Glossary
AI Risk Assessment
The structured evaluation of an AI system's risks across its intended purpose, data, decision authority and potential to cause harm, producing a documented basis for the controls that follow.
Term: AI Risk Assessment
An AI risk assessment is the structured evaluation of an AI system’s risks across its intended purpose, data, decision authority and potential to cause harm. It produces a documented basis for the controls that follow. It is the input to EU AI Act high-risk scoping and to ISO 42001 readiness.
Why it matters
Without a completed assessment, an organisation cannot say which of its AI systems carry material risk, nor justify the controls it applies to them. For UK boards and CISOs, this is the evidence that shows a system was evaluated before it went live, not after a problem surfaced. It is also the foundation of EU AI Act obligations: the classifications, controls and conformity evidence built on top of it inherit any error made at this stage. Assess the risk badly and everything downstream is wrong.
How it works in practice
We inventory the AI systems in use, characterise each one’s purpose and data, then rate the likelihood and severity of harm. The output feeds directly into EU AI Act classification and control selection, and into the management system controls that ISO 42001 expects. Our AI Security Gap Analysis service runs this assessment and maps the result to the work that follows, and our AI Act Preparedness service takes it through to a defensible compliance position.
Want this in context?
See how this term fits into the broader programme of work.