AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
5 to work through
-
advanced
An enterprise AI provider must apply governance proportionate to risk across many model deployments. How should tiering work?
2 min answer -
advanced
An organisation deploys many AI systems with very different risk profiles. How should they be tiered, and which controls attach to each tier?
2 min answer -
advanced
How should AI systems be risk-tiered so that governance is proportionate?
1 min answer -
advanced
The business wants to deploy a model that ranks loan applications, with a credit officer making the final decision. What must the architecture provide, and what will you insist on before go-live?
2 min answer -
advanced
Your company is deploying twelve AI features. Compliance wants one governance process for all of them. What do you propose?
2 min answer
3 terms in this topic
AI Risk Tiering
Classifying AI systems by potential harm so that governance effort is proportionate, rather than applying the same controls to every use.
practiceConsequence-Based Tiering
Assigning governance requirements according to the consequence of a system being wrong and who bears it, rather than by technology - so that the stri…
practiceUse Case Risk Classification
Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply.
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.