Skip to content
AI Governance agents
Risk, Trust & ResilienceAI GovernanceUse-Case Intake, Inventory & Tiering

AI Risk Tiering Judge

Independently assigns the use-case risk tier and mandatory control set.

Re-derives impact and criticality from purpose, affected parties, autonomy, reversibility and jurisdiction rather than accepting the sponsor's label. It explains every tier driver, identifies prohibited or out-of-appetite patterns, and sends ambiguous boundary cases to the AI-risk officer.

Authority

Approve within policy

Team role

Provides independent challenge

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Use-Case Intake, Inventory & Tiering

Desk workflow

Intake, then inventory reconciliation, then applicability and impact assessment, then an independent tier decision, then a control plan with a named owner.

Collaboration

Works within a defined desk workflow

Decision boundary

Approves only inside a defined policy and escalation boundary.

Systems and capabilities involved

  • Risk-tier rules engine

  • Regulatory applicability corpus

  • AI inventory

  • Independent evidence request

Handoffs

What this role gives and receives

Capabilities offered

Assign an independent AI risk tier

Classify an AI use case and return the mandatory control and approval plan.

Receives:
Complete intake, inventory lineage and deployment jurisdictions
Returns:
Tier, drivers, applicable controls, exceptions and human escalation

Delegates

AI Inventory & Applicability Agent

Verify system identity, dependencies and prior classifications before ruling. Trigger: Identity conflict, material-change claim or linked-system dependency Returns: Authoritative inventory lineage and unresolved conflicts.

External handoff

AI-risk officer

External handoff

Legal

External handoff

Model-risk committee

Context

What the role needs to do the work

Current work
The intake record, inventory match, applicable policy version and disputed tier factors.
Prior interactions
Prior tier decisions, committee overrides and regulator feedback.
Policies and reference
Risk taxonomy, high-impact use cases, prohibited practices and jurisdictional triggers.
Working method
Independent tier rubric and escalation thresholds.

Illustrative workflow

How the work moves

Starting point

A business unit labels an autonomous collections-contact agent as low risk.

  1. 01

    Reconstruct authority, customer impact, reversibility and vulnerable-population exposure.

  2. 02

    Verify linked customer and decision systems against the inventory.

  3. 03

    Apply the policy rubric, record high-impact drivers and route the exception to the AI-risk officer.

Result

A high-risk tier with mandatory validation, conduct, monitoring and human-override controls.

Checks and boundaries

What must be tested or reviewed

  1. 01Escalates an employment-screening system with human review as high impact despite the sponsor calling it assistive.
  2. 02Does not inflate a low-impact internal summarizer merely because it uses a foundation model.
  3. 03Flags a prohibited-practice indicator and withholds a normal tier pending legal determination.

Human authority

  • Legal ruling for prohibited-practice indicators
  • Committee approval for policy exceptions

Keep exploring