Free Excel triage
AI risk assessment template
Answer ten questions to place an AI system in a risk tier using signals from the EU AI Act, Colorado and New York City rules. The workbook calculates the example as HIGH and tells you what to do next.
Download the free triage (.xlsx)The five risk tiers
| Tier | What to do next |
|---|---|
| PROHIBITED? STOP | Pause the project and get legal advice before any further use. |
| HIGH | Full risk assessment, human oversight, bias testing, logging, documentation and a named approver before go-live. |
| MEDIUM | Risk assessment and a named owner; add controls for data, transparency and agent permissions. |
| LIMITED | Record it in your AI inventory and meet transparency duties. |
| MINIMAL | Record it in your AI inventory and review yearly. |
What a full AI risk assessment covers
- System identification: purpose, owner, users, vendors and deployment context.
- Data governance: sources, lawful use, quality, access and retention.
- Risk scoring: likelihood × severity on a 1–5 scale.
- Mitigation and residual risk: controls, evidence and risk remaining after treatment.
- Human oversight: named reviewers, authority and escalation.
- Monitoring and reassessment: metrics, incidents, material changes and review dates.
The Starter kit's AI-System-Risk-Assessment.xlsx covers all six.
Common questions
- How do you perform an AI risk assessment?
- Identify the system and owner, classify its use, data and affected people, score likely harms, document controls and residual risk, assign human oversight, approve the decision, and set a reassessment date.
- What are the 5 things a risk assessment should include?
- A practical assessment needs system context, hazards and affected people, likelihood and severity, controls and residual risk, and an accountable owner with a review date.
- Can AI write a risk assessment?
- AI can help draft questions and summarize evidence, but it should not approve its own risk. A named person must verify the facts, judge the consequences, and own the decision.