What do we mean by AI risk?
Risk arises when uncertainty may affect our objectives. In AI, we can put it simply: something may happen and cause a consequence that matters.
If a system recommends candidates for a job, one risk may be that certain groups are systematically disadvantaged. Saying that ‘AI is biased’ is not precise enough. We need to ask what may happen, why, who may be affected and what the consequences would be.
Once the risk is expressed clearly, it becomes possible to manage it.
Risk depends on context
The same AI technology can create very different risks depending on how it is used. A model that organises personal photographs does not have the same consequences as one that helps decide who gets a job, credit, medical priority or access to an essential service.
Risk management therefore starts by understanding the system: what it does, why it is used, who may be affected, which data it uses, which decisions it influences and what would happen if it failed.
An AI systems inventory is especially useful here, as it connects each system with its real organisational context.
Identify risks before assessing them
Before assigning a risk level, the organisation needs to know what it is looking for. Identification should be proportionate to the system and its context.
- Data quality
- Bias and discrimination
- Errors in outputs
- Lack of explainability
- Misuse or unintended use
- Supplier dependency
- Security and privacy
- Insufficient human oversight
- Model changes and loss of traceability
- Impacts on rights and regulatory non-compliance
Likelihood and impact
Once a risk has been identified, it can be assessed using two practical criteria. Likelihood asks how probable it is that the event will occur. Impact asks how serious the consequences would be if it did.
A simple five-point scale — very low, low, medium, high and very high — can be used for each criterion. Combining them helps the organisation prioritise, because not every risk requires the same response.
The risk matrix
A risk matrix visualises the combination of likelihood and impact. A risk with high impact and high likelihood clearly deserves more attention than one with low impact and very low likelihood.
The matrix does not replace judgement. It organises it and gives different people across the organisation a shared language for discussing risk.

From risk to control
Identifying a risk is of little value unless action follows. A practical chain is: risk — what may happen; control — what reduces its likelihood or impact; evidence — how the organisation can demonstrate that the control exists and works.
For a recruitment system, the risk may be discriminatory recommendations. A control could be periodic outcome reviews and human oversight before a decision. The evidence would be the records of those reviews and decisions.
What can an organisation do with a risk?
A risk can be reduced through controls, avoided by changing or ending the activity, transferred or shared through contractual arrangements, or accepted.
Acceptance does not mean ignoring the risk. It is a conscious, documented decision stating who accepted it, why it is considered tolerable, for how long and when it must be reviewed.
Who should take part?
AI risks rarely belong only to the technology team. IT, Compliance, Legal, Human Resources, Security, Data Protection, Procurement, Operations, business teams and senior management may all hold part of the picture.
Technology can explain how the system works, business teams why it is used, Legal and Compliance the obligations involved, and process owners what happens in practice. This cross-functional view is part of effective AI governance.
Review risks throughout the lifecycle
A one-off assessment does not remain valid forever. Systems, data, suppliers, uses and the regulatory environment all change.
Risks should be reviewed after significant system or purpose changes, new data, supplier changes, incidents, relevant new information or the planned review date. Managing risk is not merely creating a matrix; it means keeping it alive.
Document the decisions
Risk management must leave a trace. Six months later, someone may need to know why a risk was accepted, which controls were selected, who made the decision and when it was due for review.
If that history can be reconstructed, the organisation has traceability. Risk management then becomes a real governance process rather than a table completed once.
The goal is not to eliminate all uncertainty. It is to make better, accountable decisions about AI and to know whether risks remain under control.
Would you like to understand the risks in your AI?
Start by identifying your systems and understanding how they are being used.
Start the Céntrika assessment →
Use the Céntrika assessment to obtain an initial view of your organisation’s AI governance, risk and compliance and identify areas that need deeper review.
The assessment provides initial guidance and does not replace a specific evaluation.
