Free AI Risk Assessment Template
Turn an AI use case into a documented decision. This free Excel starter helps you record the use case, owner, affected people, data, risks, controls, evidence, residual risk, approval decision and review date.
No email gate · Editable Excel workbook · Includes fictional worked examples · Published by Evidelis / Ingenii OÜ
What an AI risk assessment should help you decide
A useful assessment is not a list of generic AI concerns. It should create a reviewable record that leads to an operational decision: approve, approve with conditions, defer for evidence, escalate for specialist review, or stop.
Context
✓ What is the AI actually used for?
✓ Who owns it and who may be affected?
✓ What data and business decisions are involved?
Risk & controls
✓ What could go wrong, and how material could it be?
✓ Which controls reduce the risk?
✓ What evidence shows the controls exist?
Decision & review
✓ What risk remains after controls?
✓ Who approves or escalates the use?
✓ When must the assessment be revisited?
AI risk assessment template: recommended fields
| Field | What to record |
|---|---|
| AI system / tool | The product, model, service or internal system being used. |
| Business use case | The specific workflow, decision or activity supported by AI. |
| Accountable owner | The person responsible for the business use and its controls. |
| People affected | Employees, customers, applicants, suppliers or other groups who may be affected. |
| Data used | The information entered, accessed, generated or inferred by the AI workflow. |
| Decision / output role | Whether AI drafts, recommends, ranks, decides, acts autonomously or supports human judgement. |
| Risk statement | A concrete description of what could go wrong, for whom, and why. |
| Controls | Technical, process, contractual or human controls intended to reduce the risk. |
| Evidence | Tests, approvals, settings, records or other proof that the control is implemented. |
| Residual risk | The risk that remains after controls are applied. |
| Decision | Approve, approve with conditions, defer, escalate or stop. |
| Review date | When the assessment must be revisited, including after material changes. |
How to use the template
Assess the real business use, not just the name of the AI product.
Identify where harm, confidentiality, fairness, security or operational risk could arise.
Replace vague labels with testable statements about what could fail and who would be affected.
Document not only what should happen, but how you can demonstrate that it happens.
Estimate what remains after the controls are applied and note uncertainty.
Approve, conditionally approve, defer, escalate or stop — and name the approver.
A risk assessment is only one part of AI governance.
Once AI use starts spreading across a business, you also need visibility of AI systems and use cases, clear policy, approvals, vendor review, incident handling, human oversight, literacy evidence and recurring management review. Evidelis AI Governance connects those pieces into one operating system.
Explore Evidelis AI GovernanceFrequently asked questions
What should an AI risk assessment template include?
At minimum: the AI use case, owner, affected people, data used, decision role, key risks, controls, evidence, residual risk, approval decision and review date.
Is an AI risk assessment the same as a DPIA or model validation?
No. An AI risk assessment is a governance record. It does not replace a data protection impact assessment, model validation, security assessment, legal review or sector-specific process where one is required.
Should third-party AI tools be risk assessed?
Yes when the way the tool is used could create material business, data, security, fairness, legal, operational or reputational risk. Focus on the actual use case and controls, not only the vendor name.
Reference: NIST AI Risk Management Framework (AI RMF), a voluntary and use-case-agnostic framework for managing AI risks: NIST AI RMF. The Evidelis starter is not a NIST certification or conformance tool.