AI risk assessment

What could go wrong with the AI you already use?

Pick one way your business uses AI today. Fourteen questions later you get a risk band, the dimension that needs attention first, and a straight answer on whether to carry on, fix something first, or stop.

Free

No email needed to see your result.

About five minutes

Fourteen questions, on one use case.

One at a time

Assess as many as you like. The pattern across them is the useful part.

Assess one use case

Step 1 of 15

Which use of AI do you want to assess?

One at a time. Pick the one you rely on most, or the one you are least sure about.

What actually goes into it?
Which account does that go through?
Has anyone decided what the tool keeps, or trains on?
What can it reach?
Can it change anything, or only read?
Who in the business can use it?
What does the output affect?
What happens before that output gets used?
Would you know if it were wrong?
Who owns this particular use of AI?
Are there written rules for it, and does the team know them?
Does anyone check it is still doing what it should?
Does it influence a decision about a person?
Does anything restrict how you may use AI on this work?

Nothing is sent anywhere until you choose to send it.

The short answer

Assessing AI risk means taking one thing you already do with AI and asking four questions about it: what data it touches, what it can reach, what its output affects, and who owns it. A fifth question matters in Australia from December 2026: whether it influences a decision about a person. Most businesses have never done this for any of their use cases, which is not negligence. It is that nobody handed them a way to.

This does it for one use case, free, in about five minutes. No email needed to see the result. It reports exposure, not compliance, and it is not legal advice.

Governance, risk, compliance, security: four different things

These get used as though they mean the same thing, and a business that asks for one and is handed another has bought a quarter of what it needed.

Governance

The rules of the game. How AI should be used here, who decides, and whether we should be doing this at all.

Risk

What happens if something goes wrong. How likely, how bad, and what we would do about it. This page is here.

Compliance

Whether you are following the rules that actually apply to you: the law, your contracts, your clients' conditions.

Security

Whether the systems are protected. Necessary, and on its own it answers none of the three above.

This page does the second one. Whether a business your size needs formal governance at all is worked through in do Australian businesses still need AI governance, and if what you actually need is the rules written down, there is a plain-English AI use policy you can copy.

What the assessment measures

Four of them come from a risk framework taught in the Innovating with AI programme, by a certified chief information security officer. The fifth is ours, because Australia has a date on it.

Data

What the use case touches, how sensitive it is, and where it could end up. The most common cause and the cheapest to fix.

Access

What systems it can reach, whether it only reads or can also act, and who is able to use it.

Decision impact

What the output influences, what a wrong answer costs, and whether anyone would notice.

Governance

Who owns it, what rules exist, and whether anyone is still watching it. Usually the least comfortable question in the room.

Regulatory exposure

Whether it touches a decision about a person, and whether a contract or a client condition already restricts what you may do.

From 10 December 2026

Why one of these questions is about a date

Australian Privacy Principle 1.7 starts on 10 December 2026, and the part businesses get wrong is the width of it. It reaches a program doing something substantially and directly related to making a decision, which includes one recommending or guiding a decision a person then makes. Having a human review the output is not an exemption.It is not limited to AI either: a rule-based system is captured the same way.

Whether it reaches your business is a separate question, and the answer is less obvious than the turnover threshold suggests. That, and what governance is actually worth doing at your size, is worked through properly here.

Do Australian businesses still need AI governance

Which check do you actually want?

There are two on this site and they answer different questions. This one is about exposure from something you already do. The other is about whether the business can get value from AI at all: direction, workflows, people, trust and whether buyers find you when they ask an AI.

If you have not started with AI yet, take that one first. If AI is already in use and nobody has looked at it properly, you are in the right place.

The AI Readiness Score

Questions we get asked

How long does the AI risk assessment take?

Fourteen questions about one use case, roughly five minutes. Your result appears on screen as soon as you finish, and you do not need to leave an email to see it.

What is the difference between AI governance, risk, compliance and security?

They get used interchangeably and they are four different things. Governance is the rules of the game: how AI should be used here, and whether we should do this at all. Risk is what happens if something goes wrong. Compliance is whether you are following the rules that apply to you. Security is whether the systems are protected. A business that asks for AI governance and is handed a security solution has bought one quarter of what it needed.

Why does it assess one use case instead of the whole business?

Because risk is not a property of a business, it is a property of a particular thing that business does. Summarising internal meetings and screening job applicants carry completely different exposure even inside the same company with the same policy. Assess the use cases you actually rely on, one at a time. If you want the business-level picture instead, that is the AI Readiness Score.

Does a human reviewing the output make it safe?

It helps, and it is not the exemption people assume it is. Australian Privacy Principle 1.7 reaches a system that is substantially and directly related to making a decision, and that includes one guiding or recommending a decision a person then makes, so having someone check the output does not put the system outside it. Whether the obligation applies to your business is a separate question that turns on whether you are an APP entity and whether personal information is involved. If AI touches decisions about people in your business, that is worth establishing before 10 December 2026.

Is a risk assessment the same as AI risk management?

No. An assessment is a snapshot of one use case on one day. AI risk management is the ongoing part: someone owning each use, rules people have actually read, and a review that happens on a schedule rather than after something goes wrong. Those are three of the questions here, which is why governance scores badly for most businesses on their first run. The assessment tells you where you stand. Managing it is what you do next.

Is this legal advice?

No, and it is not a compliance assessment either. It reports exposure so you can have a better conversation with whoever advises you. Where the result points at a legal or contractual question, the right next step is your own legal or compliance advice, not a webpage.

What happens to my answers?

Your result is yours. If you leave an email, I use your answers to write you something specific about your situation. Answers are also used anonymously to understand where Australian businesses are exposed, and that anonymised picture may be published. The privacy page has the detail.

What if the result says not yet?

It means one or two specific things need to be true before that use case is safe to widen, not that AI is wrong for you. The result names them. Most are small: moving people onto business accounts, deciding who owns the thing, putting a human approval step in front of anything that leaves the business.

Get started

Assessed it, and now you want it fixed?

Book a discovery call and bring the result. We will tell you which parts are a half-day of work and which need someone else entirely.

AI Readiness Score

Before you go, how ready is your business for AI?

Twelve questions, three minutes, scored on the spot. No email needed to see your result.

Score your business