This checklist helps organisations classify their AI systems by risk level, based on the probability and severity of potential harm. Proper risk classification is the foundation of responsible AI governance. It determines the level of oversight, documentation, and controls required for each system. Use this tool to systematically assess your AI deployments and ensure appropriate safeguards are in place.
How to use: Begin with the Risk Classification Matrix to understand the four risk tiers. Then complete a Per-System Risk Assessment for each AI system in your organisation. Finally, record your findings in the Risk Register Summary Table to maintain a centralised view of AI risk across your operations.
Risk Classification Matrix
Use the matrix below to determine the risk level of each AI system based on two key factors: the probability that the system could cause harm, and the severity of that harm if it occurs.
Customer segmentation, chatbots handling general enquiries, sentiment analysis
Regular audits, documentation of AI logic, user notification of AI use
High
Likely
Significant
Credit scoring, HR screening and recruitment, insurance underwriting
Human oversight, bias testing, data protection impact assessment, explainability requirements
Critical
Almost certain
Severe
Medical diagnosis, autonomous decision-making affecting legal rights, safety-critical systems
Full governance framework, external audit, board-level oversight, continuous monitoring, incident response plan
Per-System Risk Assessment
Complete the following assessment for each AI system deployed in your organisation. The answers will help determine the appropriate risk classification and identify areas requiring additional controls.
_______________________________________________
A. Data Sensitivity
☐ Does this system process personal data (e.g., names, email addresses, phone numbers)?
☐ Does this system process sensitive personal data (e.g., health records, financial data, biometric data)?
☐ Does this system process data relating to children or vulnerable individuals?
☐ Does this system process large volumes of personal data (e.g., more than 10,000 records)?
B. Decision Impact
☐ Does this system make or directly inform decisions that affect individuals (e.g., approvals, rejections, rankings)?
☐ Could the decisions made by this system result in financial, legal, or reputational consequences for individuals?
☐ Are the decisions made by this system reversible if an error is identified?
☐ Is there a process for human review of AI-generated decisions before they are actioned?
C. Transparency
☐ Can the decisions or outputs of this system be explained in plain language to affected individuals?
☐ Are users or data subjects informed that AI is being used in this process?
☐ Is there a mechanism for individuals to appeal or challenge AI-generated decisions?
☐ Is documentation maintained that describes the system's purpose, data inputs, logic, and limitations?
Assessed Risk Level: ☐ Low ☐ Medium ☐ High ☐ Critical
Maintain a centralised record of all AI systems and their assessed risk levels. Update this register whenever a new AI system is deployed or an existing system is modified.
AI System
Risk Level
Key Risks Identified
Mitigation Measures
Owner
Review Date
IMDA Framework Alignment: This checklist maps to the four pillars of Singapore's Model AI Governance Framework issued by the Infocomm Media Development Authority (IMDA):
1. Internal Governance Structures and Measures: The risk classification matrix and risk register support the establishment of clear accountability and oversight structures for AI systems. 2. Determining AI Decision-Making Model: The Decision Impact assessment questions help organisations determine the appropriate level of human involvement in AI-assisted decisions. 3. Operations Management: The Per-System Risk Assessment covers data management, robustness, and regular review practices aligned with operational best practices. 4. Stakeholder Interaction and Communication: The Transparency assessment ensures organisations maintain clear communication with individuals affected by AI-driven processes, including notification, explainability, and appeal mechanisms.
Working through this classification
AI governance is not something DataCare Solutions sells as a separate service. Our free AI governance guide explains how to apply this classification and what to do with the result. The practical side, staff knowing what they may put into a tool and when output must be checked, is covered in AI Training.