Report
Assessing an AI system's risk, no PhD required: six steps
Key takeaways
- Sixteen questions with a file, executable by a committee in days — no consultants.
- Assessment is per risk, not per system: the system inherits its worst residual risk.
- Critical does not deploy; high is conditioned on prior verification.
- "We don't know" is a valid answer — and it is a risk.
- The summary is published in the register: secret assessments protect less and get captured more.
Every framework demands risk assessment and almost none says how to do it with a real public agency's teams. Sixteen questions born from the failure case files — and two non-negotiable rules.
The full document is currently published in Spanish; an English edition is prepared when demand warrants it. The Spanish record carries the complete summary and contents.