AIGP Study Guide
Module 3: Governance & Risk Management · BoK III.A

Calculating risk

The working Risk formula is probability × severity. High → avoid or change; medium → explore and mitigate. Plus the four technical assessment categories and the EU risk pyramid's four tiers.

The process

Determine who needs to be involved (business + technical stakeholders) → understand business purposes and planned usesenumerate potential harms incl. false positives, false negatives and numeric over- and under-predictions → assess the training data description incl. sensitive data → check whether the AI has been benchmarked against established alternative approaches. Then the formula → probability of the harm × potential (severity) of it happening. Result highavoid or change the AI to prevent the harm. Result mediumexplore and mitigate the risks.

  • Intended task → what will it achieve
  • Function & performance metrics
  • Robustness → scalable, withstands more or less use
  • Transparency → workings and intended consequences
Fairness is at the core

All assessment criteria sum to one question → is the AI outcome ultimately fair?

The EU risk pyramid
TierWhat it means
Unacceptable riskBanned → social credit scoring, real-time remote facial recognition in public spaces
High riskHarms safety or fundamental rights → mandatory requirements apply
Limited riskOnly transparency requirements prescribed
Minimal riskNo mandatory requirements → voluntary industry standards

Risk assessment is context-specific → context comes from five places → owner and operator · industry and use case · social impacts · timing · jurisdiction. Tailoring the framework to context strengthens governance and enables informed, values-aligned decisions.

Practitioner voice

"Risk assessment of AI is both an art and a science." - Vivienne Artz

Exam flash

Memorise the actions → high risk = avoid or change, medium risk = explore and mitigate. And the unacceptable-tier bans → social credit scoring and real-time remote facial recognition in public spaces.

Key terms - quick answers

What is “Risk formula”?
Probability of the harm × potential (severity) of it happening.
What is “EU risk pyramid”?
Four tiers, unacceptable (banned), high (mandatory requirements), limited (transparency), minimal (voluntary).
What is “Unacceptable risk”?
Banned AI uses such as social credit scoring and real-time remote facial recognition in public spaces.