TOPIC · RISK

AI risk management: a cycle that holds up

AI risk management is the cycle of identifying, assessing, treating and reviewing the risks of each AI use, with criteria defined in advance, controls proportional to impact, named owners and dated evidence. The cycle matters more than the form: risks that are assessed once and never revisited stop reflecting the use.

A simple cycle

The cycle matters more than the template.

  • Identify risks from the concrete use and the people affected.
  • Assess impact and likelihood with criteria defined before the urgent case.
  • Decide treatment: accept, reduce, transfer or do not allow the use.
  • Name an owner and a deadline for each control.
  • Record evidence and the decision that closed the cycle.
  • Reassess on a schedule and whenever something relevant changes.

Risks that are not only technical

Beyond model failure, the scope includes improper purpose, inadequate data handling, missing transparency, vendor dependency and impact on people. Technical and bias evaluations deepen that reading and depend on the data and access available.

Criteria before the rush

Defining decision criteria in advance is what prevents improvised calls when a new use needs to go live quickly.

Frequently asked questions

How do we assess the risk of an AI use?

Through purpose, data involved, people affected, degree of automation in the decision and reversibility of an error, with impact and likelihood criteria defined beforehand.

Who owns the risk?

The area that answers for the use, supported by governance, legal, security and technology. Every control needs a named owner and a review date.