AI That Works  ·  AI6 Guidance
AI6-T03.1
Classification Matrix — Pillar 03
AI Risk Triage System
Document No.AI6-T03.1Version[1.0]
Document Owner[Name / Role]Date[DD/MM/YYYY]
Review Date[DD/MM/YYYY]Status[ Draft / In Review / Approved ]
Organisation[Organisation Name]
Classify every AI system before deployment using the four-tier triage matrix below. Risk classification determines the required governance controls. Re-assess whenever a system's use case, data inputs, or operational context changes materially.
Risk Classification Framework
Risk LevelCriteriaExamplesRequired Response
UnacceptablePotential for serious, irreversible harm; no meaningful human oversight possible; violates privacy or human rightsAutonomous safety-critical decisions with no override; covert surveillance; biometric profiling without consentDo not deploy. Escalate to Board for explicit decision and documented justification if proceeding.
HighSignificant harm potential; affects employment, safety, financial outcomes, or vulnerable groupsAI-assisted fatigue management; automated pre-qualification of subcontractors; AI used in injury investigationFull SIA required. Enhanced human oversight. Mandatory pre-deployment testing. Quarterly monitoring.
MediumModerate harm potential; affects operational decisions; limited direct impact on individualsAI-assisted estimating; document classification; AI-generated scheduling recommendationsStandard SIA required. Human review of all outputs. Monthly monitoring. Annual audit.
LowMinimal harm potential; limited operational impact; no direct effect on individualsSpell-check and grammar tools; basic search and retrieval; image classification for asset managementRegister in AI Register. Baseline monitoring. Annual review.
AI System Triage Register
System NameUse CaseRisk ClassificationAssessment DateAssessed ByApproved ByNext Review
[System name][Brief description]High[DD/MM/YYYY][Name][Name][DD/MM/YYYY]