Report

Assessing an AI system's risk, no PhD required: six steps

An engineer in a hard hat holding a clipboard.

Key takeaways

  • Sixteen questions with a file, executable by a committee in days — no consultants.
  • Assessment is per risk, not per system: the system inherits its worst residual risk.
  • Critical does not deploy; high is conditioned on prior verification.
  • "We don't know" is a valid answer — and it is a risk.
  • The summary is published in the register: secret assessments protect less and get captured more.

Every framework demands risk assessment and almost none says how to do it with a real public agency's teams. Sixteen questions born from the failure case files — and two non-negotiable rules.

The full document is currently published in Spanish; an English edition is prepared when demand warrants it. The Spanish record carries the complete summary and contents.