Classify every AI system before deployment using the four-tier triage matrix below. Risk classification determines the required governance controls. Re-assess whenever a system's use case, data inputs, or operational context changes materially.
Risk Classification Framework
| Risk Level | Criteria | Examples | Required Response |
| Unacceptable | Potential for serious, irreversible harm; no meaningful human oversight possible; violates privacy or human rights | Autonomous safety-critical decisions with no override; covert surveillance; biometric profiling without consent | Do not deploy. Escalate to Board for explicit decision and documented justification if proceeding. |
| High | Significant harm potential; affects employment, safety, financial outcomes, or vulnerable groups | AI-assisted fatigue management; automated pre-qualification of subcontractors; AI used in injury investigation | Full SIA required. Enhanced human oversight. Mandatory pre-deployment testing. Quarterly monitoring. |
| Medium | Moderate harm potential; affects operational decisions; limited direct impact on individuals | AI-assisted estimating; document classification; AI-generated scheduling recommendations | Standard SIA required. Human review of all outputs. Monthly monitoring. Annual audit. |
| Low | Minimal harm potential; limited operational impact; no direct effect on individuals | Spell-check and grammar tools; basic search and retrieval; image classification for asset management | Register in AI Register. Baseline monitoring. Annual review. |
AI System Triage Register
| System Name | Use Case | Risk Classification | Assessment Date | Assessed By | Approved By | Next Review |
| [System name] | [Brief description] | High | [DD/MM/YYYY] | [Name] | [Name] | [DD/MM/YYYY] |
| | | | | | | |
| | | | | | | |