AI Risk Management Checklist for Organizations
AI risk cannot be managed from a list of approved chatbot brands. Organizations need to know which systems and informal workflows use AI, what data and decisions they touch, who owns the outcome and how the system can be stopped.
This checklist adapts the four functions of the NIST AI Risk Management Framework—govern, map, measure and manage—into a practical starting point. It is not a certification or legal checklist.
Govern: establish ownership and rules
- Name an accountable business owner and a technical owner for every material AI use case.
- Publish a short acceptable-use rule that staff can understand: approved tools, prohibited data, required review and a channel for exceptions.
- Define who can approve higher-risk uses and who can disable them during an incident.
- Assign security, privacy, legal, procurement and subject-matter review according to the impact—not the novelty of the model.
- Train people for their role. General AI literacy, secure implementation and model evaluation are different skills.
- Keep a dated decision record: intended use, owner, accepted risks, evidence, conditions and review date.
Map: understand the system and its impact
Maintain an inventory that includes:
- the purpose, users and people affected;
- model and provider, version where available, hosting and contractual plan;
- prompts, datasets, retrieval sources, connectors and downstream tools;
- personal, confidential or regulated data entering and leaving the system;
- decisions or actions the system can influence or perform;
- human review, fallback process and dependencies;
- applicable jurisdictions, contracts and sector rules.
Map misuse and failure, not just intended use. Ask what happens if the model is wrong, manipulated, unavailable, biased, over-permissioned or silently changed.
Measure: produce evidence before trust
Define testable requirements for the use case. Depending on impact, measure:
- task accuracy and known failure modes on representative data;
- security abuse cases, access-boundary tests and data leakage;
- performance across relevant groups and accessibility needs;
- human-review effectiveness and automation bias;
- provenance, source quality and reproducibility;
- latency, availability, cost limits and recovery behavior;
- changes after model, prompt, data or tool updates.
A vendor benchmark is not evidence that your workflow is safe. Test the configured system with your data, permissions and consequences. Record limitations as prominently as successful results.
Manage: reduce, monitor and respond
- Remove unnecessary data, tools and permissions before adding compensating controls.
- Use staged rollout, usage limits and human approval where consequences are difficult to reverse.
- Monitor policy decisions, access, tool actions, overrides, complaints, security events and material quality changes.
- Set review triggers: provider changes, new data, new users, new tools, expanded geography, incidents and regulatory updates.
- Maintain rollback and manual fallback procedures.
- Give users and affected people a way to question, correct or appeal consequential results where appropriate.
- Exercise an AI incident scenario with security, privacy, legal, communications and the business owner.
Vendor due diligence
Ask for evidence relevant to the service you will actually buy and configure:
- What models, subprocessors, regions and data flows are involved?
- Is customer data used for training or product improvement? Which controls are contractual?
- How are tenant isolation, access control, prompt injection and tool abuse tested?
- What changes can the vendor make without notice, and how are model versions communicated?
- What logs, export, deletion, retention, incident notification and audit rights exist?
- Can the service meet your recovery, availability and exit requirements?
- Which claims have independent evidence, and what exactly was in the assessment scope?
Reassess material vendors and high-impact uses periodically; an approval should not last forever.
A proportionate review gate
Escalate review when an AI system:
- affects access to employment, education, credit, insurance, health, housing, justice or public services;
- processes sensitive or large-scale personal data;
- communicates externally as the organization;
- can spend money, execute code, change records or control physical processes;
- operates without timely human review;
- creates safety, rights, legal or material financial consequences if it fails.
Do not use a low-risk label to bypass ordinary cybersecurity, privacy or procurement controls.
Law and policy change quickly
The EU AI Act and national or sector-specific rules apply on different timelines and to different roles. Use the European Commission AI Act portal for the current EU implementation position, then obtain qualified advice for your organization and use case. Keep legal dates in a maintained tracker rather than copying them into a policy that no one updates.