AI Risk Assessment
An AI risk assessment is a structured review of an AI system's potential harms — to individuals, groups, the organization, and society — covering likelihood, severity, affected populations, and mitigation controls across safety, fairness, security, privacy, and compliance dimensions.
Full definition
Frameworks include the NIST AI RMF (Govern/Map/Measure/Manage), the EU AI Act's Fundamental Rights Impact Assessment (FRIA) for high-risk systems, ISO/IEC 23894, and Canada's Algorithmic Impact Assessment. A useful assessment is repeated at design, pre-deployment, and at major model changes — not a one-time PDF. AIDOLS integrates AI risk assessment into our ai-readiness-assessment for any client deploying user-facing AI.
Why it matters
Under the EU AI Act, risk assessments are legally required for high-risk systems and FRIA is required for many public-sector and credit/insurance deployments. Beyond compliance, structured risk assessment surfaces failure modes that engineering reviews miss — particularly disparate-impact and downstream-misuse scenarios.
Example
A bank's pre-deployment risk assessment of a credit-scoring model surfaces a 4-point approval gap by ZIP-code demography traced to a proxy feature; the feature is removed before launch and disparate-impact litigation risk is materially reduced.
Related terms
- NIST AI RMFThe NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a voluntary U.S. framework for managing AI risks throughout the lifecycle, organized around four core functions — Govern, Map, Measure, Manage — and seven characteristics of trustworthy AI.
- EU AI ActThe EU AI Act (Regulation (EU) 2024/1689) is the European Union's comprehensive, risk-tiered regulation of AI systems, the world's first horizontal AI law, with obligations phasing in from February 2025 and full general-purpose AI rules applying from August 2025.
- AI GovernanceAI governance is the framework of policies, roles, controls, and processes an organization uses to ensure its AI systems are lawful, safe, fair, accountable, and aligned with business intent — across the full lifecycle from problem framing to retirement.
- AI AuditAn AI audit is a structured, evidence-based examination of an AI system or AI program against defined criteria — covering training data, model, deployment context, monitoring, and governance — performed by an internal team, an external firm, or a regulator.
Source & further reading
Primary source: NIST — AI Risk Management Framework (AI RMF 1.0) (2023).
Citation policy: this entry is part of the AIDOLS AI Implementation Glossary and may be quoted for research, journalism, and education with attribution to aidolsgroup.com/en/glossary/ai-risk-assessment/.