Craig Stanley
Home / Risk / Risk map / Mapping risk to work activities

Mapping risk to work activities

A grid that places risks against the activities a role performs, so you can see where AI changes the risk and who should own it.

· 3 min read · Craig Stanley
In short, explained

Draw a grid. Down the side, write the jobs a person does. Across the top, write the kinds of trouble. Tick where trouble could happen. Now you can see where to look first.

A risk map is a grid with work activities down the side and risk types across the top. Each cell asks whether AI changes the risk for that activity. It shows clusters, gaps and the right owner much faster than a long list does.

Cross work activities (from O*NET, ESCO or your own task list) with the five risk types and the AI capability in use. Mark each cell as new risk, changed risk or unchanged. Owners follow the activity's process owner; clusters indicate where a control can cover several cells at once.

Why a map as well as a register

A register is a list, which is good for tracking. A map is a grid, which is good for seeing patterns. I use both. The register comes from decisions, as in Start a risk register from the decision inventory. The map comes from work activities: the things a role does all day, whether or not they involve a clear decision.

Activities matter because AI tools are often introduced activity by activity. Someone starts using Copilot to draft letters, or summarise meetings, or search policy. Each of those changes risk somewhere, even if no formal decision changes.

How the grid works

Down the side, list the role's main work activities. O*NET and ESCO are good sources, or use the team's own task list. Across the top, use the five risk types: data, decision, people, supplier and cost.

In each cell, write one of three marks.

MarkMeaning
NAI adds a new risk to this activity
CAI changes an existing risk, making it larger or smaller
blankNo meaningful change

Then add a column for which AI capability is involved, such as Copilot Chat, a SharePoint agent or a Copilot Studio agent. The same activity can carry different risks depending on the tool.

A worked example

This role and its markings are illustrative. An HR adviser's main activities:

ActivityToolDataDecisionPeopleSupplierCost
Answer policy questions from managersSharePoint agentCCN
Draft letters for formal processesMicrosoft 365 CopilotNCC
Summarise case notes before a hearingMicrosoft 365 CopilotNNC
Analyse absence dataCopilot in ExcelCC
Book training for staffNone

Three things stand out. Data risk is new or changed in four of five activities, because Copilot can reach whatever the adviser can open. Decision risk clusters around formal processes, where summaries and letters shape outcomes for an individual. And cost appears only for the SharePoint agent, because managers without a Copilot licence would use it on pay-as-you-go.

Reading the map

Look for columns. A column full of marks suggests one control could cover many cells. Here, a review of the adviser's access before rollout addresses most of the data column at once.

Look for rows. A row with marks in three or more columns is usually the activity to pilot carefully, with a named reviewer. Here, that's case note summaries.

Look for empty columns. If supplier is blank for every activity, either the risk is genuinely low or nobody has thought about what happens when the tool or model changes. I'd ask which.

Who owns each cell

I give ownership by row, to the person responsible for the activity, with specialist help by column. The HR lead owns the case summary row. The data protection officer helps across the data column. That keeps one accountable person per activity without making a specialist responsible for work they don't do.

Where I got stuck

The trap I keep running into on paper is too many activities, until every cell gets a mark and nothing stands out. My working limit is about ten activities per role. If a role has more, I group them, then split only the rows that light up.

Sources

This article describes my own method and uses no external facts or figures. Activity lists can come from O*NET OnLine or the European Commission's ESCO classification, covered in the Work section.

Read next

A question to take awayWho gets told, and how fast, when a decision model starts drifting?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry (formerly Azure AI Foundry) work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

I write this site to learn in public: explaining each idea simply is how I check I understand it. Why I write this site.

Find me