INSTRUMENT 04 · RISK CLASSIFIER

How much control does this use case need?

Rate each dimension, then make the reversibility of the outcome explicit. The result identifies the control level and why it landed there — like insurance underwriting: the more severe and harder to undo the potential outcome, the tighter the required controls, regardless of how good the AI seems.

Example: an AI drafting an internal meeting summary is low severity and easily undone — a light touch is fine. The same AI auto-approving a part for shipment to a customer is high severity and hard to reverse once it's out the door — that needs the strictest control level, even if the AI is equally accurate in both cases. The control level below tracks the consequence of being wrong, not just how often the AI is right.

CONTROL LEVEL

A

DRIVER

All assessed dimensions are low and the action is reversible.

MINIMUM CONTROL SET

  • Define intended use and named process owner
  • Keep output advisory
  • Review data-use boundary

Use-drift watch: Confirm that the output still goes only to: Quality-team review workspace. Reassess whether it now influences a higher-consequence decision.

GOVERNANCE SCORECARD

Independent of the control level above: do the underlying practices exist yet?

A use case can land at control level A and still have no named accountable owner; a level C use case can already have every practice below in place. This scores the organisational practices a controlled deployment depends on, separately from how much control this specific use case needs.

POSTURE

50%

Developing — some of the practices exist; the gaps below are where to invest next.

WHY THIS INSTRUMENT EXISTS

Two use cases built on the same technology can carry entirely different consequences: a drafting aid and a tool that influences product release are not the same risk, even if both are called "AI". Applying one governance process to both either over-controls the harmless case or under-controls the consequential one.

Scoring consequence severity, reversibility, autonomy, scale, evidence quality, novelty, oversight and regulatory exposure — with an irreversibility gate that overrides a merely-average total — sets the control level from the specific use case instead of from the technology label attached to it.