Things can go wrong in five ways. The information is wrong, the choice is wrong, people get hurt or confused, the company you buy from changes things, or it costs too much.
Most AI risks at work fit into five groups: data, decisions, people, suppliers and cost. Sorting risks this way helps you spot gaps and give each one an owner who knows that area.
Classify AI risks as data, decision, people, supplier or cost. Assign owners by type (data owner, process owner, line manager, commercial lead, budget holder) and pair each risk with a preventive control and a detective nudge.
Data
The model sees information it shouldn't, or works from information that's wrong or stale.
- Example: an agent grounded on SharePoint surfaces a salary file because permissions were too broad.
- First control: review permissions on the sites the model can reach before you switch it on.
Decision
The model gives a wrong answer and someone acts on it.
- Example: a triage model routes an urgent complaint to a low-priority queue.
- First control: a threshold and a hard stop for categories that always go to a person.
People
The way people work changes in ways nobody chose.
- Example: staff stop checking model output because it's usually right, and lose the skill to spot when it isn't.
- First control: sample automated decisions for human review every week, and rotate who does it.
Supplier
The vendor changes the price, the terms, the model or the product.
- Example: a model version is retired and its replacement scores cases differently.
- First control: keep a test set of past cases and re-run it whenever the model changes.
Cost
Spending drifts beyond the budget.
- Example: a looping agent burns through a month's consumption allowance in a weekend.
- First control: daily spend alerts and a hard cap per agent. See the Cost section.
Using the five types
Go through your decision-based register and tag each row with one or more types. If one type has no rows at all, that's usually a gap rather than good news.