Who is accountable, and what can go wrong
Each AI system is classified, scored on the dimensions that matter to a regulated business and given an accountable owner. The tier decides which controls apply and how often the system is reviewed.
Underwriting risk summariser
Serving endpoint on Databricks. Discovered 12 Aug 2026, registered 14 Aug 2026.
Risk dimensions
Scored 1 to 5Tier rule: any of data, financial or customer at 4 or more makes the asset High.
Inherent and residual risk
InherentResidualLikelihood (rows) by impact (columns). Residual moves to 3 by 3 once two open controls are evidenced.
Accountability
- Accountable exec
- Chief Underwriting Officer
- FAR function
- Underwriting
- Business owner
- S. Okafor
- Technical owner
- Data Platform
- Lifecycle
- Pilot, 40% of policies
- Next review
- 14 Dec 2026
- Controls
- 4 of 6
History
- Tier raised to High3 Sep 2026, S. Okafor
- Assessment completed20 Aug 2026, Risk team
- Discovered on Databricks12 Aug 2026, connector
Controls required for a High tier asset
4 of 6 in placeA tier you can explain to a regulator
Six dimensions, scored one to five, with a written rule for the tier. Inherent and residual risk sit on one matrix, so the effect of each control is visible.
| Dimension | What it asks |
|---|---|
| Data sensitivity | Does the system touch personal, financial or health information? |
| Autonomy | Does it recommend, decide with review, or act on its own? |
| External actions | Can it send, pay, change records or contact customers? |
| Financial impact | What is the cost of a wrong output or action? |
| Customer impact | Could a customer be treated unfairly or harmed? |
| Critical system access | Does it reach systems that support critical operations? |
Classification, impact and accountability
Risk work produces records that later controls and evidence depend on, so it is kept with the AI system rather than in a separate spreadsheet.
- Classification against regulatory categories, such as EU AI Act risk tiers
- Impact assessments recorded with the system they cover
- Accountable executive and FAR key function per system
- Review dates that follow the tier
Reassessment when things change
When a release changes what an agent can do, the copilot reads the change record, release notes and decision receipts, proposes score changes with their sources and shows the controls that would follow. Scores change only when a person confirms.
Underwriting risk summariser
Serving endpoint on Databricks. Version 2.3 released 28 Sep 2026.
Risk dimensions
2 proposed changesWhat changed in v2.3
- MediumNew tool: send email to broker
- HighAuto-approve quotes under $5,000
- LowModel upgraded, same provider
Controls
4 of 6 in place- Read change CR-4471 and the v2.3 release notes
- Compared tool access before and after
- Checked 1,204 decision receipts from 30 days
- 2 score changes need your confirmation
- Update required controls for the new scores
Tier stays High. Adds control OR-15, human approval above threshold.
Adds a tool permission review and an outbound email control.
Let's connect
Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.