AI GovernanceRisk

How to Carry Out a Business AI Risk Assessment

9 minutes to readLast checked: 4 August 2026

IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.

An AI risk assessment does not need to be a forty-page document. It needs to answer, in writing, what the AI will do, what information it touches, who could be affected, what happens when it is wrong, and who owns the decision. This guide sets out the IT Club nine-step method, sized for a small business.

The nine steps

  1. 1DEFINE THE USE — What task will AI perform? One assessment per use case, not per tool: “drafting marketing emails” and “summarising customer complaints” are different assessments even in the same product.
  2. 2IDENTIFY THE INFORMATION — What data enters and leaves? Classify it: public, internal, confidential, personal, special category. This single step decides most of the rest.
  3. 3IDENTIFY PEOPLE AFFECTED — Customers, staff, applicants, suppliers or the public. If real people are affected by errors, the bar rises.
  4. 4ASSESS CONSEQUENCES — What happens if the system is wrong, unavailable, biased or breached? Work through all four failure modes, not just accuracy.
  5. 5ASSESS THE SUPPLIER — Terms, security, data use and resilience, using the supplier-assessment guide in this hub.
  6. 6DEFINE CONTROLS — Human review points, access limits, anonymisation or placeholders, logging, and testing before launch.
  7. 7ASSIGN AN OWNER — Name the accountable role. A risk without an owner is a risk nobody is managing.
  8. 8APPROVE OR REJECT — Record the decision: approved, restricted, pilot or prohibited — with the reasons.
  9. 9MONITOR — Review incidents, changes and performance at a defined interval. Assessments age; uses drift.

The risk scale

LevelTypical usesWhat it demands
LOWFormatting, brainstorming and non-sensitive internal assistanceApproved tool, basic rules, light review
MODERATECustomer communications, analysis and business recommendationsNamed owner, defined human review, source checking, records
HIGHPersonal data, automated decisions, regulated advice, safety, employment or significant financial consequencesFull assessment, strongest supplier scrutiny, qualified human review, DPIA where personal data is involved, senior sign-off

The point of the exercise

The purpose of an AI risk assessment is not to stop every project. It is to match controls to consequences.

Keeping it proportionate

For a low-risk use, the assessment is a few lines in the tool register. For a moderate one, a page. Reserve the full treatment for high-risk uses — and for those, add the formal pieces: a data protection impact assessment where personal data and significant effects are involved, legal advice where regulated decisions are touched, and genuine testing before anything reaches a customer. The downloadable AI Risk Assessment Worksheet in this hub walks through all nine steps.

When to reassess

  • The use case expands — a pilot becomes permanent, or a drafting tool starts touching customer data
  • The supplier changes terms, models or subprocessors
  • An incident or near-miss occurs
  • New people or departments start using the tool
  • At the defined review date, even if nothing appears to have changed

Plain-English Takeaway

Nine questions, answered in writing and owned by a named person, turn AI adoption from guesswork into a decision. Scale the effort to the risk level — a few lines for low-risk uses, the full method plus DPIA and advice for high-risk ones — and reassess when anything material changes.

Sources and further reading

External guidance changes. Check the source itself for the current position before acting on it.

Unsure whether your business is using AI safely?

Ask the IT Club Advisor about AI tools, data handling, staff use, supplier checks, prompting or human review.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.

IT Club cannot provide legal advice. Questions requiring legal interpretation may be redirected to an appropriate qualified adviser.