BookmarkSubscribeRSS Feed

Risk Assessment and Classification Guide

Started Monday by
Modified Monday by
Views 37

Risk and classification

SAS® AI Navigator Risk Assessment and Classification Guide

A four-step method for rating a use case and mapping it to a policy classification

Overview

This guide walks through a repeatable way to assess the risk of an AI use case and translate that rating into a SAS AI Navigator policy classification. Work the four steps in order: rate the potential for harm, rate the likelihood of impact, read the overall risk level off the matrix, then map that level to a classification type.

The levels and matrix shown here are an example. Organizations are encouraged to use their own terminology, granularity, and thresholds. What matters is that whatever scheme you use maps cleanly onto the three fixed classification types in SAS AI Navigator.

Jump to a section

The four steps

1.  Identify Potential for Harm

2.  Identify Likelihood of Impact

3.  Map Harm and Likelihood on the Risk Matrix

4.  Map Risk Levels to Policy Classifications

Reference

The three classification types

Risk matrix

1

Identify Potential for Harm  Back to top ↑

Determine the potential for harm that could result internally and externally from the failure, misuse or unintended behavior of an AI system.

Agent-specific assessment

For AI systems capable of taking actions, consider the scope of system and tool access; the scale of affected systems, records, transactions, and stakeholders; the number and type of actions that may be executed; the potential for actions to propagate; the availability of human review; and whether resulting actions can be stopped or reversed.

Level

Internal Organizational Harm

Operational, financial, legal, compliance, cybersecurity, and reputational impacts

External Stakeholder Harm

Impacts to customers, employees, individuals, partners, and other affected stakeholders

Severe

  • Potential for major or sustained disruption to critical business operations, including failure of mission critical systems or services
  • Large-scale exposure, alteration, deletion or unauthorized transmission of sensitive or regulated information
  • Unauthorized or irreversible actions, including actions across connected systems or workflows, with significant financial, legal, security, compliance, or reputational consequences
  • Compounding failures that propagate across systems, workflows, or AI agents before detection or intervention

Example: For an extended period, an AI-enabled loan decision system applies an unauthorized decision rule across multiple lending products without detection, resulting in widespread incorrect approvals and denials, inaccurate regulatory records, significant exposure, and extensive remediation.

  • Potential for widespread, irreversible, or life-altering harm to individuals or affected groups
  • Systematic denial of critical services, benefits, opportunities, employment, healthcare, financial products, or other consequential resources
  • Permanent exposure or misuse of highly sensitive personal information affecting a substantial number of individuals
  • Unauthorized or erroneous AI actions that produce widespread consequences before they can be stopped, corrected or reversed

Example: An AI-enabled loan decision system systematically denies qualified applicants access to mortgages and provides inaccurate reasons for the denials, affecting a substantial number of people before detection and causing financial and housing opportunities that cannot be fully restored.

Major

  • Potential for substantial or prolonged disruption to important operations, services, or workflows
  • Significant financial loss, resource burden, data exposure, compliance failure, or damage to organizational reputation
  • Unauthorized AI actions affecting multiple systems, records, transactions, or external communications
  • Requires extensive manual intervention, coordinated remediation, or formal external review

Example: An AI agent incorrectly modifies numerous customer account records and initiates erroneous transactions across connected systems, requiring a coordinated investigation, account restoration, customer notification, and significant remediation.

  • Potential for significant financial, privacy, fairness, safety, or access-related harm affecting a group
  • Inaccurate, biased, or unauthorized decisions or actions that materially affect access to services, employment, benefits, or other opportunities
  • Substantial intervention required to identify affected individuals, halt further impacts, and correct outcomes
  • Significant loss of stakeholder trust or potential legal or regulatory action

Example: Erroneous transactions initiated by an AI agent result in incorrect charges or account balances for numerous customers, causing significant financial hardship until the organization reverses the transactions and restores the affected accounts.

Moderate

  • Noticeable but temporary disruption, inefficiency, or service degradation
  • Moderate financial, resource, compliance, security, or reputational impact
  • Limited incorrect or unauthorized actions that require human intervention or temporary workarounds to correct

Example: An AI agent incorrectly routes a batch of loan applications for additional review, causing temporary processing delays and requiring employees to identify and reprocess the affected applications using manual procedures.

  • Inaccurate, unclear, or unfair outcomes causing temporary inconvenience or limited harm
  • Incorrect AI-generated actions or communications affecting a limited number of stakeholders
  • Impact is reversible but requires human intervention to correct outcomes and restore normal service

Example: The routing error delays loan decisions for a limited number of applicants, requiring them to provide additional information or wait longer for a decision, but the applications are reprocessed without lasting financial harm.

Minor

  • Limited operational error, inefficiency, or incorrect action that is quickly corrected through normal processes
  • Minimal financial, compliance, security, or reputational impact

Example: An AI assistant routes several credit card service requests to the wrong internal queue, but employees promptly identify and redirect them through normal processes without disrupting customer service.

  • Limited inconvenience or minor error affecting few individuals, with no material or lasting harm
  • Incorrect output, communication, or action is easily identified, reversed, and corrected

Example: The routing error causes brief delay in responding to a small number of customers, but the requests are redirected and resolved without financial loss or other repercussions.

Scoring rule

The overall Potential for Harm is the higher level of the two potentials for harm (e.g. if internal organizational harm is Major but external stakeholder harm is Minor, the overall is still Major). If the impact falls between two levels, select the higher level and document the reasoning.

Record your result

Potential for Internal Organizational Harm:  __________________________

Potential for External Organizational Harm:  __________________________

Overall Potential for Harm:  __________________________

2

Identify Likelihood of Impact  Back to top ↑

Evaluate the likelihood that the harmful scenario will occur during the AI system’s intended use. Consider factors such as the system’s expected frequency and scale of use, complexity, degree of autonomy, reliance on human review, performance under expected operating conditions, and evidence from testing or similar systems.

Assess before mitigations

Assess likelihood before planned controls or mitigations are applied. If the likelihood falls between two levels or evidence is limited, select the higher likelihood. Often, this risk is categorized as low, medium, or high, but any system that will work best for a business is acceptable. A more granular, 4-level scheme is shown here.

Likelihood

Definition

Examples

Rare

The harmful outcome is highly exceptional and would require multiple independent failures, extraordinary conditions, or use substantially outside the intended operating context. There is no relevant occurrence in testing or available operational evidence.

An informational banking assistant with read-only access could initiate an unauthorized transaction only if separate identity, permission, tool-access, and approval conditions all failed or were bypassed.

Unlikely

The harmful outcome is not expected during normal use or operations but could occur under unusual conditions, through an uncommon combination of failures, or when safeguards do not operate as intended.

A banking assistant could provide an incorrect credit card payment date if an uncommon account configuration is combined with outdated source information, but validation checks and employee review would ordinarily identify the discrepancy quickly.

Possible

The harmful outcome could occur under normal or foreseeable conditions but is not expected routinely. The system has relevant limitations or dependencies, and existing evidence shows a credible path to the outcome.

An AI agent can update customer records across connected systems. Testing showcases occasional errors when records contain conflicting information, but human review generally detects the errors before transactions are initiated.

Likely

The harmful outcome is expected to occur during normal or reasonably foreseeable use. The system operates frequently or at scale, and known limitations, prior incidents, testing results, limited oversight, or autonomous actions make recurrence probable.

Testing reveals that an AI-loan processing agent regularly misclassifies a recurring type of application documentation. Since the agent processes a high volume of applications with limited human review, incorrect routing and delayed decisions are expected during normal use.

Record your result

Likelihood of Impact Result:  __________________________

3

Map Potential for Harm and Likelihood on the Risk Matrix  Back to top ↑

Determine the overall risk level by locating the intersection of the Overall Potential for Harm identified in Step 1 and the Likelihood of Impact identified in Step 2. Your matrix might be a 3x3 or other configuration appropriate for your organization.

 

Potential for Harm

Likelihood of Impact

Minor

Moderate

Major

Severe

Likely

Medium

High

Very High

Very High

Possible

Medium

High

High

Very High

Unlikely

Low

Medium

High

High

Rare

Low

Low

Medium

High

Risk level key

Low
Medium
High
Very High

 

Record your result

Overall Risk Level:  __________________________

4

Map Organizational Risk Levels to AI Navigator Policy Classifications  Back to top ↑

Organizations are encouraged to use their own terminology and methodology to classify AI risk. In SAS AI Navigator, organization-defined classification options map to one of the three fixed classification types:

The three classification types

standard-risk: Use cases may be deployed with appropriate governance documentation.

high-risk: The highest-risk classification that still permits deployment and represents the organization’s risk tolerance ceiling.

prohibited: Use cases with this classification cannot be deployed under any circumstances.

The mapping drives alert severity in AI Navigator and supports consistent comparison across policies that may use different risk terminology. The mapping below is an example of how an organization’s four-level risk framework could map to the three SAS AI Navigator classification types.

Risk Level

Example AI Navigator Mapping and Governance Approach

Very High

prohibited: The use case exceeds the organization’s risk tolerance and is not permitted for deployment under the applicable policy.

  • Document the classification decision and its rationale. Reconsider the classification only if the use case is materially redesigned or the conditions that produced the Very High rating change.
  • Complete a new risk assessment before reconsidering deployment.

High

high-risk: The use case is at the organization’s risk tolerance ceiling but remains eligible for deployment.

  • Apply enhanced governance review and obtain documented approval from the organization’s designated decision authority before deployment.
  • Supporting materials may include a risk mitigation plan, testing and validation evidence, policies for high-risk use cases, human-oversight procedures, monitoring requirements, incident-response procedures, and reassessment triggers.

Medium

standard-risk: The use case may be deployed through the organization’s standard governance process with appropriate documentation and safeguards in place.

  • Document the intended use, accountable owner, relevant data and system access, testing results, safeguards, monitoring expectations, and conditions requiring reassessment.

Low

standard-risk: The use case may be deployed through a streamlined version of the organization’s standard governance process.

  • Maintain basic documentation, accountable ownership, standard operational controls, and routine monitoring. Reassess the classification if the use case or its risk profile materially changes.

 

Contributors
Version history
Last update:
Monday
Updated by:

CFC_SAS_Communities_400x225.jpg

Call for content now open!

It's your turn to help shape SAS Innovate 2027. Share your expertise and inspire the SAS community.

Submit your proposal →

Article Tags