AI, data and governance consulting
AI risk management
What can go wrong, with what consequence, and which control contains it. Including the limit of what a tool can support.
The risk is not the model
The risk sits in the decision the system touches, not in the technology that computes it. A model that suggests a sentence and one that sets a credit limit can use the same technique and have incomparable consequences.
That is why classification starts with the consequence: who it affects, how reversible it is, and whether there is a route to complain. How the system works comes after.
How it works
With a risk register per system, impact assessments where they are required, and escalation routes defined before they are needed. Aligned to ISO 31000 for the risk side and the EU AI Act for classification.
Every accepted risk is recorded as a decision, with whoever made it. Accepting a risk is legitimate; accepting it without a record is not.
The limit of the tool
Part of the work is determining what a system should not do. A vendor who draws the limit of their own tool is showing maturity; one who says it works for everything is transferring the risk to the buyer.
Frequent questions
- How do I know if a system is high risk?
- It depends on the decision it touches and the regulation that applies. The EU AI Act defines categories; the practical test is what happens to the affected person if the system is wrong, and whether they can contest it.
- Does it apply if we use third-party tools?
- Especially then. Risk is not outsourced along with the tool: whoever put it in a position to decide is who answers to the affected person.
- Is this the same as cybersecurity?
- No, and they complement each other. Security protects the system from an attacker; this deals with what the system does when it works exactly as designed.
- How often is it reviewed?
- When the system changes, when the rules change, or on a recurring basis if neither happens. A risk register without a review date stops being true on its own.