How to Carry Out a Business AI Risk Assessment
IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.
An AI risk assessment does not need to be a forty-page document. It needs to answer, in writing, what the AI will do, what information it touches, who could be affected, what happens when it is wrong, and who owns the decision. This guide sets out the IT Club nine-step method, sized for a small business.
The nine steps
- 1DEFINE THE USE — What task will AI perform? One assessment per use case, not per tool: “drafting marketing emails” and “summarising customer complaints” are different assessments even in the same product.
- 2IDENTIFY THE INFORMATION — What data enters and leaves? Classify it: public, internal, confidential, personal, special category. This single step decides most of the rest.
- 3IDENTIFY PEOPLE AFFECTED — Customers, staff, applicants, suppliers or the public. If real people are affected by errors, the bar rises.
- 4ASSESS CONSEQUENCES — What happens if the system is wrong, unavailable, biased or breached? Work through all four failure modes, not just accuracy.
- 5ASSESS THE SUPPLIER — Terms, security, data use and resilience, using the supplier-assessment guide in this hub.
- 6DEFINE CONTROLS — Human review points, access limits, anonymisation or placeholders, logging, and testing before launch.
- 7ASSIGN AN OWNER — Name the accountable role. A risk without an owner is a risk nobody is managing.
- 8APPROVE OR REJECT — Record the decision: approved, restricted, pilot or prohibited — with the reasons.
- 9MONITOR — Review incidents, changes and performance at a defined interval. Assessments age; uses drift.
The risk scale
| Level | Typical uses | What it demands |
|---|---|---|
| LOW | Formatting, brainstorming and non-sensitive internal assistance | Approved tool, basic rules, light review |
| MODERATE | Customer communications, analysis and business recommendations | Named owner, defined human review, source checking, records |
| HIGH | Personal data, automated decisions, regulated advice, safety, employment or significant financial consequences | Full assessment, strongest supplier scrutiny, qualified human review, DPIA where personal data is involved, senior sign-off |
The point of the exercise
The purpose of an AI risk assessment is not to stop every project. It is to match controls to consequences.
Keeping it proportionate
For a low-risk use, the assessment is a few lines in the tool register. For a moderate one, a page. Reserve the full treatment for high-risk uses — and for those, add the formal pieces: a data protection impact assessment where personal data and significant effects are involved, legal advice where regulated decisions are touched, and genuine testing before anything reaches a customer. The downloadable AI Risk Assessment Worksheet in this hub walks through all nine steps.
When to reassess
- The use case expands — a pilot becomes permanent, or a drafting tool starts touching customer data
- The supplier changes terms, models or subprocessors
- An incident or near-miss occurs
- New people or departments start using the tool
- At the defined review date, even if nothing appears to have changed
Plain-English Takeaway
Nine questions, answered in writing and owned by a named person, turn AI adoption from guesswork into a decision. Scale the effort to the risk level — a few lines for low-risk uses, the full method plus DPIA and advice for high-risk ones — and reassess when anything material changes.
Sources and further reading
- ICO — AI and data protection risk toolkit
- GOV.UK — Introduction to AI assurance
- NCSC — Guidelines for secure AI system development
External guidance changes. Check the source itself for the current position before acting on it.