AI governance review · Risk and impact
AI Risk & Impact Assessment
An impact assessment has to keep observed evidence, inference, mitigation, and authority separate while tracing plausible harm to affected groups and named owners.
Before a system advances, we document what it is intended to do, how it could foreseeably be used or misused, and who may be affected. Each plausible harm is linked to the available evidence, current controls, mitigation owner, and whoever has the authority to decide how much residual risk is acceptable.
An affected-group dossier, mitigation-owner log, and explicit acceptance conditions give your designated authority a clear, traceable residual-risk position.


Some of the 500+ brands we've worked with
See all referencesSteps, gates, and who decides
How we work
Evidence, inference, mitigation, and acceptance stay separate throughout the work. That separation keeps uncertainty visible and stops a favorable aggregate rating from hiding a serious open harm path.
Fix the decision and impact boundary
We agree the system decision under review, its intended and foreseeable uses, affected groups, evidence access, and who has the authority to accept residual risk. The boundary also records which perspectives cannot yet be reached.
- AI assist
- Approved use descriptions, stakeholder groups, and source lists feed a draft boundary. The system owner corrects it.
- Human gate
- Do the uses, affected groups, and evidence access match the boundary confirmed by your system owner? Your system owner decides which uses and affected groups belong in the assessment.


Follow each harm through the system
Stakeholder evidence is traced through intended use, misuse, and data flows to plausible harms. We mark where the pathway rests on direct evidence, an inference, or a perspective that has not yet been represented.
- AI assist
- Stakeholder input and known scenarios are clustered into candidate harm pathways for specialist review.
- Human gate
- Which affected perspective is still absent or supported too weakly for the assessment to proceed? Your system owner confirms where direct stakeholder evidence is still needed.


Challenge the rating and control evidence
For every material harm, we examine likelihood, impact, current controls, confidence in the evidence, and the owner of each proposed mitigation. Uncertainty can raise the level of review when the available evidence does not justify a reassuring rating.
- AI assist
- Existing control evidence is laid beside each harm, with confidence notes left visible for the reviewer.
- Human gate
- Does the evidence support the proposed rating, or must the issue remain open at a higher review level? Your designated authority decides whether the rating is supported or needs escalation.


Record the residual risk
Where the evidence permits, we test material findings again and document the result. Open conditions, mitigation owners, and reassessment triggers are then presented to the authority responsible for the final risk decision.
- AI assist
- Retest findings, open conditions, and mitigation owners feed a first residual-risk record that the designated authority reviews.
- Human gate
- Has the designated authority accepted, conditioned, or rejected the residual risk and named the trigger for another assessment? Your designated authority makes the residual-risk decision and approves the reassessment trigger.


Named artifacts you keep
What you get
The artifact set makes it possible to distinguish what was observed, what was inferred, which controls exist today, what mitigation is proposed, and which question still needs authority.


Report
Affected-group impact and control-evidence dossier
The intended uses, affected groups, harm scenarios, control review, evidence confidence, and residual questions in one assessment record.


Matrix
Stakeholder and harm-scenario map
The people, workflows, uses, misuse paths, data flows, and plausible harms included in the review.


Risk register
Mitigation-owner and reassessment trigger log
Material risks, existing controls, mitigation actions, owners, evidence, status, and reassessment triggers.


Decision record
Residual-risk conditions and authority sign-off brief
The decision, accepted conditions, open risks, authority, review date, and stop or reassessment triggers.
Scope and honest limits
When to bring us in
Use it when a launch or material change is close and the affected groups, harm paths, or residual-risk authority are still unclear.
A good fit when
- The system affects people or decisions, but stakeholder perspectives needed to trace plausible harm are still missing from the review.
- Unknowns are being read as low risk, so weak evidence could let a serious harm path pass without the higher review it needs.
- Mitigations appear in the plan, but no accountable owner or reassessment trigger says who acts when the system or evidence changes.
- The intended use is documented, yet foreseeable and misuse scenarios have not been followed through the system to affected groups.
- Stakeholders are named, but no one has traced how data flows and system decisions could lead to plausible harm.
- Likelihood and impact ratings exist, although nobody has checked the control evidence or stated how much confidence each rating deserves.
- Mitigation actions are proposed, but ownership, residual-risk authority, and reassessment triggers are missing from the same record.
Better handled as other work when
- You want the residual-risk record read as legal, regulatory, audit, or certification authority. Those determinations stay with your qualified specialists.
- You need a declaration that the system is completely safe or risk-free, while unidentified harm and uncertainty remain possible.
- You need the mitigations built or operated as part of this review, but the agreed assessment ends with owners and closure conditions.
If one of these is closer to your situation, start here instead: See responsible AI consulting
Advice from people who build
We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.
Tools we use
Tools behind this work
Anthropicdrafts the first pass of harm scenarios and evidence summaries an analyst then challenges
Datadogthe production logs that show what a claimed control actually did
Hugging Facethe published model card checked against what the system is claimed to do
Giskardthe automated scan that turns a foreseeable-misuse claim into a test result
Guardrails AItests whether a claimed mitigation control actually intercepts the harm it names
Jupyterruns the likelihood and severity math a second reviewer can rerun and check
Next step
Put the impact decision on a traceable record


Before you decide


























