Tier 1: Foundation controls
AI system risk classification
A formal method for categorizing AI systems by risk level, so controls, approvals, and obligations match the impact of the use case.
Board-defensible evidence
- Risk taxonomy and written criteria defining tiers (prohibited, high-risk, limited-risk, minimal-risk) and the specific triggers that move a system into each category, including jurisdictional mappings where applicable.
- Classification decision record for each system showing who classified it, when it was classified, what evidence was reviewed (use case, data types, user population, environment), and the documented rationale for the final tier.
- Governance workflow proof showing required approvers by tier (risk, legal, compliance, security) and the timestamps of approvals, exceptions, or escalations to an AI governance committee.
- Change-control linkage showing how reclassification happens when the system changes (model updates, new features, new data sources, new deployment context), including who authorized the change and why.
- Independent challenge or second-line review evidence (risk, internal audit, or external advisor) confirming the taxonomy is applied consistently and that edge cases are handled through a documented exception process.
Why this matters
In enforcement or litigation, an inconsistent or undocumented classification process becomes evidence that the organization did not exercise credible oversight over AI risk.
How ready is your board on foundation controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.