
François B. Arthanas
Founder of CyberProsAI | Agentic AI Governance Advisor | CISSP, CISA, AAIA
Most first AI risk assessments read like an opinion. A list of concerns, no evidence behind them, no clause to point at, and nothing anyone can act on.
Four things separate an assessment from an opinion:
Every risk carries a real-world precedent, so it reads as a forecast rather than a hunch
Every rating carries a written rationale, so it survives being challenged
Every control maps to a named clause, so it can be audited
Every recommendation has an owner and a date, so something actually moves
This kit gives you the structure for all four plus a completed example showing what it looks like when it's done properly.
Three files. Two are editable, so you can fill them in and use them on a real system.
1. AI Risk Assessment Template (Word, editable)
Nine pages, seven sections: system profile, regulatory scope, risk identification, rating against a 5×5 matrix, control design, formal finding, executive summary. Fill-in fields throughout type straight into it in Word or Google Docs. Aligned to NIST AI RMF 1.0, ISO/IEC 42001:2023 and the EU AI Act. Includes an autonomy and scope-of-action section for agentic systems: what it can do without asking, which actions are irreversible, and where the stop is.
2. Worked Example (PDF)
The same template completed end to end on a high-risk system: a third-party résumé screening tool that auto-rejects roughly 14,700 candidates a quarter with no human review. Five risks, each with a precedent. Ratings with the reasoning written out. Controls mapped to named articles and Annex A controls. One formal finding, and an executive summary a CHRO could actually act on. This is the one to copy the shape of.
3. Workshop Workbook (Word, editable)
Eleven pages: a bridge assessment for where you're starting from, a job posting decoder for reading AI governance roles like an insider, the full assessment to build yourself, and a 90-day plan.
- Security, audit, privacy, compliance and risk professionals who've been handed an AI system and told to assess it
- GRC people moving into AI governance who need a portfolio artifact that holds up in an interview
- Anyone who has to explain an AI system to leadership, legal or a regulator and needs the work to survive the room
You don't need a technical background. You need to be willing to understand how a system uses data, makes decisions and takes action.
Not for you if you're after a theory primer. This is a working set of documents.
Free
Download an editable assessment template, a completed example on a real high-risk system, and the workshop workbook.