AI Act • AI Governance • Risk Management

AI Risk Assessment Template

A practical AI risk assessment helps you decide whether an AI use case is safe, acceptable, transparent and properly controlled before launch.

Last updated4 May 2026
Update workflowWeekly monitoring, monthly edits
MethodOfficial sources + practical governance controls
Quick next step

Not sure where your AI use stands?

Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.

Template

AI Risk Assessment Template

Use this table before adopting or launching an AI system. Copy it into a spreadsheet and add evidence, owners, deadlines, and review dates.

AreaQuestionEvidence to collectOwner
PurposeWhat decision, recommendation, or output does the AI system support?Use-case description, user group, business ownerProduct / business owner
Risk classificationCould the system be prohibited, high-risk, transparency-risk, or minimal risk?AI Act mapping, use-case category, legal notesCompliance / legal
DataWhat data is used, and could it create privacy, security, or bias risk?Data inventory, DPIA notes, source documentationPrivacy / security
Human oversightWho can review, override, or stop the AI system?Escalation path, role descriptions, training recordsOperations / product
TransparencyDo users need to know they are interacting with AI or viewing AI-generated content?Notices, chatbot labels, content labelling designUX / legal
MonitoringHow will incidents, drift, misuse, and performance failures be tracked?Monitoring plan, incident process, audit logsEngineering / risk

When to run an AI risk assessment

Run an AI risk assessment before launching a new AI system, approving a new vendor, using AI in a sensitive workflow, changing the model or data, or expanding AI use to a new group of people. For high-impact areas such as employment, education, credit, essential services, biometric systems, and safety components, the assessment should be more formal and evidence-based.

Advertisement

The six-part assessment

  1. Use case: what the AI system does and who is affected.
  2. Risk category: whether the use case may be prohibited, high-risk, transparency-risk, GPAI-related, or lower risk.
  3. Data: data sources, personal data, quality, bias, confidentiality and security.
  4. Controls: human oversight, access controls, logging, user notices and testing.
  5. Impact: possible harm to individuals, customers, workers, the business, and society.
  6. Monitoring: post-launch review, incidents, complaints and model/vendor changes.

Scoring risk without false precision

Avoid pretending that AI risk can be reduced to a perfect score. Use simple levels: low, medium, high and critical. Explain why the level was chosen, what controls reduce risk, and what residual risk remains. The evidence and reasoning matter more than the number.

Advertisement

FAQ

Is an AI risk assessment the same as a DPIA?

No. A DPIA focuses on data protection risk. An AI risk assessment may include privacy but also covers safety, bias, transparency, human oversight, security and regulatory classification.

How often should assessments be reviewed?

Review before launch, after major changes, after incidents, and on a regular schedule for important systems.

Who should sign off?

At minimum the business owner, technical owner, privacy/security owner and compliance/legal reviewer where relevant.

Sources and review method

This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.

Reviewed byAI Compliance Checkup Editorial Team
Review methodOfficial AI Act, European Commission, EUR-Lex and NIST sources
Last reviewed4 May 2026
Contactcontact@aicompliancecheckup.com