: | -------- |
| R-001 | Biased candidate ranking      |          4 |      5 |    20 | Critical |
| R-002 | Discriminatory outcome        |          3 |      5 |    15 | High     |
| R-003 | Incorrect candidate exclusion |          3 |      4 |    12 | High     |
| R-004 | Privacy violation             |          2 |      5 |    10 | High     |
| R-005 | Unauthorized access           |          2 |      5 |    10 | High     |
| R-006 | Automation bias               |          4 |      4 |    16 | High     |
| R-007 | Model drift                   |          3 |      4 |    12 | High     |
| R-008 | Supplier model change         |          3 |      4 |    12 | High     |
| R-009 | Insufficient explainability   |          3 |      4 |    12 | High     |
| R-010 | Inaccurate recommendation     |          3 |      4 |    12 | High     |

***

# 25. Risk R-001 — Biased Candidate Ranking

## 25.1 Risk Description

The AI system may produce systematically biased candidate rankings because of limitations in training data, features, model behavior, or implementation.

## 25.2 Potential Consequence

Potential consequences include:

* unequal opportunity;
* systematic disadvantage;
* discrimination concerns;
* regulatory exposure;
* reputational damage.

## 25.3 Inherent Risk

**Likelihood:** 4 — Likely

**Impact:** 5 — Severe

**Score:** 20

**Level:** Critical

***

# 26. Risk R-001 — Existing Controls

Existing controls include:

* data-quality assessment;
* fairness testing;
* model validation;
* human review;
* monitoring;
* incident escalation.

***

# 27. Risk R-001 — Control Effectiveness

| Control             | Effectiveness       |
| ------------------- | ------------------- |
| Data Quality        | Effective           |
| Fairness Testing    | Partially Effective |
| Model Validation    | Effective           |
| Human Review        | Effective           |
| Monitoring          | Partially Effective |
| Incident Escalation | Effective           |

***

# 28. Risk R-001 — Residual Risk

After considering existing controls:

**Likelihood:** 2 — Unlikely

**Impact:** 5 — Severe

**Residual Score:** 10

**Residual Level:** High

Residual risk remains because statistical testing and human oversight cannot completely eliminate the possibility of unfair outcomes.

***

# 29. Risk R-001 — Treatment

Additional treatment:

* increase fairness monitoring frequency;
* introduce additional review thresholds;
* monitor outcome disparities;
* conduct periodic independent testing;
* review material model changes.

**Risk Owner:** Enterprise Risk Manager

**Control Owner:** Model Owner

***

# 30. Risk R-002 — Discriminatory Outcome

## 30.1 Risk Description

The AI system may contribute to discriminatory recruitment outcomes.

## 30.2 Inherent Risk

**Likelihood:** 3

**Impact:** 5

**Score:** 15

**Level:** High

## 30.3 Controls

* fairness assessment;
* restricted features;
* human review;
* monitoring;
* complaint handling;
* incident management.

## 30.4 Residual Risk

**Likelihood:** 2

**Impact:** 5

**Score:** 10

**Level:** High

## 30.5 Treatment

* enhanced fairness testing;
* review of affected populations;
* escalation of material findings;
* temporary suspension if serious concerns arise.

***

# 31. Risk R-003 — Incorrect Candidate Exclusion

## 31.1 Risk Description

The system may produce an inaccurate recommendation that contributes to a candidate being incorrectly deprioritized.

## 31.2 Inherent Risk

**Likelihood:** 3

**Impact:** 4

**Score:** 12

**Level:** High

## 31.3 Controls

* model validation;
* performance testing;
* human review;
* minimum information requirements;
* override capability.

## 31.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

## 31.5 Treatment

* maintain mandatory human review;
* monitor false-negative indicators;
* periodically validate model performance.

***

# 32. Risk R-004 — Privacy Violation

## 32.1 Risk Description

Personal information may be processed beyond the approved purpose or exposed through unauthorized access.

## 32.2 Inherent Risk

**Likelihood:** 2

**Impact:** 5

**Score:** 10

**Level:** High

## 32.3 Controls

* data minimization;
* access control;
* retention requirements;
* privacy assessment;
* logging;
* security monitoring.

## 32.4 Residual Risk

**Likelihood:** 1

**Impact:** 5

**Score:** 5

**Level:** Medium

## 32.5 Treatment

* periodic access review;
* privacy monitoring;
* security testing;
* incident response readiness.

***

# 33. Risk R-005 — Unauthorized Access

## 33.1 Risk Description

Unauthorized users may gain access to candidate data or AI system functionality.

## 33.2 Inherent Risk

**Likelihood:** 2

**Impact:** 5

**Score:** 10

**Level:** High

## 33.3 Controls

* identity management;
* role-based access;
* privileged access management;
* audit logging;
* security monitoring.

## 33.4 Residual Risk

**Likelihood:** 1

**Impact:** 5

**Score:** 5

**Level:** Medium

***

# 34. Risk R-006 — Automation Bias

## 34.1 Risk Description

Human users may place excessive reliance on AI recommendations and fail to exercise independent judgment.

## 34.2 Inherent Risk

**Likelihood:** 4

**Impact:** 4

**Score:** 16

**Level:** High

## 34.3 Controls

* mandatory human decision;
* user training;
* override capability;
* decision documentation;
* monitoring of override rates.

## 34.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

***

# 35. Risk R-007 — Model Drift

## 35.1 Risk Description

Changes in candidate populations, recruitment patterns, data, or system conditions may reduce model performance over time.

## 35.2 Inherent Risk

**Likelihood:** 3

**Impact:** 4

**Score:** 12

**Level:** High

## 35.3 Controls

* performance monitoring;
* periodic validation;
* drift detection;
* change management.

## 35.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

***

# 36. Risk R-008 — Supplier Model Change

## 36.1 Risk Description

A third-party provider may modify the underlying model or service without sufficient organizational awareness.

## 36.2 Inherent Risk

**Likelihood:** 3

**Impact:** 4

**Score:** 12

**Level:** High

## 36.3 Controls

* supplier agreements;
* change notification;
* supplier monitoring;
* contractual requirements;
* reassessment.

## 36.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

***

# 37. Risk R-009 — Insufficient Explainability

## 37.1 Risk Description

Recruitment personnel may be unable to understand the basis or limitations of an AI recommendation.

## 37.2 Inherent Risk

**Likelihood:** 3

**Impact:** 4

**Score:** 12

**Level:** High

## 37.3 Controls

* system documentation;
* user guidance;
* output rationale where available;
* human review;
* training.

## 37.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

***

# 38. Risk R-010 — Inaccurate Recommendation

## 38.1 Risk Description

The system may produce incorrect recommendations because of model limitations, poor data, or unusual candidate circumstances.

## 38.2 Inherent Risk

**Likelihood:** 3

**Impact:** 4

**Score:** 12

**Level:** High

## 38.3 Controls

* validation;
* performance thresholds;
* human review;
* exception handling;
* monitoring.

## 38.4 Residual Risk

**Likelihood:** 2

**Impact:** 4

**Score:** 8

**Level:** Medium

***

# 39. Consolidated Risk Register

| ID    | Risk                        | Inherent | Residual | Treatment                    |
| ----- | --------------------------- | -------- | -------- | ---------------------------- |
| R-001 | Biased candidate ranking    | Critical | High     | Enhanced fairness controls   |
| R-002 | Discriminatory outcome      | High     | High     | Enhanced fairness monitoring |
| R-003 | Incorrect exclusion         | High     | Medium   | Human review                 |
| R-004 | Privacy violation           | High     | Medium   | Privacy/security controls    |
| R-005 | Unauthorized access         | High     | Medium   | Access/security controls     |
| R-006 | Automation bias             | High     | Medium   | Human oversight              |
| R-007 | Model drift                 | High     | Medium   | Monitoring/revalidation      |
| R-008 | Supplier model change       | High     | Medium   | Supplier/change management   |
| R-009 | Insufficient explainability | High     | Medium   | Documentation/training       |
| R-010 | Inaccurate recommendation   | High     | Medium   | Validation/monitoring        |

***

# 40. Risk Treatment Prioritization

Treatment priority is determined by:

1. severity;
2. potential impact on individuals;
3. regulatory significance;
4. likelihood;
5. control effectiveness;
6. detectability;
7. reversibility;
8. organizational risk tolerance.

***

# 41. Treatment Priority

| Priority | Risk  | Reason                           |
| -------- | ----- | -------------------------------- |
| 1        | R-001 | Critical inherent risk           |
| 2        | R-002 | Potential discriminatory impact  |
| 3        | R-006 | Strong human-behavior dependency |
| 4        | R-003 | Potential individual impact      |
| 5        | R-007 | Lifecycle degradation            |
| 6        | R-008 | Third-party dependency           |
| 7        | R-010 | Accuracy concern                 |
| 8        | R-009 | Transparency concern             |
| 9        | R-004 | Privacy exposure                 |
| 10       | R-005 | Security exposure                |

***

# 42. Risk Treatment Plan

| Risk  | Action                       | Owner          | Priority | Status      |
| ----- | ---------------------------- | -------------- | -------- | ----------- |
| R-001 | Enhanced fairness monitoring | Model Owner    | Critical | Open        |
| R-002 | Periodic impact assessment   | Risk Owner     | High     | Open        |
| R-003 | Mandatory human review       | HR Owner       | High     | Implemented |
| R-004 | Privacy control review       | Privacy Owner  | High     | Implemented |
| R-005 | Access review                | Security Owner | High     | Implemented |
| R-006 | User training                | HR Owner       | High     | Implemented |
| R-007 | Drift monitoring             | Model Owner    | High     | Open        |
| R-008 | Supplier change controls     | Supplier Owner | High     | Open        |
| R-009 | Improve user guidance        | System Owner   | Medium   | Open        |
| R-010 | Performance monitoring       | Model Owner    | High     | Implemented |

***

# 43. Control-to-Risk Relationship

```text theme={null}
AI Risk
   ↓
Risk Treatment
   ↓
Control
   ↓
Procedure
   ↓
Evidence
   ↓
Monitoring
   ↓
Control Effectiveness
   ↓
Residual Risk
```

***

# 44. Control Effectiveness Assessment

Controls are assessed using:

* design effectiveness;
* implementation status;
* operating effectiveness;
* evidence quality;
* monitoring results.

***

# 45. Control Effectiveness Scale

| Rating              | Description                                       |
| ------------------- | ------------------------------------------------- |
| Effective           | Control adequately addresses the risk             |
| Partially Effective | Control reduces risk but has material limitations |
| Ineffective         | Control does not adequately address the risk      |
| Not Tested          | Sufficient evidence is not yet available          |

***

# 46. Example Control Assessment

| Control           | Design    | Operation  | Evidence | Rating              |
| ----------------- | --------- | ---------- | -------- | ------------------- |
| Human Review      | Effective | Effective  | Strong   | Effective           |
| Fairness Testing  | Effective | Partial    | Moderate | Partially Effective |
| Model Validation  | Effective | Effective  | Strong   | Effective           |
| Access Control    | Effective | Effective  | Strong   | Effective           |
| Monitoring        | Effective | Partial    | Moderate | Partially Effective |
| Change Management | Effective | Not Tested | Weak     | Not Tested          |

***

# 47. Residual Risk Evaluation

Residual risk is evaluated after:

* controls are implemented;
* control effectiveness is assessed;
* monitoring information is considered;
* known incidents are reviewed.

Residual risk must not be assumed to be low merely because controls exist.

***

# 48. Residual Risk Decision Model

```text theme={null}
Residual Risk
      ↓
Within Risk Tolerance?
   ↙              ↘
 Yes              No
 ↓                  ↓
Accept        Additional Treatment
                  ↓
             Reassessment
```

***

# 49. Risk Acceptance Criteria

Risk acceptance should consider:

* organizational risk appetite;
* potential impact on affected persons;
* legal and regulatory requirements;
* control effectiveness;
* evidence quality;
* reversibility;
* ability to detect harm;
* availability of safer alternatives.

***

# 50. Example Acceptance Decision

The organization determines that the residual risks are manageable only under specific conditions.

Conditions include:

* mandatory human oversight;
* enhanced fairness monitoring;
* periodic risk reassessment;
* incident escalation;
* formal change management;
* independent assurance.

***

# 51. Risk Acceptance Record

| Field                | Example                 |
| -------------------- | ----------------------- |
| Risk                 | R-001                   |
| Residual Score       | 10                      |
| Residual Level       | High                    |
| Treatment            | Enhanced controls       |
| Acceptance Status    | Conditional             |
| Risk Owner           | Enterprise Risk Manager |
| Acceptance Authority | AI Governance Authority |
| Conditions           | Enhanced monitoring     |
| Review Frequency     | Quarterly               |

***

# 52. Risks That Must Not Be Accepted Automatically

Certain situations may require escalation rather than ordinary risk acceptance.

Examples include:

* uncontrolled critical risks;
* unlawful processing;
* serious discriminatory effects;
* inability to maintain required human oversight;
* material security compromise;
* unknown critical model behavior;
* failure of mandatory controls.

***

# 53. Risk Escalation

```text theme={null}
Risk Identified
      ↓
Risk Assessment
      ↓
Critical / Unacceptable?
   ↙               ↘
 No                Yes
 ↓                   ↓
Treat             Escalate
                    ↓
              Governance Decision
                    ↓
          Treat / Restrict / Suspend
```

***

# 54. Risk Monitoring

Risk monitoring tracks:

* changes in risk level;
* control effectiveness;
* incidents;
* complaints;
* model performance;
* fairness indicators;
* changes in context;
* regulatory developments;
* supplier changes.

***

# 55. Risk Indicators

Example indicators include:

| Indicator          | Purpose                        |
| ------------------ | ------------------------------ |
| Override Rate      | Detect automation bias         |
| Error Rate         | Detect performance degradation |
| Fairness Indicator | Detect disparity               |
| Complaint Volume   | Detect stakeholder impact      |
| Incident Count     | Detect operational risk        |
| Model Drift        | Detect changing performance    |
| Control Failure    | Detect governance weakness     |
| Supplier Change    | Detect external dependency     |

***

# 56. Trigger Conditions

A risk reassessment is triggered when:

* the intended purpose changes;
* affected persons change;
* data changes materially;
* model changes materially;
* supplier changes;
* performance deteriorates;
* significant incidents occur;
* new legal requirements apply;
* monitoring identifies material anomalies.

***

# 57. Risk Reassessment Flow

```text theme={null}
Trigger Event
     ↓
Materiality Assessment
     ↓
Risk Reassessment
     ↓
Control Reassessment
     ↓
Residual Risk
     ↓
Governance Decision
```

***

# 58. Example Trigger Event

A model provider releases a new underlying model version.

ExampleCorp receives notification that the model architecture has changed.

Because the underlying model may affect system behavior, the organization treats the change as potentially material.

***

# 59. Change-Related Risk Assessment

The organization evaluates:

* performance;
* fairness;
* data behavior;
* explainability;
* security;
* human oversight;
* new failure modes.

Deployment is paused until required testing is completed.

***

# 60. Evidence Requirements

The risk assessment must be supported by evidence.

Examples include:

* completed risk assessment;
* stakeholder records;
* risk register;
* scoring rationale;
* control assessment;
* test results;
* monitoring reports;
* incident records;
* treatment plans;
* approval records;
* risk acceptance records.

***

# 61. Risk Evidence Chain

```text theme={null}
Risk
 ↓
Assessment
 ↓
Score
 ↓
Treatment
 ↓
Control
 ↓
Evidence
 ↓
Effectiveness
 ↓
Residual Risk
 ↓
Acceptance / Escalation
```

***

# 62. Risk Assessment Traceability

Every significant risk should be traceable to:

* the AI system;
* its purpose;
* its lifecycle stage;
* affected stakeholders;
* applicable controls;
* accountable owner;
* evidence;
* treatment;
* residual risk;
* decision.

***

# 63. Example Traceability Record

| Element               | Record                       |
| --------------------- | ---------------------------- |
| AI System             | `AI-HR-001`                  |
| Risk ID               | `R-001`                      |
| Lifecycle             | Operate                      |
| Risk                  | Biased candidate ranking     |
| Impacted Stakeholders | Applicants                   |
| Control               | Fairness testing             |
| Procedure             | AI Risk Assessment Procedure |
| Evidence              | Fairness Assessment          |
| Owner                 | Model Owner                  |
| Residual Risk         | High                         |
| Decision              | Conditional acceptance       |
| Monitoring            | Quarterly                    |

***

# 64. Relationship to AIGO Lifecycle

The assessment operates throughout the AIGO lifecycle.

```text theme={null}
Govern
   ↓
Identify
   ↓
Classify
   ↓
Assess
   ↓
Treat
   ↓
Approve
   ↓
Deploy
   ↓
Operate
   ↓
Monitor
   ↓
Assure
   ↓
Improve
   ↓
Change / Continue / Suspend / Retire
```

Risk assessment is therefore not a one-time activity.

***

# 65. Risk Assessment Frequency

Risk assessments should be performed:

* before deployment;
* after material changes;
* after significant incidents;
* when risk context changes;
* at defined periodic intervals;
* when monitoring identifies material concerns.

***

# 66. Management Review

Management review should consider:

* high and critical risks;
* overdue treatments;
* residual risk;
* incidents;
* control effectiveness;
* monitoring trends;
* assurance findings;
* emerging risks;
* regulatory changes.

***

# 67. Example Management Review Decision

Management reviews the risk register and determines:

**Decision:** Continue operation with enhanced controls.

Conditions:

* complete outstanding fairness monitoring;
* complete supplier change assessment;
* perform quarterly risk review;
* report material incidents immediately.

***

# 68. Risk Assessment Completion Criteria

The assessment is considered complete when:

* context is documented;
* stakeholders are identified;
* risks are identified;
* risks are analyzed;
* risks are evaluated;
* controls are identified;
* treatment is defined;
* residual risks are calculated;
* owners are assigned;
* evidence is available;
* acceptance or escalation is documented.

***

# 69. Assessment Quality Review

Before approval, an independent reviewer checks:

* completeness;
* consistency;
* scoring rationale;
* evidence;
* control relationships;
* residual risk;
* treatment adequacy;
* ownership;
* approval authority.

***

# 70. Example Assessment Review

| Review Area         | Result   |
| ------------------- | -------- |
| Scope               | Complete |
| Context             | Complete |
| Stakeholders        | Complete |
| Risk Identification | Complete |
| Risk Scoring        | Complete |
| Controls            | Complete |
| Treatment           | Complete |
| Residual Risk       | Complete |
| Evidence            | Adequate |
| Ownership           | Complete |
| Approval            | Pending  |

***

# 71. Final Risk Assessment Decision

The assessment concludes:

**Overall Inherent Risk:** High / Critical

**Overall Residual Risk:** Medium / High

**Governance Decision:** Conditional approval

**Required Conditions:**

* enhanced monitoring;
* human oversight;
* periodic fairness assessment;
* formal change management;
* independent assurance.

***

# 72. Example Risk Assessment Summary

| Area                  | Result                         |
| --------------------- | ------------------------------ |
| AI System             | Candidate Assessment Assistant |
| Classification        | High-Risk                      |
| Highest Inherent Risk | Critical                       |
| Highest Residual Risk | High                           |
| Critical Controls     | Operational                    |
| Human Oversight       | Mandatory                      |
| Monitoring            | Enhanced                       |
| Assurance             | Required                       |
| Risk Acceptance       | Conditional                    |
| Lifecycle Decision    | Continue with conditions       |

***

# 73. Lessons From the Example

This assessment demonstrates several AIGO principles.

### 73.1 Risk Is Contextual

The same technology may present different risks depending on its purpose and environment.

### 73.2 Risk Is Lifecycle-Based

Risks can change as an AI system moves from development to operation.

### 73.3 Controls Do Not Eliminate Risk

Controls reduce risk but may leave residual exposure.

### 73.4 Evidence Matters

Risk decisions should be supported by evidence rather than assumptions.

### 73.5 Human Oversight Is a Control

Human involvement must be meaningful and capable of challenging AI outputs.

### 73.6 Monitoring Is Essential

Risk assessments must be updated when operating conditions change.

***

# 74. AIGO Risk Assessment Model

The complete model can be summarized as:

```text theme={null}
Context
   ↓
Stakeholders
   ↓
AI System
   ↓
Risk Identification
   ↓
Risk Analysis
   ↓
Inherent Risk
   ↓
Controls
   ↓
Control Effectiveness
   ↓
Residual Risk
   ↓
Treatment
   ↓
Acceptance / Escalation
   ↓
Monitoring
   ↓
Reassessment
   ↓
Continual Improvement
```

***

# 75. Minimum Risk Assessment Record

AIGO implementations should maintain, at minimum:

* AI system identifier;
* intended purpose;
* lifecycle stage;
* classification;
* affected stakeholders;
* risk category;
* risk statement;
* likelihood;
* impact;
* inherent risk;
* existing controls;
* control effectiveness;
* residual risk;
* treatment;
* risk owner;
* control owner;
* evidence;
* acceptance decision;
* review date;
* reassessment triggers.

***

# 76. Relationship to AIGO Procedures

This example should be implemented through the applicable AIGO procedures, particularly:

* AI Governance Procedure;
* AI System Registration Procedure;
* AI Risk Assessment Procedure;
* AI Classification Procedure;
* AI Control Assessment Procedure;
* AI Approval Procedure;
* AI Change Management Procedure;
* AI Incident Management Procedure;
* AI Monitoring Procedure;
* AI Assurance Procedure;
* AI Risk Acceptance Procedure;
* Continuous Improvement Procedure.

***

# 77. Relationship to AIGO Controls

The risk assessment provides the foundation for determining which AIGO controls are required.

```text theme={null}
Risk
  ↓
Control Requirement
  ↓
Control Selection
  ↓
Control Implementation
  ↓
Control Assessment
  ↓
Evidence
  ↓
Residual Risk
```

***

# 78. Relationship to ISO/IEC 42001

The example demonstrates risk-management activities that may support an AI management system aligned with ISO/IEC 42001.

Relevant areas include:

* organizational context;
* risk and opportunity management;
* operational planning;
* AI system lifecycle controls;
* performance evaluation;
* management review;
* continual improvement.

The actual conformity assessment must be performed against the applicable ISO/IEC 42001 requirements and the organization's implemented management system.

***

# 79. Relationship to NIST AI RMF

The example can also be mapped to the four NIST AI RMF Functions.

| NIST AI RMF Function | Example Activity                            |
| -------------------- | ------------------------------------------- |
| GOVERN               | Risk ownership, accountability and policies |
| MAP                  | Context, stakeholders, purpose and impacts  |
| MEASURE              | Risk analysis, testing and monitoring       |
| MANAGE               | Treatment, prioritization and response      |

***

# 80. Final Assessment Record

**AI System:** Candidate Assessment Assistant

**AI System ID:** `AI-HR-001`

**Classification:** High-Risk

**Assessment Type:** Initial AI Risk Assessment

**Assessment Status:** Conditionally Approved

**Overall Inherent Risk:** High / Critical

**Overall Residual Risk:** Medium / High

**Human Oversight:** Mandatory

**Monitoring:** Enhanced

**Assurance:** Required

**Next Review:** Quarterly or upon material trigger

***

# 81. Document Status

**Document:** AIGO — AI Risk Assessment Example

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-EXAMPLE-003`

**Document Type:** Implementation Example

**Example Type:** AI Risk Assessment

This document provides an illustrative example of how AI risk assessment can be performed and governed within the AIGO Framework.

***

# 82. End of Example Document

**AIGO — AI Risk Assessment Example**

**Document ID:** `AIGO-EXAMPLE-003`

**Version:** 0.1

**Status:** Draft

**End of Document**
