AI risk assessment
Structured, deterministic AI risk assessment
Consistent criteria, versioned rules, mandatory floors and a readable explanation trace — so two assessors reach the same outcome and the reasoning survives scrutiny months later.
Why spreadsheet scoring fails
Free-text risk workshops produce a number nobody can reproduce. The criteria drift between assessors, the weighting is invisible, the rationale lives in a document that is edited after the fact, and there is no way to re-run last quarter's assessment under the rules that actually applied at the time.
AIRAS Cloud replaces that with a rulebook: risk dimensions, indicators and thresholds are approved by named humans, published as a version, and applied identically to every assessment made while that version is in force.
How an assessment is calculated
Guided intake captures context — purpose, population affected, data categories, autonomy, oversight, supplier position and deployment environment. The engine then scores each dimension, applies mandatory floors, runs prohibited-use checks and produces a band with the reason it was reached.
- Inherent risk across weighted dimensions
- Mandatory floors that cannot be scored away
- Prohibited-use screening at intake
- Evidence and control confidence adjustment
- Residual position after assessed controls
- Explanation trace in plain language
- Immutable snapshot of inputs and ruleset version
- Automatic routing to the correct review path
Reproducible by design
Every result stores the inputs, the ruleset version and the rule trace as an immutable record. Re-running a historic assessment returns the identical score and identical explanation. Risk criteria can still evolve — new versions are published under governed change control without invalidating decisions already made.
Assessment feeds the rest of the lifecycle
The assessed context determines which controls apply, which reviewers must be involved, what evidence is required, how often the record must be reassessed and what constitutes a material change requiring a fresh decision.
Risk dimensions
Ruleset v2.4 · approved- Impact on people4 / 5
- Data sensitivity4 / 5
- Autonomy of action3 / 5
- Regulatory exposure5 / 5
- Operational criticality3 / 5
- Vendor dependency2 / 5
Calculated outcome
Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.
Explanation trace
- Special category data declared in intake → sensitivity floor applied
- GxP-impacting process confirmed → Quality review mandatory
- Operational write-back enabled → Security review mandatory
- No prohibited-use pattern matched
Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.
Rules are versioned and human-approved. AI does not approve AI.
Illustrative interface – synthetic data
Illustrative public methodology using synthetic data. Production rulesets, weightings and thresholds are configured per tenant and are not published.
See deterministic assessment against your own use cases
Bring two or three real AI use cases to an executive briefing and we will walk them through intake, scoring, controls and the decision record.
No pricing commitment. No confidential information required.