AI Risk Tiering Criteria

AI risk tiering assigns a system a level of scrutiny based on what happens when it is wrong, rather than on which technology it uses. The four tests are who is affected, whether the effect reaches rights, safety, eligibility or livelihood, whether the person can appeal, and whether the effect is reversible.

Tiering schemes built around technology age badly, because every wave of capability needs a new rulebook, and they reach the wrong conclusion: a rules engine that denies a claim deserves more scrutiny than a language model that drafts meeting notes.

The template

TierTestRequirement
4. CriticalAffects rights, safety, eligibility, or livelihood. Effect hard to reverse.Full review, named accountable owner at director level, pre-agreed stopping condition, quarterly review
3. SignificantAffects individuals materially but with appeal and correction routes.Full review, semi-annual review cycle
2. OperationalAffects internal process efficiency. Errors visible and correctable in workflow.Light review, annual cycle, self-attestation against checklist
1. AssistiveDrafting, summarising, search. Human reviews every output before use.Registration only, no gate

How to use it

  • Assign the tier from the consequence of a wrong output, not from whether the system uses machine learning, generative models, or ordinary rules.
  • Apply the four tests in order: who is affected, whether rights or eligibility are touched, whether an appeal route exists, and whether the effect can be reversed.
  • Record the tier in the model register, and let it drive review frequency and control requirements rather than sitting as a label.
  • Re-tier when the use changes. A system promoted from drafting to deciding has changed tier even if the model has not changed at all.

Common questions

How do you tier AI risk?

Tier on consequence rather than technology. Ask who is affected when the system is wrong, whether the effect reaches rights, safety, eligibility or livelihood, whether the person can appeal, and whether the effect is reversible. Tier 4 is critical, affecting rights or livelihood with effects hard to reverse, and requires full review, a director-level accountable owner, a pre-agreed stopping condition, and quarterly review.

Why tier AI risk by consequence rather than by technology?

Because technology-based schemes need a new rulebook for each wave of capability and produce the wrong answer. A deterministic rules engine that denies a benefit claim carries more consequence than a language model drafting meeting notes, but a technology-based scheme would scrutinise the language model more heavily.