Craig Stanley
Home / Risk / Risk map

Data, decision, people, supplier, cost: five risk types

A simple way to group AI risks at work into five types, with examples and a first control for each.

10 October 2026 · 2 min read · Craig Stanley
In short, explained

Things can go wrong in five ways. The information is wrong, the choice is wrong, people get hurt or confused, the company you buy from changes things, or it costs too much.

Most AI risks at work fit into five groups: data, decisions, people, suppliers and cost. Sorting risks this way helps you spot gaps and give each one an owner who knows that area.

Classify AI risks as data, decision, people, supplier or cost. Assign owners by type (data owner, process owner, line manager, commercial lead, budget holder) and pair each risk with a preventive control and a detective nudge.

Data

The model sees information it shouldn't, or works from information that's wrong or stale.

  • Example: an agent grounded on SharePoint surfaces a salary file because permissions were too broad.
  • First control: review permissions on the sites the model can reach before you switch it on.

Decision

The model gives a wrong answer and someone acts on it.

  • Example: a triage model routes an urgent complaint to a low-priority queue.
  • First control: a threshold and a hard stop for categories that always go to a person.

People

The way people work changes in ways nobody chose.

  • Example: staff stop checking model output because it's usually right, and lose the skill to spot when it isn't.
  • First control: sample automated decisions for human review every week, and rotate who does it.

Supplier

The vendor changes the price, the terms, the model or the product.

  • Example: a model version is retired and its replacement scores cases differently.
  • First control: keep a test set of past cases and re-run it whenever the model changes.

Cost

Spending drifts beyond the budget.

  • Example: a looping agent burns through a month's consumption allowance in a weekend.
  • First control: daily spend alerts and a hard cap per agent. See the Cost section.

Using the five types

Go through your decision-based register and tag each row with one or more types. If one type has no rows at all, that's usually a gap rather than good news.

Read next

A question to take awayWho gets told, and how fast, when a decision model starts drifting?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Azure AI Foundry work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

Find me