Appendix C: Initial AI Risk Triage Form
Route an AI proposal to the right owners and controls by assessing context, data, autonomy, exposure, affected people, and uncertainty before design begins.
Route the Proposal Before It Gathers Momentum
A product team wants to trial an assistant that summarizes employee performance notes. The feature is described as “suggestion only.” Yet it sits inside employment decisions, processes personal data, inherits uneven manager records, and may shape promotion or dismissal. The capability sounds modest because the description stops before the consequence.
Initial triage is a routing decision, not a safety certificate. Its job is to identify hard stops, expose missing facts, assign a provisional tier, and bring the right owners into the work before architecture and vendor choices become expensive to reverse.
How to Use This Form
Begin with the decision being requested: permission to explore, prototype, pilot, deploy, or change an existing system. Complete the form with the product owner, technical owner, workflow or domain expert, and a risk representative. Use a concrete proposed use, not a category such as “copilot.” Attach the AI Use Case Canvas when one exists.
Record evidence and uncertainty beside every answer. When reviewers disagree, retain the highest plausible exposure until the disagreement is resolved. Re-run triage when the system’s purpose, affected population, data, autonomy, provider, deployment region, or action path changes materially.
Read the Route Before Choosing a Tier
Start with hard gates. A use prohibited by binding law or policy does not become acceptable through extra monitoring. Neither does a proposal with unlawful data, intolerable irrecoverable harm, an outcome that cannot be evaluated, or no accountable owner. Stop or route the unresolved question to someone with authority to decide it.
For proposals that remain open, follow the output into the workflow. A suggestion that a manager routinely accepts may carry more practical authority than an automated action that is tightly bounded, reversible, and monitored. Ask what action follows, who bears an error, whether burdens accumulate on one group, and whether a person can prevent, detect, contain, correct, and appeal the harm.
Then assign a provisional tier using the organization’s approved definitions. Raise it as scale, irreversibility, autonomy, sensitive context, concentrated harm, or unresolved uncertainty increases. The tier does not establish regulatory classification and does not authorize launch. It determines the evidence, controls, reviewers, and next decision the proposal needs.
Initial AI Risk Triage
SYSTEM AND REVIEW
System name and version:
Review date:
Proposal owner:
Technical owner:
Workflow/domain owner:
Triage facilitator:
Decision requested: explore / prototype / pilot / deploy / change
PROPOSED USE
User and workflow:
AI role: predict / classify / rank / retrieve / generate / recommend / act
Output and immediate next action:
Decisions and actions explicitly outside system authority:
Non-AI baseline:
DOMAIN AND CONTEXT (select all that apply)
[ ] Healthcare or life sciences [ ] Employment or worker management
[ ] Education [ ] Credit, finance, or insurance
[ ] Public services or benefits [ ] Law enforcement or security
[ ] Critical infrastructure [ ] Consumer product
[ ] Internal productivity [ ] Children or vulnerable people
[ ] Other consequential context:
Jurisdictions and deployment regions:
Specialist review trigger and owner:
DATA AND RIGHTS
[ ] Public [ ] Internal
[ ] Confidential [ ] Personal data
[ ] Sensitive personal data [ ] Regulated or contract-restricted
[ ] Third-party or licensed [ ] Inferred or generated data
Sources, owners, permissions, retention, and deletion path:
Data the system must never receive or reveal:
Known coverage, quality, or representativeness gaps:
AUTHORITY AND REVERSIBILITY
[ ] Suggestion only
[ ] Human-approved action
[ ] Automated reversible action
[ ] Automated consequential action
[ ] Autonomous multi-step action
Who can approve, override, pause, correct, and appeal?
Tools, permissions, and resources available to the system:
Maximum credible blast radius:
ERROR AND EXPOSURE
False-positive consequence:
False-negative consequence:
Harmful or unsupported generation consequence:
Tool, integration, or downtime consequence:
Security, privacy, fairness, accessibility, or rights exposure:
Can harm be prevented, detected, contained, corrected, and appealed?
AFFECTED PEOPLE
Direct users:
People affected by outputs or actions:
People who may face concentrated or cumulative burden:
How affected people can obtain notice, correction, human contact, or appeal:
People who need preparation to use, challenge, or explain the system:
EVIDENCE AND UNCERTAINTY
What evidence exists now?
What cannot yet be evaluated?
Most consequential assumption:
Unknown / owner / due date:
HARD-GATE RESULT
[ ] No known hard stop
[ ] Specialist review required before work continues
[ ] Blocked pending evidence or control
[ ] Use is prohibited by binding law or policy
Reason and authority:
PROVISIONAL ROUTING TIER
[ ] Tier 0 — no AI component or no material AI exposure
[ ] Tier 1 — low exposure; normal product and engineering controls
[ ] Tier 2 — material exposure; documented evaluation and risk review
[ ] Tier 3 — high or consequential exposure; independent challenge and formal approval
[ ] Tier 4 — prohibited or intolerable use; do not proceed
Organization-specific tier definition/version:
REQUIRED REVIEWS (name an owner, not only a function)
[ ] Product [ ] Engineering / ML [ ] Domain safety
[ ] Security [ ] Privacy [ ] Legal
[ ] Accessibility [ ] Compliance [ ] Responsible AI
[ ] Labor / works council [ ] Procurement / vendor [ ] Executive sponsor
Other:
DECISION
[ ] Stop
[ ] Gather evidence
[ ] Redesign
[ ] Bounded discovery or prototype
[ ] Proceed to formal impact assessment and evaluation planning
Conditions, owners, evidence, and due dates:
Next review date and change triggers:
Worked Triage: When “Suggestion Only” Is Not Low Risk
Suppose the team initially proposes Tier 1. Their reasoning is brief: the assistant only summarizes, and a manager reads every draft. Before accepting that route, trace one summary forward. It becomes the manager’s compressed account of a review period, informs a performance conversation, and may later support compensation, promotion, or dismissal. The reviewer is also the person who wrote many of the source notes. A click in this workflow is not independent challenge.
The context now supplies facts that the capability label concealed. The system processes confidential employee records in an employment setting. Historical notes may reflect inconsistent standards, silence may be mistaken for poor performance, and fluent compression may make omissions difficult to notice. The affected employee does not see the generation process and may have no direct way to correct the source or summary.
No claim in those facts proves that the use is unlawful, but they do rule out casual experimentation on live records. The triage record routes the proposal to Tier 3 under the organization’s internal scheme, pending named privacy, labor, fairness, accessibility, security, and legal decisions. It excludes ranking and recommendations from system authority. Any bounded discovery must use approved data, show source excerpts beside every claim, test omission and framing errors across relevant groups, and give employees a human correction route. Managers need guidance on the tool’s limits and remain accountable for the final record.
The resulting decision is precise: no pilot or deployment; bounded discovery only while the named reviewers determine whether the use is permissible and whether those controls can make it supportable. A reviewer, due date, and required evidence accompany each unresolved question. A change from summarization to ranking would trigger new triage rather than inherit this decision.
Before Circulating the Record
Read the completed form from the decision backward. Can each condition be traced to an owner, evidence, and due date? Does the stated tier reflect the real action path rather than the product label? Could an affected person find a route to notice, correction, human contact, or appeal? Would a material change in data, authority, population, provider, region, or workflow reliably return the proposal for review? If any answer is no, the record is not ready to route.
Continue with Risk Triage Before Building, the AI Appropriateness Scorecard, and the Evaluation Plan Template.
Continue reading
Full table of contents