AI Risk Tiering Criteria
Last updated: 2026-08-14
AI risk tiering assigns a system a level of scrutiny based on what happens when it is wrong, rather than on which technology it uses. The four tests are who is affected, whether the effect reaches rights, safety, eligibility or livelihood, whether the person can appeal, and whether the effect is reversible.
Tiering schemes built around technology age badly, because every wave of capability needs a new rulebook, and they reach the wrong conclusion: a rules engine that denies a claim deserves more scrutiny than a language model that drafts meeting notes.
The template
| Tier | Test | Requirement |
|---|---|---|
| 4. Critical | Affects rights, safety, eligibility, or livelihood. Effect hard to reverse. | Full review, named accountable owner at director level, pre-agreed stopping condition, quarterly review |
| 3. Significant | Affects individuals materially but with appeal and correction routes. | Full review, semi-annual review cycle |
| 2. Operational | Affects internal process efficiency. Errors visible and correctable in workflow. | Light review, annual cycle, self-attestation against checklist |
| 1. Assistive | Drafting, summarising, search. Human reviews every output before use. | Registration only, no gate |
How to use it
- Assign the tier from the consequence of a wrong output, not from whether the system uses machine learning, generative models, or ordinary rules.
- Apply the four tests in order: who is affected, whether rights or eligibility are touched, whether an appeal route exists, and whether the effect can be reversed.
- Record the tier in the model register, and let it drive review frequency and control requirements rather than sitting as a label.
- Re-tier when the use changes. A system promoted from drafting to deciding has changed tier even if the model has not changed at all.
This template comes from the AI Governance: A Practical Playbook, which sets out the reasoning behind it, the rules of thumb that govern its use, and the signals that tell you the approach is failing. The full playbook is also available as Markdown. See all AI governance templates.