Staging environment
Digital asset

The AI Risk Assessment Kit: Template, Worked Example & Workbook

François B. Arthanas

François B. Arthanas

See all products from François B. Arthanas

You have been asked to assess an AI system. Now what?

Most first AI risk assessments read like an opinion. A list of concerns, no evidence behind them, no clause to point at, and nothing anyone can act on.

Four things separate an assessment from an opinion:

  • Every risk carries a real-world precedent, so it reads as a forecast rather than a hunch

  • Every rating carries a written rationale, so it survives being challenged

  • Every control maps to a named clause, so it can be audited

  • Every recommendation has an owner and a date, so something actually moves

This kit gives you the structure for all four plus a completed example showing what it looks like when it's done properly.

What's in the kit

Three files. Two are editable, so you can fill them in and use them on a real system.

1. AI Risk Assessment Template (Word, editable)

Nine pages, seven sections: system profile, regulatory scope, risk identification, rating against a 5×5 matrix, control design, formal finding, executive summary. Fill-in fields throughout type straight into it in Word or Google Docs. Aligned to NIST AI RMF 1.0, ISO/IEC 42001:2023 and the EU AI Act. Includes an autonomy and scope-of-action section for agentic systems: what it can do without asking, which actions are irreversible, and where the stop is.

2. Worked Example (PDF)

The same template completed end to end on a high-risk system: a third-party résumé screening tool that auto-rejects roughly 14,700 candidates a quarter with no human review. Five risks, each with a precedent. Ratings with the reasoning written out. Controls mapped to named articles and Annex A controls. One formal finding, and an executive summary a CHRO could actually act on. This is the one to copy the shape of.

3. Workshop Workbook (Word, editable)

Eleven pages: a bridge assessment for where you're starting from, a job posting decoder for reading AI governance roles like an insider, the full assessment to build yourself, and a 90-day plan.

Who this is for

- Security, audit, privacy, compliance and risk professionals who've been handed an AI system and told to assess it

- GRC people moving into AI governance who need a portfolio artifact that holds up in an interview

- Anyone who has to explain an AI system to leadership, legal or a regulator and needs the work to survive the room

You don't need a technical background. You need to be willing to understand how a system uses data, makes decisions and takes action.

Not for you if you're after a theory primer. This is a working set of documents.

Free

Download an editable assessment template, a completed example on a real high-risk system, and the workshop workbook.