AI Risk Assessment Template
AI Risk Assessment Template
Branch/Unit
Consultation: Legal
ICT
Governance
and Risk
Other
Branch/Unit
Approved? Yes No
Reasons:
Name Date:
Yes. The decisions The use-case can proceed with appropriate ongoing
include low risk factors controls and monitoring. Pilot the use-case first.
e.g. AI generates insights
or alerts for operational
human use with minimal
potential for harm.
No. Relies on historical The use-case can proceed, but you need to review
data. However, outputs your risk treatments and make sure there are
may generate insights sufficient controls in place.
for non-operational
human use from non-
sensitive data.
No. Relies on historical The use-case can proceed with appropriate ongoing
data for reporting or controls and monitoring.
informing purposes only.
Comments
Please include your overall assessment of the general benefits and the rationale for your assessment.
Comments
Please include your overall assessment of the general risk and the rationale for your assessment.
Physical harms
Unfair Treatment
Unintended identification or
misidentification of an individual
Inconvenience or delay
Other harms
Comments
Please include your overall assessment of the risks and the rationale for your assessment.
Yes, but You must have Legal, Governance and Risk Branch
it’s better advice that allows this use-case to proceed.
than Consult with Chief Executive Board. Consider a Human
existing Rights Impact Assessment.
systems
Yes, but it’s You must have Legal, Governance and Risk Branch
better than advice that allows this use-case to proceed.
existing Consult with Chief Executive Board. Consider a Human
systems Rights Impact Assessment.
Yes, but it’s You must have Legal, Governance and Risk Branch
better than advice that allows this use-case to proceed.
existing Consult with Chief Executive Board. Consider a Human
systems Rights Impact Assessment.
Consider the risks associated with: Insignificant Minor Moderate Major Severe
Comments
Please include your overall assessment of the risks and the rationale for your assessment.
It’s better
Document your reasons. You should clearly demonstrate
than
that you have consulted with Legal, Governance and Risk
existing
Branch and Chief Executive Board before proceeding.
systems
Not
entirely, but You should clearly demonstrate that you have consulted
it’s better with Legal, Governance and Risk Branch and Chief
than Executive Board before proceeding to pilot phase.
existing Consider a Human Rights Impact Assessment
systems
Not
entirely, but You should clearly demonstrate that you have consulted
it’s better with Legal, Governance and Risk Branch and Chief
than Executive Board before proceeding to pilot phase.
existing Consider a Human Rights Impact Assessment
systems
Do you use sensitive data, including Identifiable Identifiable Identifiable High Identifiable
information on: cohort >50 cohort cohort Identifiable cohort <5
>20 and >10 and cohort
or N/A
<50 <20 >5 and <10
Children
Religious individuals
Comments
Please include your overall assessment of the risks and the rationale for your assessment.
16. Have you applied the “Privacy by Design” and “Security by Design” principles in your use-case?
Comments:
20. Does your dataset include using sensitive data subjects as described by section 19 of the NSW Privacy and Personal Information
Protection Act 1998?
Comments:
Comments
Please include your overall assessment of the risks and the rationale for your assessment.
Transparency – Consultation
You must consult with the relevant community when designing an AI system. This is particularly important for operational AI systems.
Communities have the right to influence government decision-making where those decisions, and the data on which they are based, will have an
impact on them.
For use-cases intended to operate under legislation which allows use without community consultation, the public benefits must be clear before
proceeding to pilot phase.
21. Have you consulted with the relevant community that will benefit from (or be impacted by) the use-case?
Comments:
No, but it's Document your reasons. You should clearly demonstrate
better that you have consulted with Legal, Governance and Risk
than Branch and Chief Executive Board before proceeding to
existing pilot phase.
systems
2 A Community Engagement Plan should demonstrate: objectives and planned outcomes, how the public can question and seek reviews of AI-based decision, how the community can get
insights into data use and methodology, how the community will be informed of changes to an AI solution, including where existing technology is adapted for another purpose. Source:
https://www.digital.nsw.gov.au/policy/artificial-intelligence/artificial-intelligence-ethics-policy/mandatory-ethical-principles
No, but a Consult with Legal, Governance and Risk Branch and
person Chief Executive Board and establish a process to
makes the readily reverse any decision or action made by the
final use-case. Actively monitor for potential harms during
decision pilot phase.
Comments
Please include your overall assessment of the risks and the rationale for your assessment.
Accountability – Responsibilities
25. Have you established who is responsible for:
– use of the AI insights and decisions
– policy/outcomes associated with the use-case
– monitoring the performance of the use-case
– data governance?
Comments:
Procurement
27. If you are procuring all or part of a use-case, have you satisfied the above requirements for:
– transparency
– privacy and security
– fairness
– accountability
As defined in the NSW AI Assurance Framework?
Comments:
AI should deliver the best outcome for the citizen, and key Use of AI will include safeguards to manage data bias or data
insights into decision making. quality risks, following best practice and Australian Standards.
AI will include the highest levels of assurance. Ensure use-cases Review mechanisms will ensure citizens can question and
adhere to PPIPA. challenge AI based outcomes. Ensure use-case adhere to GIPA
Act.
Accountability
Highest risk
No. of Risks
Does the overall risk assessment indicate the use-case involving AI (or other form of automated decision-making technology) can be
implemented?
Comments: