← All FAQs
AI

What is an AI risk assessment?

An AI risk assessment is a structured review identifying how artificial intelligence tools are currently being used across your business (often far more extensively than leadership realises), what data is being exposed to them, and what specific risks, POPIA compliance gaps, confidentiality breaches, model reliability issues, that usage creates.

Why "Discovery" Is Usually the Genuine Starting Surprise

Most businesses significantly underestimate how much AI tool usage is already happening internally, staff adopting tools individually, without any formal decision or IT visibility. A proper AI risk assessment starts with genuine discovery, understanding actual current usage, not assuming it away or starting from a theoretical "what if we introduced AI" position when the reality is AI is very likely already in active use today.

What a Structured Assessment Actually Covers

  • Tool inventory, which AI tools are staff actually using, official and unofficial, and on what account tiers (free consumer versus paid business tiers with different data handling terms)
  • Data flow mapping, what categories of data are being entered into these tools, client personal information, confidential business data, credentials
  • Third-party terms review, understanding each tool's actual data handling and processing terms, not assuming favourable terms without verification
  • Compliance gap identification, specifically flagging where current usage creates POPIA exposure or breaches existing confidentiality obligations
  • Technical risk review, for businesses building AI into their own products or processes, assessing risks like model drift, hallucination, and prompt-injection vulnerabilities relevant to that specific implementation

Output: A Prioritised, Actionable Picture

A genuinely useful assessment doesn't end with just a list of risks, it produces a prioritised set of findings, distinguishing urgent gaps needing immediate attention from lower-priority items that can be addressed as part of an ongoing governance cadence, giving leadership a clear, realistic roadmap rather than an overwhelming, undifferentiated list.

Who Should Actually Commission One

Any business where staff have adopted AI tools organically, which today describes the large majority of businesses regardless of whether there's been a formal decision to "adopt AI", benefits from understanding its actual current exposure. This is particularly urgent for businesses handling significant client personal information or operating under specific regulatory or contractual confidentiality obligations.

How Long This Typically Takes

An initial discovery and risk snapshot for a typical SME can usually be completed within around 10 business days, fast enough to give genuine, actionable visibility without becoming its own prolonged, disruptive project.

What Happens After the Assessment

The assessment findings directly inform the next steps, building an acceptable-use policy addressing the specific gaps identified, technical controls where appropriate, and staff training grounded in your business's actual situation rather than generic, abstract AI risk education.

Our Approach

The discovery and AI risk snapshot is the first phase of our GovernAI framework specifically because building policy before understanding actual current usage produces guesswork, not genuine governance. We deliver this as a concrete, time-bound engagement with a clear, prioritised output your leadership can act on immediately.