Document and manage AI risk.
Per-system risk assessments your organisation can stand behind, kept current as the portfolio evolves.
Why structured risk records matter
For APRA-regulated entities, AI risk sits inside CPS 230 operational risk obligations and, where information is involved, CPS 234 information security obligations. For other organisations, the trigger is often a board-level AI governance directive, peer-group benchmarking, internal audit scope or a material AI deployment that has just gone live.
A spreadsheet someone updates once a year is not a risk record. A solid record captures classification, structured risk items, controls, residual position and the trail of how the assessment was reached. It updates when the system changes, and it surfaces missing controls rather than papering over them.
Catalogue the systems requiring assessment
The system list comes straight from your AI Register. When a new system enters the register, a notification surfaces suggesting it for assessment. Existing systems can be assessed in the order that matches your priorities, typically starting with the most material.
Classify each system by impact and AI involvement
The classification uses the NSW AI Assessment Framework levels, with Level 4 indicating significant impact on individuals and substantial AI involvement, ranging down through to Level 1. Aicura proposes a level based on what is captured in the register and provides a plain-English summary of the system. You confirm, adjust or push back as the actual implementation requires.
Document structured risk items per system
The structured risk items get populated for each system. False positive risk, false negative risk, bias risk, model drift, prompt injection, data leakage and any others relevant to the system type. Each carries severity, suggested controls and a residual risk position. The AI6 practice statements get populated for each of the six CSIRO Essential Practices, with wording you can edit where your specific implementation differs.
Review the narrative and sign off
Aicura assembles a narrative summary from the structured content. You review and edit it for executive accuracy. The approval workflow takes the assessment through review, capturing who signed off and when. The assessment is now versioned and signed.
Re-assess on change and at periodic review
Material changes to a system, such as a new model, a new data source or an expanded scenario, surface a notification suggesting the system for re-assessment. You decide when to run it. Periodic review keeps the residual risk position current even when the system has not materially changed. The dashboard shows the risk distribution across the portfolio at a glance.
Once the first portfolio pass is complete, risk assessment is a continuous activity. New systems surface for assessment when they enter the register. Material changes prompt re-assessment notifications. You decide what to run. Periodic review keeps the residual position current. When the General Manager Risk, the internal auditor, the board or APRA wants detail on a system, the assessment is there, structured and signed off, with the trail of how the position was reached.
Frequently asked questions
What should an AI risk assessment record capture?
A solid record captures the system's classification, structured risk items, the controls in place and the residual position, along with the trail of how the assessment was reached. It updates when the system changes and surfaces missing controls rather than papering over them. A spreadsheet someone updates once a year is not a risk record.
Do APRA-regulated entities have specific AI risk obligations?
For APRA-regulated entities, AI risk sits inside CPS 230 operational risk obligations and, where information is involved, CPS 234 information security obligations. For other organisations the trigger is more often a board-level AI governance directive, internal audit scope or a material AI deployment going live. In both cases the record needs to stand up when the General Manager Risk, the internal auditor or the regulator asks for detail on a system.
How do risk assessments stay current as systems change?
New systems surface for assessment when they enter the AI Register, and material changes prompt re-assessment notifications. You decide what to run. Periodic review keeps the residual position current rather than frozen at the first portfolio pass.
Start the work in Aicura
Aicura supports this work from the register that anchors it through to the documents and records it produces, with your people reviewing and approving everything along the way. It is guidance, not certification, audit or legal advice.