Map risks to concrete failure scenarios
Course overview · 4 min reading + 12 min practice, estimated
Principles and method
A risk statement should name what can go wrong, who is affected and how harm occurs. Consider inaccurate evidence, exclusion, privacy, security, inaccessible participation and overreliance. Assess likelihood and severity with uncertainty, then choose controls that address the mechanism. A policy saying use responsibly is not a control unless it changes behaviour. Track residual risk and who accepts it within their authority. The NIST framework offers a voluntary organising structure; it is not a compliance certificate. Use case-specific tests and specialist review where the consequences require them.
Worked example
A summariser omits career context and makes a candidate appear less experienced. Controls include source-linked claims, reviewer access to originals and sampling for omission, not just a spelling check.
Put it into practice
Write five risks for one fictional use case, each with a control and verification method.
Use fictional information and keep your work in your own notes.
Compare your approach: self-review guidance
Each control should have an owner and observable evidence. Include one risk caused by human overreliance rather than model error alone. State unresolved risks instead of declaring the system risk-free.
Sources and further reading
Original Academy teaching and fictional examples. These references provide context, not endorsement. Edition 2026.09; updated 2026-09-24.
- GOV.UK: Responsible AI in recruitment
UK guidance on procuring and deploying recruitment AI.
- NIST: AI Risk Management Framework
Voluntary framework for organising AI risks and controls.
- European Commission: AI regulatory framework
Check the current rules, scope and implementation dates for EU operations.