Skip to main content
AI Readiness · 7 min read

AI Risk Assessment: A Practical Checklist

An AI risk assessment inventories where AI touches your business, then scores the exposure across four areas: data handling, access and identity, AI-specific security threats, and human oversight. Work the checklist below in order; the first gap it surfaces is almost always ungoverned access.

By Dr. Jen Anderson

What an AI risk assessment is for

An AI risk assessment answers a narrow, urgent question: where could AI use hurt us, and how badly? It is not a general security audit. It focuses on the risks specific to AI — data leaving the business through third-party models, prompts manipulated to extract or alter behavior, and agents or users acting with more access than they should.

The output is a ranked list of exposures with an owner and a fix for each, not a risk-register spreadsheet nobody reads. Score each item by likelihood and blast radius, then fix in that order.

The checklist: data handling

Start where the loss is irreversible — data that leaves the building.

  • Inventory which AI tools receive company data, and whether they train on it.
  • Confirm sensitive data classes (customer PII, source code, financials) are blocked from unsanctioned tools.
  • Check whether data entered into AI tools flows through corporate or personal accounts.
  • Verify retention: how long does each tool keep what your team sends it?

The checklist: access and identity

This is where most assessments find their biggest gap. If AI acts with a shared superuser token instead of the user's own scoped identity, you have no attribution and no containment.

  • Confirm AI tools and agents act under the user's identity, inheriting that user's permissions — not a shared service account.
  • Find and revoke stale OAuth grants and API keys connected to AI services.
  • Verify that revoking a user's access also revokes the AI's access on their behalf.
  • Check that privileged or destructive actions require confirmation, not silent execution.

The checklist: AI-specific security and oversight

The last two areas cover threats unique to AI systems and the human gate that catches what automation misses.

  • Assess exposure to prompt injection where AI reads untrusted content (emails, web pages, documents).
  • Confirm every action an agent takes is logged with enough context to answer who, what, when, and on whose authority.
  • Verify a human approves AI-generated changes before they reach production or customers.
  • Check that AI outputs feeding decisions are reviewed, not trusted blindly.

Turn the checklist into a plan

Scoring the checklist gives you a ranked exposure list. The fix pattern is consistent across almost every organization: establish identity-scoped access, turn on audit logging, and put a review gate in front of anything AI ships. Those three controls close the majority of the risk.

If you want this run as a scoped engagement with a report and roadmap, it is part of the AI readiness audit — see /services/ai-readiness-audit, or the overview at /guides/ai-readiness-audit.

Frequently asked questions

How is an AI risk assessment different from an AI readiness audit?

The risk assessment is one dimension of the broader readiness audit. The audit scores six dimensions (strategy, data, infrastructure and security, talent, governance, and use-case ROI); the risk assessment goes deep on the security and governance exposure specifically. If your main concern is risk, start there.

What is the single most common gap an AI risk assessment finds?

Ungoverned access: AI tools and agents acting under shared tokens or personal accounts instead of the user's own identity-scoped permissions. It means no attribution when something goes wrong and no clean way to contain it. It is almost always the first thing to fix.

Who should own an AI risk assessment?

It is a shared effort between engineering, security, and leadership, but one person should own the resulting action list. The assessment is only useful if each ranked exposure has a named owner and a fix, rather than sitting in a register nobody acts on.

Related guides

Governed AI engineering, in your inbox

Occasional, practical notes for engineering leaders on putting AI to work without losing control. No spam; unsubscribe anytime.

Subscribe

Your first call with Jen is free. Here’s what you’ll walk away with.

Book your free call