How to conduct an AI risk assessment: step by step
An AI risk assessment is only useful if it's done consistently. This guide walks the process end to end — scoping, identifying and scoring risks, defining controls, and making a documented decision. Part of our guide to the AI risk assessment.
AramGRC Team·AI Risk & Assurance·September 11, 2026·9 min read
Before you start
Decide the scope (which system, and where it sits in a decision) and who's involved — the system owner, plus risk, data and, for higher-risk systems, legal and a human-oversight owner. A risk assessment done by one person in isolation misses the cross-functional risks that matter most.
The AI risk assessment process
Scope the system — what it does, what data it uses, who it affects, and where it sits in a decision.
Identify risks — work through each dimension (purpose and impact, data, bias and fairness, transparency, robustness and security, human oversight, regulatory exposure) and list the specific ways this system could cause harm.
Score likelihood and impact — rate each risk to produce a prioritised view; this is where a template does the work.
Define controls — for each significant risk, specify the mitigation: a bias test, a human-in-the-loop step, a monitoring alert, a data fix.
Assign owners and decide — give each control an owner and make a documented go / no-go / conditional-go decision.
Monitor and review — re-assess on a schedule and whenever the system or its context changes.
The questions to ask
Good assessments are driven by sharp questions: What decision does this system make, and what happens if it's wrong? Whose data trained it, and do we have a lawful basis? Have we tested for bias across the groups it affects? Can we explain a given output? Who can override it? Where does it sit against the EU AI Act and ISO 42001? Turn these into a standard questionnaire so every system is assessed the same way.
How to score AI risk
Score each risk on likelihood and impact — a simple 1–5 scale on each, multiplied for an overall rating, works well. The rating determines how much control and oversight the system needs, and whether it can go live, needs conditions, or must be stopped.
From assessment to decision and register
The output is a risk register — each risk with its score, control, owner and status — and a documented decision. That register is both your action plan and the audit evidence the EU AI Act and ISO 42001 expect. A template makes it repeatable.
Common mistakes
The usual failures: assessing only technical risk and missing impact on people; scoring once and never revisiting; no owner for the controls; and no evidence trail. Avoid them and the assessment becomes a real control, not a formality.
How AramGRC helps
AramGRC runs independent AI risk assessments — a scored risk register and a prioritised mitigation plan mapped to ISO/IEC 42001 and the EU AI Act — for every system in scope.
Frequently asked questions
How do you conduct an AI risk assessment?+
Scope the system, identify risks across the key dimensions, score each for likelihood and impact, define controls with owners, make a documented go/no-go decision, and monitor and re-assess.
What questions should an AI risk assessment ask?+
What the system decides and the cost of error, the data's lawful basis, bias across affected groups, explainability, who can override it, and where it sits against the EU AI Act and ISO 42001.
How do you score AI risk?+
Rate each risk on likelihood and impact (e.g. 1–5 each) and combine them into an overall rating that determines the controls and oversight the system needs.
When should you conduct an AI risk assessment?+
Before a system is deployed, and again whenever the system or its context changes materially.