← Implementer
Module 2 of 11 · 15 min
Stage 3 · Turn requirements into working governance

Risk and opportunity assessment

Build a practical AI risk process aligned with the AIMS and client objectives.

Learn

Define risk criteria, identify threats and opportunities, evaluate likelihood/impact in the client's context and assign treatment owners.

Keep regulatory classification separate from broader organisational AI risk: a system can be legally lower-risk but still create security, privacy or operational exposure.

Record residual risk and acceptance decisions so management ownership is visible.

Remember
  • •Regulatory class is not the whole risk picture.
  • •Define criteria before scoring.
  • •Residual risk needs ownership.
Client practice

Build a risk entry for an internal generative-AI assistant handling commercially sensitive documents.

Evidence you should be able to produce
AI risk registerRisk criteriaTreatment planRisk acceptance record
Source basis

Training summary based on public ISO and BSI descriptions of ISO/IEC 42001. It teaches the management-system structure and practical implementation approach without reproducing the copyrighted standard text.

← Previous moduleNext module →