Governance & Compliance
AI risk assessment
An AI risk assessment systematically evaluates an AI tool or use case before adoption — data flows, training terms, compliance scope, misuse potential — and documents the verdict.
An AI risk assessment examines a proposed tool or use case across the dimensions that later become incidents: what data flows in, where it goes, whether it trains models, which certifications apply at the tier in question, what misuse looks like, and which controls compensate. Privacy impact assessments and the EU AI Act's requirements formalize versions of it.
Two practices keep assessments honest: verify vendor claims against published terms rather than sales decks, and reassess on change — AI vendors revise data-handling terms often enough that an annual review misses the flip.
Where this shows up
Related terms
See it in your own organization.
Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.