AI Risk Assessment Template UK: Score Use Cases Before Rollout
Four scoring dimensions — data, customers, compliance, review — that tell you whether an AI use case is ready to ship, needs guardrails, or should wait.
Most SMEs assess AI ideas by enthusiasm. A risk assessment template replaces that with ten minutes of structure: score the use case on four dimensions before rollout, and let the score decide whether it ships, ships with guardrails, or waits.
The four dimensions
1. Data sensitivity. What information does the use case touch? Public or internal-only material scores low. Customer records, employee data, financial, health, or legal content scores high — and high here means data rules and tooling choices come before anything else.
2. Customer impact. Does the output reach customers directly, indirectly, or not at all? Internal drafts score low. Anything sent to a customer without a human in between scores high.
3. Compliance exposure. Does the workflow sit anywhere near regulated territory — claims, contracts, HR decisions, financial advice? If a regulator or tribunal could ever read the output, score it high.
4. Review needs. How much human checking does the output require, and is that review realistic at your volumes? A use case that needs expert review on every item but runs at hundreds of items a day scores high — the review burden is the risk.
Reading the score
All low: ship it narrowly and measure. Mixed: ship with the specific guardrail the high dimension demands — a data rule, an approval step, a sampling-based review. Mostly high: wait, redesign the use case, or keep the human in the loop permanently. The point is not to block AI use; it is to make the riskiest ideas visibly different from the safe ones before money is spent.
Using it in practice
Run the template on every proposed use case in one sitting — a leadership hour covers a dozen. File the scores with the staff AI policy so the rules and the assessments live together, and re-score whenever a use case gains a data source or an audience. For use cases that pass, the next step is a scoped pilot as described in our implementation guide.
If you want help scoring a real list of use cases, book a free consultation with Blue Canvas.
If this is the kind of work you want help with, learn how we run AI consultancy for SMEs, or book a free consultation.
Phil Patterson · Founder, Blue Canvas AI
Phil runs Blue Canvas AI, a Derry-based consultancy helping UK and Irish SMEs scope, train for, and implement practical AI workflows.
FAQ
Frequently asked questions
What should an AI risk assessment cover for an SME?
Four dimensions: data sensitivity, customer impact, compliance exposure, and review needs. Score each use case low/medium/high and let the profile decide whether it ships, ships with guardrails, or waits.
How often should use cases be re-scored?
Whenever they gain a data source, an audience, or an action type — and at a periodic review alongside the staff AI policy. A use case that was safe as an internal draft tool changes risk class when its output starts reaching customers.
Is this needed for low-stakes internal tools?
Run the template anyway — it takes minutes, and the exercise regularly surfaces a data-sensitivity issue nobody had flagged. Low scores are a useful record, not wasted effort.