ActiveHub

Illustrative example — not client work

AI Risk & Controls Review Example

See how ActiveHub can assess proposed AI uses individually, identify the controls each use requires and distinguish acceptable uses from situations where the business should not proceed.

Download Example PDFPDF · A4 · 399 KB

Executive recommendation

Can these proposed AI uses proceed?

The answer is different for each use.

Some uses involve limited information, straightforward human review and low consequences if an output is imperfect.

Others involve confidential information, important decisions or consequences that require significantly stronger controls.

Two proposed uses should not proceed in their current form.

The assessment therefore does not recommend either:

  • unrestricted AI use; or
  • a blanket prohibition on AI.

It recommends different decisions according to the use.

Five proposed uses, five decisions

The ratings below are qualitative decision aids. They are not claims of mathematical precision.

Control intensity

  1. Proceed with standard controls
  2. Proceed with controls
  3. Proceed with additional controls
  4. Do not proceed
Proposed useInformation sensitivityConsequence of errorHuman reviewSupplier/data concernOverall recommendation
Use 1Routine internal draftingLowLowStraightforwardLow if approved tool usedProceed with standard controls
Use 2Client meeting summariesMediumMediumRequiredMediumProceed with additional controls
Use 3Internal knowledge searchMediumMediumRequired for important useMediumProceed with controls
Use 4Highly sensitive files in unapproved public AIHighHighDoes not resolve data-handling concernHighDo not proceed
Use 5Automated professional recommendationsMedium–HighHighAbsent in proposed useMediumDo not proceed

Interpretation

Risk does not increase simply because more AI is involved.

It increases when factors such as these combine:

  • sensitive information
  • weak supplier controls
  • limited verification
  • significant consequences
  • absent human responsibility

A comparatively sophisticated AI use may be acceptable in one controlled context.

A simple use may be unacceptable if it involves information or decisions that should not be handled that way.

A use that can proceed: Use 1

Use 1

Routine internal drafting

Proceed with standard controls

Proposed use

Employees use an approved AI tool to prepare first drafts of routine internal material using non-sensitive information.

Examples could include:

  • agenda drafts
  • internal administrative summaries
  • meeting preparation notes
  • wording for routine internal communications

Business value

The use may:

  • reduce repetitive drafting
  • help employees structure information
  • speed up routine administrative work

Information involved

The proposed use does not require:

  • confidential client files
  • sensitive personal information
  • commercially restricted material

Principal risks

Incorrect or invented content

The tool may produce statements that were not present in the source information.

Over-reliance

Employees may accept generated wording without checking it.

Scope creep

A low-risk use can gradually expand into employees entering more sensitive information unless boundaries are clear.

Existing controls required

  • use an approved account/tool
  • restrict the use to information permitted by business policy
  • require the employee to review the output
  • do not treat generated content as authoritative merely because it is well written

Recommendation

Proceed with standard controls

This is a proportionate use where:

  • information sensitivity is low
  • consequences of error are limited
  • human review is easy

The control burden should remain proportionate.

Do not create an approval process so heavy that the administrative control costs more than the risk it addresses.

A use that should not proceed: Use 4

Use 4

Highly sensitive client files in an unapproved public AI service

Do not proceed

Principal risks

Unknown or unsuitable data handling

The business has not established whether:

  • the service is appropriate for this information
  • submitted data is retained
  • data may be reused
  • administrators or subprocessors may have access
  • appropriate contractual protections exist

Confidentiality

Uploading the material may conflict with obligations the business owes to the client.

Loss of control

Once highly sensitive information is submitted to an unsuitable service, the business may have limited ability to reverse the disclosure.

Employee-created supplier decision

An individual employee would effectively be choosing a new information-processing service without the business evaluating the implications.

Human review does not solve the central risk

Even perfect human review of the generated output would not resolve the risk created by sending highly sensitive information to an unapproved service.

Recommendation

Do not proceed

The use should not be permitted in the proposed form.

The issue is not that highly sensitive information can never be processed using AI.

The issue is that the proposed service and data-handling arrangement have not been established as appropriate for the information.

Possible future route

If there is a strong business case, the business may separately assess whether an approved service can support the use under appropriate contractual, security, privacy, confidentiality, access and retention controls.

That would be a different proposal requiring its own assessment.

Same tool, different risk

The risk assessment should focus on the use rather than assigning one universal risk level to a technology.

Imagine the same approved AI service being used for two tasks.

  • Use A · Lower-risk use
  • Use B · Higher-risk use
Use ALower-risk useUse BHigher-risk use
Use and purpose
Draft an internal meeting agenda using:
  • public information
  • non-sensitive internal notes
Analyse highly confidential client records and produce a recommendation that could materially affect the client.
Information sensitivityLow.High.
Potential consequence of errorLimited.High.
Human reviewEasy.Essential.
Supplier/data requirementsSignificant.
Likely decisionProceed with standard controlsRequires substantially stronger controls and may not be acceptable depending on the service and proposed process

The decision also depends on:

  • why it is being used
  • what information is involved
  • who receives the output
  • what happens if the output is wrong
  • whether a person remains responsible
  • how the supplier handles the information

Therefore:

“Approved AI tool” does not mean “approved for every use”.

Practical control framework

The business does not need a large governance bureaucracy to establish useful controls. It needs a small number of clear rules employees can actually follow.

  1. Control 1

    Approved tools and accounts

    Define which services and account types employees may use for business information.

    Employees should not treat public availability as business approval.

  2. Control 2

    Information rules

    Define categories such as:

    • information that may be used
    • information that requires an approved controlled environment
    • information that must not be entered into certain tools

    The categories should use language employees understand.

  3. Control 3

    Human review

    Define when generated content must be reviewed before:

    • external use
    • decision-making
    • inclusion in formal records
    • reliance on important facts
  4. Control 4

    Verification

    Require important facts, calculations, quotations, sources, actions and recommendations to be checked where errors could matter.

  5. Control 5

    Access

    AI-enabled systems should not expand access beyond what employees reasonably need.

  6. Control 6

    Supplier/data review

    Perform proportionate review before allowing a service to process information where confidentiality, privacy or security materially matters.

  7. Control 7

    Prohibited uses

    Define a short list of uses the business does not permit.

    Examples from this assessment include:

    • highly sensitive client information in unapproved public AI services
    • automatically issued professional recommendations without responsible human review
  8. Control 8

    Responsibility

    Employees should understand that:

    Using AI does not transfer responsibility for the business decision to the tool.

  9. Control 9

    Escalation

    Provide a simple route for employees to ask:

    “Can I use this tool for this information and this purpose?”

    when the situation does not fit the standard rules.

What should be prohibited?

The business should avoid a long list of theoretical prohibitions employees cannot remember.

A short list of clear boundaries is more useful.

Based on this assessment:

Prohibited

Unapproved handling of highly sensitive information

Do not place highly sensitive client or business information into an AI service that has not been approved for that use.

Prohibited

Unreviewed professional recommendations

Do not automatically issue professional recommendations to clients without responsible human review.

Prohibited

Intentional permission bypass

Do not use AI search or summarisation to obtain information the employee is not authorised to access.

Prohibited

Pretending generated content is verified

Do not represent generated facts, quotations, summaries or recommendations as checked when they have not been checked.

Prohibited

Uncontrolled experimentation with client information

Do not use real confidential client information merely to test an unfamiliar AI service.

Use non-sensitive test material until the service and use have been appropriately assessed.

Recommended immediate decision

Need a practical view of AI risk in your business?

This example shows one way an AI risk review can be presented. The scope, controls and depth of a real assessment depend on the proposed use, the information involved and the consequences if something goes wrong.