This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If a business has already decided that an AI tool is worth assessing, the next question is not whether AI is generally risky. It is which dimensions matter for this use, what evidence answers each one, and which parts of the conclusion come from an authority rather than internal judgement. This method provides that separation.
In short: A useful AI risk assessment records the proposed use, affected people, data, possible harm, controls, evidence and residual risk. Every finding is labelled as an applicable authority requirement, voluntary framework guidance or operational judgement. That label matters because a sensible internal precaution is not automatically a legal duty.
The assessment record and its three evidence labels
A repeatable assessment starts with one defined use, not a product name in isolation. An AI assistant that drafts internal meeting summaries presents a different risk from the same technology ranking job applicants or recommending credit decisions.
The record uses three evidence labels:
- Authority: A law, regulator or government body addresses the issue. Applicability still depends on jurisdiction, sector, data and use.
- Framework: A named voluntary framework includes the issue, but the framework does not itself create a legal obligation.
- Judgement: The dimension or threshold reflects the organisation's operating context and risk tolerance. It carries no citation because NTKAI is identifying an operational decision, not attributing a rule.
The NIST AI Risk Management Framework provides a useful process backbone. Its Core organises work into Govern, Map, Measure and Manage, while NIST describes the framework as voluntary. The NIST Core also says its actions are not a checklist or necessarily an ordered sequence.
A compact assessment record contains these fields:
| Field | What it records |
|---|---|
| Proposed use | The task, users, inputs, outputs and decision influenced |
| Affected parties | Staff, customers, applicants, suppliers or members of the public |
| Risk dimension | The particular source of uncertainty or possible harm |
| Evidence label | Authority, Framework or Judgement |
| Evidence | Contract term, regulator source, test result or documented assumption |
| Initial risk | Likelihood and consequence before controls |
| Existing control | Human review, access restriction, testing or another safeguard |
| Residual risk | Risk remaining after the stated control |
| Owner and review trigger | Who owns the record and what change causes reassessment |
| Outcome | Accept, conditionally test, defer or reject, with reasons |
The dimensions and what each one rests on
The dimensions are not equivalent. Some reflect legal or regulatory concerns in particular settings, some come from voluntary frameworks, and some remain business judgement even when a framework helps organise the question.
| Dimension | Question recorded | What the dimension rests on |
|---|---|---|
| Purpose and impact | What task is performed, who is affected and what happens if the output is wrong? | Framework plus Judgement. NIST's Map function addresses context and impacts. The organisation decides whether the proposed consequence is tolerable. |
| Privacy and data | What information enters the system, where does it go, who can access it and how long is it retained? | Authority where privacy law applies; otherwise Framework and Judgement. The applicable privacy authority determines the legal basis. Data sensitivity and acceptable exposure still require contextual judgement. |
| Security and resilience | How could accounts, prompts, outputs, integrations or availability be compromised? | Framework, sometimes Authority, plus Judgement. NIST includes security and resilience among trustworthy AI characteristics. The EU AI Act addresses cybersecurity and robustness for systems within its high-risk regime. The exact control set depends on the use and technical environment. |
| Accuracy and reliability | How often is the output wrong, inconsistent or outside its intended scope, and what is the consequence? | Framework, sometimes Authority, plus Judgement. NIST treats validity and reliability as trustworthiness characteristics. EU AI Act Article 15 addresses accuracy for high-risk systems. The acceptance threshold is operational unless an applicable rule or professional standard sets it. |
| Fairness and bias | Could performance or outcomes differ materially between affected groups? | Framework and potentially Authority. NIST includes fairness with harmful bias managed. In the United States, the FTC and other federal agencies have stated that their existing enforcement authorities extend to harmful automated systems, including discriminatory outcomes. See the agencies' joint statement. Test design and tolerance remain context-specific. |
| Transparency and explainability | Can affected people and reviewers understand the AI's role, limits and basis well enough for the use? | Framework, sometimes Authority, plus Judgement. NIST includes accountability, transparency, explainability and interpretability. Particular disclosure or explanation rules depend on jurisdiction and use. |
| Human oversight and accountability | Who can review, override or stop the system, and who owns the resulting decision? | Framework, sometimes Authority, plus Judgement. EU AI Act Article 14 addresses human oversight for high-risk systems. NIST treats governance as cross-cutting. Internal ownership and approval boundaries remain organisational decisions unless another rule specifies them. |
| Vendor and operational dependency | What happens if the vendor changes the model, terms, integration, location or service availability? | Framework plus Judgement. NIST Map 4.1 addresses risks from third-party data and software. Acceptable lock-in, outage exposure and switching effort are commercial and operational judgements. |
Assessment effort is sized by consequence, not by the AI label
NTKAI's three-level triage is an editorial method, not a regulatory classification. It uses potential consequence, affected people, data sensitivity, autonomy and reversibility to decide how much evidence an assessment warrants.
| Assessment level | Typical profile | Proportionate evidence |
|---|---|---|
| Light | Internal drafting, no sensitive or confidential data, reversible output, human review before use | Defined use, basic data-flow check, vendor terms, named owner and a short output sample |
| Standard | Customer or employee data, recurring external output, integration with business systems, or moderate reliance | Light assessment plus vendor security evidence, representative testing, failure handling and documented approval conditions |
| Enhanced | Safety implications, significant decisions about people, highly sensitive data, substantial autonomy, or outcomes that are hard to reverse | Standard assessment plus specialist privacy, security, legal or domain review as relevant, formal test criteria and documented escalation |
A low-risk label does not mean risk-free. It means the initial facts support a lighter evidence burden. A change in data, users, autonomy, integration or consequence can move the same tool into a deeper assessment.
What a completed assessment looks like
Consider an illustrative AI feature that classifies incoming customer emails and drafts replies. A staff member reviews every reply before sending it.
| Record item | Example completion |
|---|---|
| Use | Categorise support email and prepare a draft response |
| People and data | Customers; names, contact details and message contents |
| Privacy | Authority depends on the applicable privacy regime. Vendor data flows and retention remain unconfirmed until documentary review |
| Security | Access controls and integration permissions require vendor evidence |
| Accuracy | Misclassification and invented details are tested against representative messages |
| Fairness | Language and communication-style differences are included in testing |
| Accountability | The service manager owns the workflow; the staff sender owns the final message |
| Initial risk | Moderate, because output reaches customers and may contain personal information |
| Controls | Restricted input, human approval, escalation for sensitive topics and logged errors |
| Residual risk | Moderate-low if the controls work as tested; unresolved if vendor data handling remains unclear |
| Outcome | Conditional pilot. Full deployment remains deferred until the evidence gaps are resolved |
The outcome is operational judgement, not a regulator's conclusion. The value of the record is its traceability: another reviewer can see which facts, sources, tests and assumptions produced the decision.
How jurisdiction changes the authority label
The neutral method works across regions, but the Authority label cannot be copied from one jurisdiction to another.
European Union
For systems within the EU AI Act's high-risk categories, Articles 9, 10, 14 and 15 address risk management, data governance, human oversight, accuracy, robustness and cybersecurity. The Act's classification and allocation of duties are use-specific, so the regulation itself and current European Commission guidance require review before marking a row as an applicable requirement. Read the official AI Act text.
United Kingdom
The ICO's AI and data protection risk toolkit covers accountability, transparency, accuracy, fairness, security, data minimisation and individual rights. The ICO currently marks this guidance as under review following changes from the Data (Use and Access) Act, so its status requires rechecking before publication or reuse.
United States
The NIST AI RMF is voluntary and does not decide legal applicability. The FTC and partner agencies have stated that existing consumer-protection, competition, civil-rights and equal-opportunity authorities can apply to automated systems. Which authority matters depends on the use, sector and affected people, not simply on the presence of AI.
Canada
The Office of the Privacy Commissioner lists accountability, consent, limiting collection, accuracy and safeguards among PIPEDA's fair information principles. Coverage varies, including where provincial private-sector laws apply. Check the OPC's current PIPEDA overview and coverage tool.
Canada's Algorithmic Impact Assessment is a mandatory tool supporting the federal government's Directive on Automated Decision-Making. It is designed for federal departments, so it is not evidence that every Canadian private business has the same assessment duty.
Australia
The OAIC's guidance for commercially available AI products addresses product suitability, personal-information flows, privacy impact assessment, human oversight, security and ongoing review for organisations within its stated scope. The same source distinguishes legal obligations from recommendations and best practice, which makes item-level evidence labels especially important.
Readiness and industry risk stay outside this artefact
Organisational readiness asks whether a business has the skills, ownership, policy, training and change capacity to adopt AI. That is an implementation assessment, not a risk assessment of one specified use, so it is deliberately excluded here.
Industry context changes evidence and consequence, but this page does not contain separate industry checklists. A healthcare, recruitment or financial-services use may trigger different rules and professional review. Those differences belong in the relevant industry or jurisdiction guidance rather than being presented as universal dimensions.
Where the published guidance stops
No source above sets a universal risk score, universal approval threshold or single assessment process for every SMB use of AI. NIST is voluntary, privacy rules depend on coverage and processing, and the EU AI Act assigns duties according to classification and role.
Questions about whether a law applies, whether an AI system falls into a regulated category, or whether residual risk is legally acceptable require the relevant authority or a qualified adviser. NTKAI's method only keeps the evidence, judgement and unresolved questions visibly separate.
Questions for the assessment record
- What precise task and decision does the AI influence?
- Which people could experience a harmful or unfair outcome?
- Which data enters the system, which parties receive it, and what evidence confirms that flow?
- Which findings come from an applicable authority, which come from a voluntary framework, and which are internal judgement?
- What test would reveal failure before it causes material harm?
- Who can override the output, and who owns the final decision?
- Which unresolved fact would change the assessment outcome?
- What product, data or workflow change triggers reassessment?
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: free AI acceptable use policy template, free AI register template, shadow AI audit checklist, AI data residency comparison, AI vendor breach response plan template, guide to liability for AI-generated content, and AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Is an AI risk assessment the same as a data protection impact assessment?
No. An AI risk assessment can cover privacy, security, accuracy, bias, oversight and operational dependency. A data protection impact assessment has a narrower privacy purpose and may carry a specific legal status under an applicable data-protection regime.
Does every AI tool require the same assessment depth?
No. NTKAI's method scales effort according to potential consequence, affected people, data sensitivity, autonomy and reversibility. These are operational triage factors, not universal legal thresholds.
Can a vendor's security certification complete the assessment?
No. A certification may support the security dimension, but it does not answer whether the intended use is accurate, fair, lawful, explainable or operationally acceptable. Its scope, date and covered service also require confirmation.
Who approves the residual risk?
That is generally a governance decision for the organisation unless an applicable law, regulator or professional rule assigns a particular responsibility. The assessment record identifies the owner and preserves the evidence behind the decision without treating the owner's judgement as an external requirement.
Methodology and source status
This desk-research assessment reviewed primary material from NIST, EUR-Lex, the European Commission, the UK ICO, the US FTC, Canada's privacy regulator and federal government, and Australia's privacy regulator. Sources were checked on 4 September 2026. NIST states that AI RMF 1.0 is being revised, and the ICO marks its AI data-protection guidance as under review, so both require monitoring.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
For the next stage, use the AI Vendor Due Diligence Checklist to organise the documentary questions raised by an assessment.
AI Vendor Due Diligence Checklist