{"id":724,"date":"2026-08-31T00:13:04","date_gmt":"2026-08-30T16:13:04","guid":{"rendered":"https:\/\/yenhui.co\/?p=724"},"modified":"2026-08-31T00:13:04","modified_gmt":"2026-08-30T16:13:04","slug":"ai-risk-assessment","status":"publish","type":"post","link":"https:\/\/yenhui.co\/en\/insights\/ai-risk-assessment\/","title":{"rendered":"How to Conduct an AI Risk Assessment? A Complete Guide for Enterprise Inventory, Classification, and Mitigation"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><strong>AI Risk Assessment<\/strong>It involves organizing the purpose, users, data, model, output impacts, and responsibilities of an AI application into evidence, and then assessing potential harms, occurrence conditions, impact levels, and mitigation measures. The output of the evaluation should not just be a high, medium, or low label, but should also include the owner, control measures, residual risk, approval decision, and re-evaluation conditions.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What are the risks of AI applications?<\/h2>\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Risk dimensions<\/th><th>What should be checked<\/th><th>Required evidence<\/th><\/tr><\/thead><tbody><tr><td>Purpose and Impact<\/td><td>Who will be affected by the output, and can it be appealed or corrected?<\/td><td>Usage contexts, decision-making processes, and affected parties<\/td><\/tr><tr><td>Data<\/td><td>Source and quality, as well as representativeness, personal data, and authorization<\/td><td>Data dictionary and consent records, as well as quality control<\/td><\/tr><tr><td>Models and Suppliers<\/td><td>Limitations and versions, as well as storage region and external dependencies<\/td><td>Model cards and contracts, as well as change notices<\/td><\/tr><tr><td>Output quality<\/td><td>Errors and biases, as well as stability and interpretability<\/td><td>Test cases, red team or stress testing logs<\/td><\/tr><tr><td>Security and Abuse<\/td><td>Privilege escalation and prompt injection, as well as data leakage and abuse<\/td><td>Permissions, logs, and event testing<\/td><\/tr><tr><td>Operations<\/td><td>Manual handover and fault handling, as well as costs and supplier exit<\/td><td>SOP and recovery plan, as well as monitoring indicators<\/td><\/tr><tr><td>Laws and contracts<\/td><td>Obligation to apply, industry rules, and customer commitments<\/td><td>Legal opinions and contracts, along with approval records<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n<h2 class=\"wp-block-heading\">Four core processes of AI risk assessment<\/h2>\n<p class=\"wp-block-paragraph\">The Ministry of Digital Affairs previously announced artificial intelligence risk classification framework uses \"taking stock of application scenarios, identifying risks, assessing risks, and responding to risks\" as its operational process. Enterprises can extend this practical process into six executable steps and integrate it with existing<a href=\"https:\/\/yenhui.co\/en\/insights\/ai-governance-guide\/\">AI governance<\/a>Duty of care<\/p>\n\n<p class=\"wp-block-paragraph\">Source:<a href=\"https:\/\/moda.gov.tw\/press\/bulletin\/20086\" target=\"_blank\" rel=\"noopener\">Ministry of Digital Affairs: Artificial Intelligence Risk Classification Framework<\/a>&amp;<a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noopener\">NIST AI Risk Management Framework<\/a>The MODA established the framework on July 7, 2026, which took effect on the same day. As of the audit on August 28, 2026, the NIST AI RMF 1.0 is currently under revision. This article uses two frameworks to assist with management, which does not imply a specific regulation or compliance determination.<\/p>\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>This work<\/th><th>NIST AI RMF Functions<\/th><th>Question to be answered<\/th><\/tr><\/thead><tbody><tr><td>Specify roles, responsibilities, and decision-making scope<\/td><td>GOVERN<\/td><td>Who is responsible, and by what policy is it decided<\/td><\/tr><tr><td>Inventory scenarios and identify risks<\/td><td>Map<\/td><td>In what context does the system influence whom<\/td><\/tr><tr><td>Assess severity and likelihood<\/td><td>MEASURE<\/td><td>What evidence is used to assess risk<\/td><\/tr><tr><td>Response, monitoring, and reassessment<\/td><td>Manage<\/td><td>How to prioritize and control, as well as continuously improve<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n<h3 class=\"wp-block-heading\">1. Specify the owner and decision-making scope<\/h3>\n<p class=\"wp-block-paragraph\">First, designate the business owner, and confirm who is responsible for data, technology, as well as security, legal, and final approval. Applications without a person in charge should not rely solely on users' own judgment.<\/p>\n\n<h3 class=\"wp-block-heading\">2. Inventory of application scenarios<\/h3>\n<p class=\"wp-block-paragraph\">Record purpose and users; input data and model or vendor; output and affected subjects; human review and existing controls. Do not just write \"use ChatGPT\", because the same tool can be used for low-impact ideation or high-impact decision-making.<\/p>\n\n<h3 class=\"wp-block-heading\">3. Identifiable Risks<\/h3>\n<p class=\"wp-block-paragraph\">Identify failure modes from data and models, security and operations, and rights and external impacts. For example, generating false outputs, unfairness to specific groups, leaking sensitive data, lack of traceability, employee over-reliance, or sudden supplier revisions.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Evaluate severity and likelihood<\/h3>\n<p class=\"wp-block-paragraph\">Assess impact and likelihood using an organization-consistent scale, then consider the number of people affected and reversibility, while incorporating exposure time and existing controls. Different frameworks may have three, four, or five steps; the focus is not on a fixed number, but that the inputs, scale, and decisions can be reproduced.<\/p>\n\n<h3 class=\"wp-block-heading\">5. Select a response method<\/h3>\n<p class=\"wp-block-paragraph\">Risks can be optionally stopped, minimized, reduced, transferred, or accepted. Control measures may include data masking, permissions, manual review, usage restrictions, testing, monitoring, vendor terms, and appeal mechanisms.<\/p>\n\n<h3 class=\"wp-block-heading\">6. Approval, Monitoring, and Re-evaluation<\/h3>\n<p class=\"wp-block-paragraph\">Record who approved under what evidence, and set quality, cost, incident, and adoption metrics. Re-evaluate when model versions or data change, or when there are significant changes to use cases, regulations, vendors, or impacted stakeholders.<\/p>\n\n<h2 class=\"wp-block-heading\">What columns should a small and medium-sized enterprise AI risk assessment form include?<\/h2>\n\n<ul class=\"wp-block-list\"><li>App name, purpose, department, owner, and approver.<\/li><li>Users, affected parties, and usage frequency.<\/li><li>Data type, source, sensitivity, retention, and permissions.<\/li><li>models, suppliers, versions, and external dependencies.<\/li><li>Output purposes, human review, and prohibited use cases.<\/li><li>Risk description and impact, as well as likelihood of occurrence and existing controls.<\/li><li>New measures, responsible person, deadline, and residual risk.<\/li><li>Approval results, monitoring indicators, and re-evaluation trigger conditions.<\/li><\/ul>\n\n\n<h2 class=\"wp-block-heading\">Three common misconceptions<\/h2>\n<h3 class=\"wp-block-heading\">Evaluate the tool only, not the usage scenario<\/h3>\n<p class=\"wp-block-paragraph\">Using the same model for rewriting public copy and screening job applicants can vary significantly in the degree of impact and risk profile. The unit of evaluation should be \"tool plus data plus process plus decision,\" not the brand name.<\/p>\n<h3 class=\"wp-block-heading\">Treating manual review as a cure-all control<\/h3>\n<p class=\"wp-block-paragraph\">Manual review is only effective when personnel have the capability, time, information, and veto power. If thousands of results are generated per minute but only one person is assigned to spot-check them, manual review cannot be written off as a complete control.<\/p>\n<h3 class=\"wp-block-heading\">Evaluate it once before launch and that's it<\/h3>\n<p class=\"wp-block-paragraph\">AI systems are affected by data, model versions, usage methods, and the external environment. Evaluation must be linked to monitoring and re-evaluation, rather than merely serving as a procurement attachment.<\/p>\n\n<h2 class=\"wp-block-heading\">When is it necessary to seek external professionals?<\/h2>\n<p class=\"wp-block-paragraph\">If an application involves healthcare, finance, labor, personal safety, children and youth, sensitive personal data, legal rights, or large-scale automated decision-making, legal, cybersecurity, privacy, industry, or audit professionals should be consulted depending on the context. A advisory framework cannot replace specific regulatory judgments, penetration testing, or formal certifications.<\/p>\n\n<p class=\"wp-block-paragraph\">When the evaluation results require incorporating permissions, reviews, audit trails, or deactivation mechanisms into the system, they can be implemented by<a href=\"https:\/\/site-now.co\/contact\/\" target=\"_blank\" rel=\"noopener\">Instant Stand-Up<\/a>Assist in evaluating development and integration.<\/p>\n\n<h2 class=\"wp-block-heading\">Text Summary<\/h2>\n<ul class=\"wp-block-list\"><li>The unit of AI risk assessment is the specific application context, not just the tool.<\/li><li>The assessment must have an owner, evidence, controls, approval, and reassessment criteria.<\/li><li>The number of steps can be adjusted according to the framework, but the judgment scale must be consistent and reproducible.<\/li><li>High-impact scenarios require industry, legal, privacy, and cybersecurity expertise.<\/li><\/ul>\n\n<h2 class=\"wp-block-heading\">turn AI risks from abstract worries into manageable tasks<\/h2>\n<p class=\"wp-block-paragraph\">If companies need to take inventory of AI applications, responsibilities, and implementation priorities, they can first explain their current situation and existing evidence through the contact page, and then confirm the appropriate scope of consulting cooperation.<\/p>\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/yenhui.co\/en\/contact\/\">Book a consultation with Yan Hui consultant<\/a><\/div><\/div>\n\n<h2 class=\"wp-block-heading\">FAQ on AI Risk Assessment<\/h2>\n<h3 class=\"wp-block-heading\">What are the four steps of risk assessment?<\/h3><p class=\"wp-block-paragraph\">Use the four steps of inventorying application scenarios, identifying risks, assessing risks, and responding to risks, and then add responsibility assignment, approval, monitoring, and reassessment.<\/p>\n<h3 class=\"wp-block-heading\">How to assess AI risks?<\/h3><p class=\"wp-block-paragraph\">First define the specific context and evidence, then evaluate likelihood and impact based on a consistent scale, taking reversibility and affected parties into consideration, and finally record the controls and residual risk.<\/p>\n<h3 class=\"wp-block-heading\">Who should participate in AI risk assessments?<\/h3><p class=\"wp-block-paragraph\">At least including the business owner, actual users, data and technical leads, information security, legal or privacy, and a decision-maker who can accept or stop the risk.<\/p>\n<h3 class=\"wp-block-heading\">What evaluation evidence is required?<\/h3><p class=\"wp-block-paragraph\">Context, data sources, model and vendor documentation, test cases, permissions, human-in-the-loop workflows, and event and monitoring data must be used; relying solely on vendor marketing claims is not allowed.<\/p>\n<h3 class=\"wp-block-heading\">When should we re-evaluate?<\/h3><p class=\"wp-block-paragraph\">A reassessment should be conducted when there are changes to the model or data, significant changes to the purpose, affected subjects, regulations, suppliers, or control methods, as well as when an incident occurs or monitoring worsens.<\/p>\n<h3 class=\"wp-block-heading\">Can we go live directly if the risk score is low?<\/h3><p class=\"wp-block-paragraph\">Not necessarily. It is also necessary to verify scoring evidence, necessary controls, approval authorities, and prohibitive conditions. A single overall score should not mask non-negligible risks such as personal data, significant rights, or safety.<\/p>","protected":false},"excerpt":{"rendered":"<p>AI \u98a8\u96aa\u8a55\u4f30\u662f\u628a\u4e00\u500b AI \u61c9\u7528\u7684\u76ee\u7684\u3001\u4f7f\u7528\u8005\u3001\u8cc7\u6599\u3001\u6a21\u578b\u3001\u8f38\u51fa\u5f71\u97ff\u8207\u8cac\u4efb\u6574\u7406\u6210\u8b49\u64da\uff0c\u518d\u5224\u65b7\u53ef\u80fd\u50b7\u5bb3\u3001\u767c\u751f\u689d [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":726,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_gspb_post_css":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-consulting"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"_links":{"self":[{"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/posts\/724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/comments?post=724"}],"version-history":[{"count":0,"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/posts\/724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/media\/726"}],"wp:attachment":[{"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/media?parent=724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/categories?post=724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yenhui.co\/en\/wp-json\/wp\/v2\/tags?post=724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}