Rate each dimension, then make the reversibility of the outcome explicit. The result identifies the control level and why it landed there — like insurance underwriting: the more severe and harder to undo the potential outcome, the tighter the required controls, regardless of how good the AI seems.
Example: an AI drafting an internal meeting summary is low severity and easily undone — a light touch is fine. The same AI auto-approving a part for shipment to a customer is high severity and hard to reverse once it's out the door — that needs the strictest control level, even if the AI is equally accurate in both cases. The control level below tracks the consequence of being wrong, not just how often the AI is right.
GOVERNANCE SCORECARD
Independent of the control level above: do the underlying practices exist yet?
A use case can land at control level A and still have no named accountable owner; a level C use case can already have every practice below in place. This scores the organisational practices a controlled deployment depends on, separately from how much control this specific use case needs.
WHY THIS INSTRUMENT EXISTS
Two use cases built on the same technology can carry entirely different consequences: a drafting aid and a tool that influences product release are not the same risk, even if both are called "AI". Applying one governance process to both either over-controls the harmless case or under-controls the consequential one.
Scoring consequence severity, reversibility, autonomy, scale, evidence quality, novelty, oversight and regulatory exposure — with an irreversibility gate that overrides a merely-average total — sets the control level from the specific use case instead of from the technology label attached to it.