Start with the use case
Risk depends on how AI is used. A low-impact drafting assistant should not be evaluated the same way as an AI system influencing employment, financial, healthcare, safety, or other consequential decisions.
Evaluate data, model, and vendor risk
Assessments should consider data sensitivity, training and inference data, privacy, security, vendor dependency, model behavior, reliability, transparency, and operational integration.
Evaluate human oversight
The degree of automation matters. High-impact decisions may require stronger human review, approval, monitoring, escalation, and auditability.
Turn risk into controls
The output should connect identified risks to specific controls, ownership, evidence, remediation, and continuous monitoring requirements.