AI risk assessment template. Take one system from inventory row to signed treatment plan.

Pick the AI system that is next in line for a go-live decision, open the workbook, and work through the eight steps below in the order the sheets run. Plan on 1 to 2 weeks for one system, and 4 to 6 weeks to work through a portfolio of 10 to 20.

When you finish you hold an inventory entry with a threshold decision, a risk register scored for the organisation and for the people the system affects, an impact assessment, a controls map with evidence, and a review log entry your approving officer has signed.

Step 01 路 Instructions

Name the people and read the scales.

Open the Instructions sheet first. It holds the likelihood scale, the consequence scale, the tier bands and the matrix you score against in step 5.

Blue text marks the cells you fill in. Grey rows are worked examples, a claims triage model (AI-001) and an internal meeting summariser (AI-002), and this page uses them as its worked examples.

Name two people before anything is scored: an assessing officer who does the work, and an approving officer who signs the decision in step 8.

Book a workshop with the business owner, the data team, privacy, legal and risk. In the New Zealand Algorithm Impact Assessment, the business owner's team runs the threshold screen and someone in a risk, privacy or legal role reviews the final report.

OUTPUT 路 Assessing officer, approving officer, workshop list

ASIC asks licensees whether staff from multiple disciplines, beyond the technical experts, are involved in assessing AI risk.

Step 02 路 AI inventory, columns A to M

Enter the system in the inventory.

Give the system one row. Write its purpose in one plain sentence, then pick the lifecycle stage and how it was sourced.

The model provider, the hosting provider and any fine-tuning or integration vendor each get their own column, because step 4 needs their names to write the supply-chain risks.

Three flags finish the row: personal information used, sensitive information used, and the automated decision flag. The decision flag takes None, Substantially related step (the program does a step and a person decides) or Sole automated decision.

Worked example 路 AI-001

The claims triage model scores incoming claims for straight-through processing or human review. It is a third-party model in production, supplied by Example Vendor Pty Ltd and hosted by Example Cloud in ap-southeast-2, with no fine-tuning vendor. It uses personal and health information. A person still decides each claim, so the flag is Substantially related step.

OUTPUT 路 Inventory row with supply chain, data flags and decision flag

APRA treats an inventory of AI tooling and use cases as a minimum expectation and expects regulated entities to map the full AI supply chain, fourth parties included.

Step 03 路 AI inventory, columns N to P

Run the threshold screen.

Column N asks whether the system will have a material impact on people. Material means a real and potentially negative effect on someone's rights, opportunities or access to critical services, such as eligibility for welfare, health, housing or education.

Answer Yes, No or Unsure. Column P reads your answer and marks a full assessment as required for Yes and for Unsure.

Column O holds the reasoning: the nature of the impact, who is affected, how long it lasts, how severe it is and how likely. Make the call with privacy, legal and risk in the room.

Worked example 路 AI-001 and AI-002

The claims triage model is a Yes. It affects how fast each claim is handled and what happens to it, for individual policyholders, on an ongoing basis, and the effect can be adverse.

The meeting summariser screens out, since it is internal and makes no decisions about individuals. It leaves the process here, and the review log records the screen and its outcome.

OUTPUT 路 Threshold decision with written reasons

The Unsure rule matches the New Zealand Algorithm Impact Assessment, where a yes or an unsure to any threshold question sends the system to the full questionnaire.

Step 04 路 Risk register, columns A to E

Write down what can go wrong.

The risk register is the first of the two registers. It records risk to the organisation on the structure of ISO/IEC 23894, which extends the ISO 31000 process your risk team already runs.

Write one risk per row against the system ID, and choose its category from the drop-down. The reference table at the end of this page lists the ten categories.

Describe the risk in one sentence an auditor can test, naming the outcome, the people it lands on and the cause.

Column E takes a source from the seven ISO/IEC 23894 Annex B themes, such as level of automation or system life cycle. The source points at the fix. Opacity is treated with explanation and disclosure, and a life cycle risk with change control.

Worked example 路 R-001 and R-002

R-001, bias, fairness and discrimination. The model declines or delays claims at a higher rate for a demographic group because the training data under-represents them. Source: machine learning.

R-002, third party and supply chain. The model provider changes the model version without notice and output behaviour shifts. Source: system life cycle.

OUTPUT 路 Risk rows with category, description and source

ASIC found licensees that did not consistently identify AI-specific risks such as algorithmic bias.

Step 05 路 Risk register, columns F to M

Score likelihood once and consequence twice.

Likelihood runs from 1 Rare to 5 Almost certain. Score it once per risk.

Consequence runs from 1 Insignificant to 5 Severe, and you score it in two columns. Column G scores the consequence for the organisation, and column H the consequence for the consumer or community, such as denied access, delay, discrimination or loss of privacy.

The workbook takes the higher of the two, multiplies it by likelihood, and sets the tier.

The scale is ours, because no Australian or New Zealand framework prescribes one. Its consequence endpoints match the descriptors in the Commonwealth AI impact assessment tool, so the tiers line up with that tool's escalation rule.

Likelihood \ Consequence 1 Insignificant 2 Minor 3 Moderate 4 Major 5 Severe
5 Almost certain5 Medium10 High15 High20 Critical25 Critical
4 Likely4 Low8 Medium12 High16 Critical20 Critical
3 Possible3 Low6 Medium9 Medium12 High15 High
2 Unlikely2 Low4 Low6 Medium8 Medium10 High
1 Rare1 Low2 Low3 Low4 Low5 Medium

Tiers: 1 to 4 Low, 5 to 9 Medium, 10 to 15 High, 16 to 25 Critical.

Medium or above needs full treatment, the same trigger the Commonwealth tool uses for full assessment. High or Critical goes to your governance body, mirroring the NSW rule that sends high or critical assessments to its AI Review Committee. The system's overall rating is its highest single risk.

Column L carries the automated decision flag across from the inventory, and column M marks risks that involve a third-party model.

Worked example 路 R-001

Likelihood 3 Possible. Consequence for the organisation 3 Moderate, for policyholders 4 Major. The workbook takes the 4, so the inherent score is 12 and the tier is High. On the organisation's column alone the same risk scores 9 and sits in Medium, one band below the governance body.

OUTPUT 路 Inherent score and tier per risk, overall system rating

ASIC found licensees that assessed the fraud risk of overseas-developed identity verification models and missed the risk of groups failing verification, because the models were not trained on representative Australian data.

Step 06 路 Impact assessment

Assess the impact on people.

This sheet is the second register. It records who the system affects and how, on the example structure in ISO/IEC 42005. ISO/IEC 42001 asks for a risk assessment and an impact assessment separately, and steps 4 to 6 give you both.

Fill one row per system: intended use, reasonably foreseeable misuse, the individuals and groups affected, the interested parties you consulted, the benefit to people and the harm.

Write a best case and a worst case in plain words, a pair taken from section 3 of the New Zealand questionnaire.

Score likelihood and magnitude of harm on the same scales as step 5. Record whether a privacy impact assessment has been done and carry the automated decision flag across.

Leave no cell blank. The New Zealand guide treats an unanswered question as an answer in itself, and it counts toward the risk profile. Column T takes the approval decision: Approved, Approved with conditions, Re-scope or Do not proceed.

Worked example 路 I-001

Intended use is triage of standard motor and home claims. The foreseeable misuse is declining complex or health-related claims without human review. Policyholders with limited English or non-standard documentation carry the most exposure. Claims staff, the customer advocacy team and an external consumer group were consulted.

Best case: median settlement time falls with no change in dispute rates by cohort. Worst case: one cohort is systematically routed to review and delayed, and complaints and regulator attention follow. Likelihood 3, magnitude 4, tier High. Decision: Approved with conditions.

OUTPUT 路 Impact row, scenario pair, impact tier, approval decision

From 10 December 2026, APP 1.7 to 1.9 require Australian APP entities to describe in their privacy policy the kinds of decisions a computer program makes, or substantially contributes to, using personal information, and the rows you flagged in both registers are that list.

Step 07 路 Risk register N to W, Controls map

Treat each risk and map it to a control.

Go back to the risk register. For each risk, choose Avoid, Reduce, Share or Accept, describe the treatment, name a risk owner and assign a control ID.

Every control ID gets a row in the Controls map, mapped to an ISO/IEC 42001 Annex A theme and a NIST AI RMF function and category. Record its owner, how often it is tested and the evidence that shows it operates.

Then score residual likelihood and consequence back in the register. Column V asks whether the residual tier sits inside the appetite your board has set.

If the organisation has no appetite statement to test against, record that as a finding. At that point a single-system assessment has become the case for an AI risk management framework (New Zealand).

Worked example 路 R-001 to C-001, R-002 to C-002

R-001 is reduced by fairness testing on Australian claims data by cohort before release, a monthly disparity report and human review of all declines. Control C-001 maps to NIST MEASURE 2.11 and to ASIC's fairness finding. Its evidence is a test report with cohort tables and the release ticket showing the gate. Residual: 2 Unlikely by 3 Moderate, a score of 6, inside tolerance.

R-002 is reduced by a contract clause that requires 30 days' notice of version changes, with drift monitoring against a frozen test set. Control C-002 maps to NIST MANAGE 3 and to the CPS 230 material service provider register.

OUTPUT 路 Treatment plan, controls with evidence, residual tiers

APRA expects regulated entities to use globally recognised control frameworks including control libraries, and the Controls map is where yours starts.

Step 08 路 Review log

Sign off and set the review triggers.

Log the assessment as the first review. A first assessment takes the trigger Pre-deployment. Record what changed, which risk and impact IDs were scored, the outcome, the reviewer and the approver. The approving officer you named in step 1 signs here.

Set the next trigger from the drop-down: a change of purpose, data, users, environment, or law or policy, or an incident. Add a maximum interval as a backstop, and keep it at 12 months or less so every system is reassessed at least once a year.

When a trigger fires, add a log row, re-score the affected risk and impact rows, and get a fresh approval.

Worked example 路 L-001

Pre-deployment review of AI-001 before production release. Risks R-001 and R-002 and impact I-001 scored. The risk analyst reviewed and the CRO approved with conditions. Next trigger: change of data. Maximum interval: 12 months.

OUTPUT 路 Signed review entry, next trigger, backstop interval

No Australian or New Zealand framework fixes a calendar interval. ISO/IEC 42005 calls for reassessment when intended use, users, environment or law change. The NSW framework sets its trigger at significant change to features, datasets, purpose or decision context.

Reference: the ten risk categories.

These are the options in column C of the risk register. Each traces to a regulator or a government tool in Australia or New Zealand. Cite the anchor when someone asks why a row exists.

Category Where it is anchored
Bias, fairness and discriminationASIC REP 798, where only 12 of 23 licensees referenced fairness; NIST MEASURE 2.11; NZ Algorithm Impact Assessment section 8; Commonwealth tool section 5.
PrivacyOAIC guidance on commercially available AI products; NIST MEASURE 2.10; NZ AIA section 7; Commonwealth tool section 7; APP 1.7 automated-decision flag.
SecurityAPRA letter information security observations (prompt injection, data leakage, misuse of autonomous agents); NIST MEASURE 2.7; ASD and NCSC Engaging with AI.
Safety and reliabilityNIST characteristics safe and valid and reliable, MEASURE 2.5 and 2.6; NZ AIA section 10; Commonwealth tool section 6.
Intellectual propertyNIST MAP 4.1 on infringement of third-party intellectual property.
Explainability, transparency and contestabilityNIST MEASURE 2.8 and 2.9; ASIC REP 798, where 10 of 23 licensees required disclosure and none had contestability arrangements; Commonwealth tool sections 8 to 10; APP 1.7.
Third party and supply chainASIC REP 798, where 30 percent of use cases ran on third-party models; APRA letter supplier risk including fourth parties; NIST MAP 4 and MANAGE 3; CPS 230 material service provider register.
Operational and resilienceCPS 230 tolerance levels; APRA letter change management and assurance observations; ISO/IEC 23894 Annex B hardware, lifecycle and technology readiness themes.
Legal, regulatory and conductASIC REP 798 on the effect of AI use on regulatory obligations; NIST GOVERN 1.1.
Impact on people and communitiesISO/IEC 42005 scope; NZ AIA section 3 (best and worst case) and section 5 (partnership with M膩ori); Commonwealth tool section 2.

Start with the system that is next in line.

The workbook has the six sheets in the order above, two worked example rows on each, and drop-down lists on every scored column. Scores and tiers calculate as you fill them in.

Free download 路 XLSX 路 6 sheets

AI risk assessment workbook.

Opens in Excel, Google Sheets or Numbers. Version 1.0.

Thirty-minute call

Walk one system through it with us.

Bring the system waiting on a go-live decision. We run steps 2 and 3 with you on the call and tell you what the remaining steps would need to cover.

Download the workbook

Tell us who you are and the workbook will download straight away.

By submitting you consent to PolyGovern contacting you about the checklist. No spam; unsubscribe any time.

Questions we get asked.

What is an AI risk assessment?

A structured identification, analysis and evaluation of what can go wrong with an AI system and who it can harm, followed by treatment, monitoring and records. It is the ISO 31000 process as extended for AI by ISO/IEC 23894, with risk defined the way the NIST AI RMF defines it: the probability of an event multiplied by the magnitude of its consequences.

Is an AI risk assessment mandatory in Australia?

There is no general statutory requirement for private-sector entities. APRA expects regulated entities to run comprehensive risk and information security assessments before deployment and throughout the lifecycle. ASIC expects AFS and credit licensees' existing obligations to cover AI risk. Commonwealth agencies must complete an AI impact assessment for in-scope use cases under the DTA policy, and NSW agencies must apply the NSW AI Assessment Framework.

Is an AI risk assessment mandatory in New Zealand?

No statute requires one. The Privacy Commissioner expects a privacy impact assessment or algorithmic impact assessment before generative AI is used, with feedback from affected communities and M膩ori. Public agencies have the Stats NZ Algorithm Impact Assessment toolkit, which begins with a threshold screen.

How is it different from a privacy impact assessment?

A privacy impact assessment tests how personal information is handled against the privacy principles. The OAIC expects one as part of privacy by design for AI products. An AI risk assessment also covers bias, safety, security, intellectual property, explainability, third-party and operational risk. The Commonwealth AI impact assessment tool treats the privacy threshold and PIA as one section out of twelve.

What likelihood and consequence scale should we use?

No Australian or New Zealand framework prescribes numbers. The Commonwealth tool scores likelihood and consequence with descriptors from insignificant to severe and escalates anything rated medium or above. NSW escalates high or critical assessments to its AI Review Committee. New Zealand's Algorithm Impact Assessment uses a yes or unsure threshold, then narrative best-case and worst-case scenarios. Our workbook uses a five by five matrix with endpoints that match the Commonwealth descriptors.

Do we need a full assessment for every AI tool?

No. Threshold screens exist so that low-impact tools exit early. The New Zealand toolkit gives internal diary scheduling as an example that does not need a full assessment, and benefit-eligibility scoring as one that does. Anything that touches rights, eligibility, access to services or sensitive data goes to full assessment.

How does an AI risk assessment relate to ISO 42001?

ISO/IEC 42001 requires both an AI risk assessment and an AI system impact assessment. ISO/IEC 23894 is the guidance companion for the risk assessment and ISO/IEC 42005 is the companion for the impact assessment. The workbook on this page carries both so one document feeds both requirements.

What did ASIC find about AI risk assessments?

Across 23 licensees and 624 AI use cases, only 12 licensees had policies referencing fairness, only 10 had documented consumer-disclosure requirements, none had AI-specific contestability arrangements, and 30 percent of use cases ran on third-party models. Some licensees assessed AI risk through a business lens and did not consistently identify consumer harm such as algorithmic bias.

How often should we reassess?

Reassess on every material change, and at least once a year. ISO/IEC 42005, the NSW framework and the NIST AI RMF all point to reassessment when purpose, data, users, operating environment or law change. APRA expects assessment throughout the lifecycle. No Australian or New Zealand framework fixes a calendar interval, so the workbook records the trigger and a maximum interval of 12 months as a backstop.

Get in Touch