LawQi

Module 6.3 · Topic 3

Risk Classification and Impact Assessment

Bottom Line Up Front: Not all AI use carries the same risk. High-risk systems (affecting hiring, credit, healthcare decisions) need formal impact assessments, documentation, and controls. Medium-risk systems need…

3.1 Categorizing AI Use Cases by Risk Level

Risk Level Characteristics Example Use Cases Minimum Controls
High Affects individual rights; difficult to override Hiring, credit, benefits, moderation Impact assessment, bias testing, human override, audit trail, appeals
Medium Affects operations; easy intervention Forecasting, segmentation, content, automation, pricing Risk register, accuracy checks, escalation
Low Informs decisions; overridable; minimal impact Drafting, summarization, research, ideation Tool approved, policies, training

3.2 Conducting AI Impact Assessments

Impact assessments are formal reviews of AI systems to identify risks before deployment and create an audit trail showing due diligence. They are mandatory for high-risk decisions and should be standard practice for medium-risk systems.

  1. Define the system boundaries and purpose: Document what the AI system does, who it affects, and what decisions it informs or makes. Be specific: "Uses employment history and test scores to screen resumes for technical roles" is clearer than "hiring AI."
  2. Identify risks across five dimensions: Accuracy (error rates and who bears cost), Bias (different outcomes across groups), Privacy (data handling adequacy), Accountability (explainability and appeal processes), Transparency (disclosure to affected parties).
  3. Document findings and mitigation: For each risk identified, describe mitigation: process controls (human review), technical controls (accuracy thresholds, bias detection), or acceptance (risk known and accepted). Assign ownership and timelines.
  4. Obtain sign-off and schedule re-assessment: High-risk systems reassess annually or with major changes. Medium-risk systems reassess biennially. Low-risk systems document once unless flagged by monitoring.

3.3 Documenting Decisions and Maintaining Audit Trails

Audit trails demonstrate that governance procedures were followed and create an evidentiary record if an AI decision is challenged. Different risk levels require different documentation depth.

  • High-risk decisions (hiring, credit, benefits): Document system version, parameters used, input data, output score/recommendation, human review, final decision, corrections or appeals
  • Medium-risk decisions (analytics, content, segmentation): Document approval workflows, periodic accuracy checks, escalation decisions
  • Low-risk decisions (drafting, summarization): Track which tool was used and conduct sample review to confirm output quality
  • Storage and retention: Store securely, indexed by date and decision type for audit access. Retain 3-7 years per regulatory requirements

3.4 Incident Response and Remediation Planning

Incident response plans ensure rapid, coordinated action when AI systems fail. Playbooks guide response; post-incident reviews prevent recurrence.

  1. Define incident types and escalation: Categorize incidents: Hallucination (AI generates false information), Bias incident (disparate outcomes across groups), Data breach (personal data exposed), Model failure (accuracy drops below threshold), Compliance violation (system used outside approved scope). Assign severity levels and escalation paths.
  2. Create response playbooks: For each incident type, define response: Hallucination—disable system, audit recent decisions, notify affected parties. Bias—pause, run diagnostics, reweight if needed. Data breach—follow incident response policy, notify regulators. Compliance violations—document, assess scope, implement remediation.
  3. Post-incident review and lessons learned: After incident resolution, document what happened, why, what response actions were taken, and what changes prevent recurrence. Share findings with governance board and update policies.