Digital asset

The AI Risk Assessment Kit: Template, Worked Example & Workbook

François B. Arthanas

François B. Arthanas

Founder of CyberProsAI | Agentic AI Governance Advisor | CISSP, CISA, AAIA

See all products from François B. Arthanas

You have been asked to assess an AI system. Now what?

Most first AI risk assessments read like an opinion. A list of concerns, no evidence behind them, no clause to point at, and nothing anyone can act on.

Four things separate an assessment from an opinion:

  • Every risk carries a real-world precedent, so it reads as a forecast rather than a hunch

  • Every rating carries a written rationale, so it survives being challenged

  • Every control maps to a named clause, so it can be audited

  • Every recommendation has an owner and a date, so something actually moves

This kit gives you the structure for all four plus a completed example showing what it looks like when it's done properly.

What's in the kit

Three files. Two are editable, so you can fill them in and use them on a real system.

1. AI Risk Assessment Template (Word, editable)

Nine pages, seven sections: system profile, regulatory scope, risk identification, rating against a 5×5 matrix, control design, formal finding, executive summary. Fill-in fields throughout type straight into it in Word or Google Docs. Aligned to NIST AI RMF 1.0, ISO/IEC 42001:2023 and the EU AI Act. Includes an autonomy and scope-of-action section for agentic systems: what it can do without asking, which actions are irreversible, and where the stop is.

2. Worked Example (PDF)

The same template completed end to end on a high-risk system: a third-party résumé screening tool that auto-rejects roughly 14,700 candidates a quarter with no human review. Five risks, each with a precedent. Ratings with the reasoning written out. Controls mapped to named articles and Annex A controls. One formal finding, and an executive summary a CHRO could actually act on. This is the one to copy the shape of.

3. Workshop Workbook (Word, editable)

Eleven pages: a bridge assessment for where you're starting from, a job posting decoder for reading AI governance roles like an insider, the full assessment to build yourself, and a 90-day plan.

Who this is for

- Security, audit, privacy, compliance and risk professionals who've been handed an AI system and told to assess it

- GRC people moving into AI governance who need a portfolio artifact that holds up in an interview

- Anyone who has to explain an AI system to leadership, legal or a regulator and needs the work to survive the room

You don't need a technical background. You need to be willing to understand how a system uses data, makes decisions and takes action.

Not for you if you're after a theory primer. This is a working set of documents.

Free

Download an editable assessment template, a completed example on a real high-risk system, and the workshop workbook.