How to Run a Lightweight AI Risk Assessment

A practical, proportionate way to assess AI risk: list your uses, ask five questions of each, rate by likelihood and consequence, and act, without a heavy framework.

You do not need a risk department to assess AI risk. For most businesses a lightweight assessment, a couple of hours per use, is enough to spot what could go wrong and decide what to do about it. The point is to be deliberate, not exhaustive.

Here is a practical way to do it.

Start with a list of uses

You cannot assess what you have not written down. List where AI actually touches the business, including the informal staff use through free tools, not just the sanctioned projects. That register is the foundation, and building it usually surfaces a few surprises.

Ask five questions of each use

For each AI use, work through five plain questions.

What data goes in? If it is personal, customer or commercially sensitive data, the risk rises and UK GDPR is in play.

What decision comes out, and who is affected? Output that informs a decision about a person, in hiring, credit or service, carries far more risk than an internal draft.

What happens if it is wrong? Some errors cost a few minutes; some cost a customer, a fine or a safety issue. Rate the consequence honestly.

Would we know if it was wrong? An error you cannot detect is worse than one you can. Consider whether there is a human check or a way to catch mistakes.

Could we explain it? If a customer or regulator asked why the AI produced an outcome, could you answer? For higher-stakes uses, you need to.

Rate, then act

Score each use by how likely a problem is and how bad it would be. That sorts them quickly: most everyday uses are low risk and need only the basic boundary; a few are higher and need controls, a human check, tighter data handling, or specialist input; and the occasional one is not worth the risk yet and should wait. The output is a short, ranked list with an action against each, not a document.

Keep it proportionate and current

The assessment should match the size of the risk, light for a drafting tool, more careful for anything touching decisions about people or money. And revisit it, because tools and uses change. A quick refresh each quarter keeps it honest without becoming a burden.

Where this sits

A risk assessment is one part of good AI governance, alongside the register, the acceptable use policy and a named owner. Together they give you a position you can defend when the question lands in a procurement pack or a due diligence request.

Where ScaleAround fits

Our free AI Governance Starter Kit includes the register and templates to run a lightweight assessment yourself, and our AI governance advisory helps with higher-risk uses or regulated settings.

Our founder, Oliver Smith, established and ran an AI and machine learning function in regulated financial services and facilitates sessions at the CDO Financial Services Exchange on the data challenges specific to machine learning. He is a Fellow of the British Computer Society. Our engagements are led by senior practitioners with at least 15 years of relevant experience.

Frequently asked questions

How do I assess AI risk? List your AI uses, then ask five questions of each: what data goes in, what decision comes out and who it affects, what happens if it is wrong, whether you would know, and whether you could explain it. Rate and act.

Do I need a formal risk framework? Not for most SMEs. A lightweight, proportionate assessment of a couple of hours per use is enough to be deliberate.

Which uses are highest risk? Those handling sensitive data or feeding decisions about people or money, especially where an error would be hard to detect or explain.

How often should we redo it? A quick refresh each quarter, because tools and uses change.

How does this fit with governance? It is one part, alongside a register, an acceptable use policy and a named owner, that together give you a defensible position.


Want to assess your AI risk without a heavy process? The free AI Governance Starter Kit gives you the tools, and our AI governance advisory covers the higher-risk cases. Book a 30-minute scoping call to talk it through.