AI Risk Assessment

Know which of your AI systems carry real risk before a regulator, customer or incident tells you. Our AI risk assessment classifies each system under the EU AI Act, finds the gaps and gives you a remediation plan your team can act on.

What it is

What an AI risk assessment covers

An AI risk assessment looks at one AI system at a time and asks five questions. What is it used for? Which data does it process? Who is affected by its output? What can go wrong, and how badly? Which controls are already in place?

The answers give each system a risk level and a list of required measures. For most companies the first surprise is the number of systems in scope. Next to the models you built yourself, the inventory usually includes AI features in CRM, HR and accounting software, plus tools such as ChatGPT or Copilot used by employees.

01

AI risk assessment framework

We score every system on two axes: likelihood and impact. Likelihood depends on data quality, model behaviour and how much people rely on the output without checking it. Impact depends on who is affected and how: a wrong product recommendation is not the same as a wrong credit decision.

On top of that we map each system to the EU AI Act categories: prohibited, high-risk, limited risk with transparency duties, or minimal risk. The framework also aligns with ISO/IEC 42001 and the NIST AI Risk Management Framework, so the results can feed an existing risk register.

02

What you receive

  • A complete inventory of AI systems in use, including third-party tools.
  • An EU AI Act classification for each system, with the reasoning written down.
  • A risk score and the main risks for each system.
  • A gap list: documentation, human oversight, logging, data governance, transparency.
  • A remediation plan ranked by risk and effort, with owners.
FAQ

Frequently asked questions

  • What is an AI risk assessment?

    A review of an AI system's purpose, data, users and possible harms, ending with a risk level and the controls it needs.

  • How often should we assess AI risk?

    Before launch, after major changes and at least once a year for systems in use.

  • Is the template enough for EU AI Act compliance?

    It is a good start for inventory and classification. High-risk systems need a full conformity process.

Know which AI systems carry real risk

We inventory your AI systems, classify each one under the EU AI Act and give you a remediation plan ranked by risk and effort.