Skip to content

Sheet 04

Risk triage

Every request gets the same eight questions. The answers decide which of three pathways it takes, and the result shows its work — the question, the answer given, and why that answer matters. No score, no weighting, nothing a requester cannot argue with.

What this model is and is not

This is a demonstration triage model built to show how classification can be made explainable. It is not a legal determination, a compliance assessment, or a production risk-scoring system. In a real organization the questions and thresholds would be written with Risk, Legal, Privacy, Security, and HR, and reviewed on a schedule.

The three pathways

One queue makes every request wait at the speed of the most complicated one. Three pathways, each with a published timeline and a published set of expectations, means a requester knows the cost of their request before they submit it.

Standard enablement

Get out of the way. These requests are answered with guidance, not review — the goal is same-week resolution.

Target timeline
Answered in the weekly triage, typically within five business days
Typical examples
  • Summarizing nonsensitive internal material
  • Drafting internal content and correspondence
  • Brainstorming, outlining, and rewriting for clarity
  • Using an approved tool in the way it was already approved for, with human review
Required reviewers
  • AI Program Manager confirms the pathway
  • No functional review required
Required documentation
  • Register entry
  • Link to the relevant quick reference or guidance page
Human oversight expected
  • The person using the output is accountable for it
  • Nothing is shared externally without the author reading it first
Decisions available to the reviewers
  • Proceed with existing guidance
  • Proceed and add a quick reference if the question recurs
  • Reclassify upward if an answer changes

2 of the ten sample use cases are classified here.

Structured review

One coordinated review with the two or three functions that actually have a stake, held on a scheduled date rather than routed through separate queues.

Target timeline
Two to three weeks from complete submission to decision
Typical examples
  • Workflow integrations with existing business systems
  • Confidential firm or client information in scope
  • External or client-facing content
  • A new vendor or a tool outside its approved scope
  • Material operational decisions informed by the output
Required reviewers
  • Information Security
  • Risk, Legal & Privacy where client or contractual terms apply
  • Data & Reporting where a document collection or data source is in scope
  • Business owner
Required documentation
  • Completed use-case record
  • Vendor evaluation worksheet if the tool is new
  • Human-oversight plan
  • Pilot measurement plan with a baseline
Human oversight expected
  • Named reviewer on every output that leaves the firm
  • Defined sampling or full-review expectation, written down rather than assumed
  • Errors and corrections logged during the pilot, not just at the end
Decisions available to the reviewers
  • Approve for pilot
  • Approve with conditions
  • Reduce scope
  • Return for more information
  • Decline

5 of the ten sample use cases are classified here.

Elevated review

Slow down on purpose. These use cases can affect people's livelihoods, rights, safety, money, or the firm's professional standing, and the review has to be able to withstand scrutiny later.

Target timeline
Four to six weeks, longer if the evidence a reviewer needs does not exist yet
Typical examples
  • Employment decisions, recruiting, evaluation, or workforce impact
  • Sensitive personal data or regulated information
  • Autonomous or semi-autonomous action in a business system of record
  • Consequential decisions about individuals or clients
  • High-impact public output attributed to the firm or a licensed professional
Required reviewers
  • AI Governance Committee
  • Risk, Legal & Privacy
  • Information Security
  • People & Culture where employment is in scope
  • Business owner and the functional owner of the affected process
Required documentation
  • Completed use-case record with the affected population described
  • Vendor evaluation worksheet including any fairness or validation evidence the vendor can produce
  • Human-oversight plan naming who reviews what, how often, and with what authority to override
  • Measurement plan covering harm indicators, not only benefits
  • Decision record capturing alternatives considered and rejected
Human oversight expected
  • A named person makes every consequential determination; the tool never decides
  • Reviewers can see and override the tool's contribution, and know they are expected to
  • Monitoring for disparate effects on affected groups, reviewed on a defined schedule
  • A written stop condition and someone with authority to invoke it
Decisions available to the reviewers
  • Approve with conditions
  • Approve a reduced scope that removes the consequential element
  • Defer pending specific evidence
  • Decline

3 of the ten sample use cases are classified here.

The nine published questions

These are published on purpose. A requester who thinks a classification is wrong needs a specific rule to point at, and a program that cannot explain a decision in one sentence does not understand it well enough to defend it. Rules are read together, not in order — the highest pathway any rule raises is the one that applies.

  1. R-01

    Does this use case affect employment or other decisions about individuals?

    Raises the request to Elevated review

    Decisions about people carry consequences that are hard to reverse and hard to explain after the fact. These need People & Culture and Risk in the room before anything is built.

  2. R-02

    Is sensitive personal or regulated data involved?

    Raises the request to Elevated review

    Sensitive and regulated data brings obligations that belong to Risk, Legal, and Privacy, not to the requesting team or the program.

  3. R-03

    Will the tool take action in a business system rather than only suggest?

    Raises the request to Elevated review

    Suggestion errors get caught by a person. Action errors get caught by whoever finds them later, in a system of record.

  4. R-04

    Is human review proposed for every output?

    Raises the request to Elevated review

    Sampled or absent review can be appropriate for low-consequence work, but combined with action-taking or people-affecting use, it removes the last check.

  5. R-05

    Will output be public-facing or client-facing?

    Raises the request to Structured review

    Errors that leave the firm cost more to correct than errors caught internally, and they attach to the firm's professional reputation.

  6. R-06

    Is confidential firm or client information in scope?

    Raises the request to Structured review

    Client agreements vary, and confidential material needs a check on where it is processed and who else could see it.

  7. R-07

    Is the tool new, unreviewed, or being used outside its approved scope?

    Raises the request to Structured review

    An approval covers a specific tool doing a specific thing with specific data. Outside that, the earlier review does not apply.

  8. R-08

    Is the intended rollout firmwide?

    Raises the request to Structured review

    Firmwide scope multiplies small problems and usually means training, support, and a license commitment that Finance needs visibility into.

  9. R-09

    Is the tool approved with conditions that this use case has to satisfy?

    Raises the request to Structured review

    Conditions exist for a reason. Somebody has to confirm this use case meets them rather than assuming it does.

Try it

Answer the eight questions and the model classifies the request in front of you, listing every rule that fired and the answer that fired it. The three presets load answers from records that appear elsewhere on this site, so you can check that the published model produces the classifications the register already shows.

Answer the eight questions

These are the same answers the intake form collects. Change any of them and the pathway updates immediately.

Load a request from the register

Each preset loads the answers behind a record shown elsewhere on this site.

  • UC-002
  • UC-001
  • UC-004

Classify by the most sensitive item in scope, not the typical one.

Describe what is actually planned, not what would be ideal.

An approval covers a specific tool doing a specific thing with specific data.

Intended rollout, not the pilot population.

Check every statement that is true

Anything that leaves the firm, including a draft sent to a client.

Hiring, evaluation, promotion, discipline, or comparable determinations.

Personal data about identifiable people, or data under a specific obligation.

Posting, sending, filing, or updating a system of record without a person doing it.

Result

Standard enablement

No rule raised this request above the standard pathway.

Why it landed here

None of the nine published questions raised this request. It stays in standard enablement: answered with guidance, no functional review required. If an answer changes later, so does the pathway.

What this pathway requires

Get out of the way. These requests are answered with guidance, not review — the goal is same-week resolution.

Target timeline
Answered in the weekly triage, typically within five business days
Typical examples
  • Summarizing nonsensitive internal material
  • Drafting internal content and correspondence
  • Brainstorming, outlining, and rewriting for clarity
  • Using an approved tool in the way it was already approved for, with human review
Required reviewers
  • AI Program Manager confirms the pathway
  • No functional review required
Required documentation
  • Register entry
  • Link to the relevant quick reference or guidance page
Human oversight expected
  • The person using the output is accountable for it
  • Nothing is shared externally without the author reading it first
Decisions available to the reviewers
  • Proceed with existing guidance
  • Proceed and add a quick reference if the question recurs
  • Reclassify upward if an answer changes

Final policy, legal, privacy, security, budget, and risk decisions belong to their authorized owners. The AI Program Manager coordinates the work, prepares the material, and tracks the outcome — the program manager does not approve on their behalf.

The same eight questions drive the intake workspace, where a submitted request is classified and recorded.

Who decides

Final policy, legal, privacy, security, budget, and risk decisions belong to their authorized owners. The AI Program Manager coordinates the work, prepares the material, and tracks the outcome — the program manager does not approve on their behalf.

Triage assigns a pathway. It does not approve anything. The pathway determines who has to be in the room and what has to be written down before the people with the authority to approve make their decision.

See the responsibility matrix and the forums where decisions are made