Who is accountable, and what can go wrong

Each AI system is classified, scored on the dimensions that matter to a regulated business and given an accountable owner. The tier decides which controls apply and how often the system is reviewed.

Northwind Mutual ⌄Console › Risk › Risk assessments › Underwriting risk summariserSearch ⌘KProductionModelPolling

Underwriting risk summariser

Serving endpoint on Databricks. Discovered 12 Aug 2026, registered 14 Aug 2026.

High riskReassessApprove for production
OverviewRiskControls 6Cyber 2Evidence 11RuntimeHistory

Risk dimensions

Scored 1 to 5
Data sensitivity5
Autonomy2
Can act externally1
Financial impact4
Customer impact4
Critical system access3

Tier rule: any of data, financial or customer at 4 or more makes the asset High.

Inherent and residual risk

InherentResidual
5432112345

Likelihood (rows) by impact (columns). Residual moves to 3 by 3 once two open controls are evidenced.

Accountability

Accountable exec
Chief Underwriting Officer
FAR function
Underwriting
Business owner
S. Okafor
Technical owner
Data Platform
Lifecycle
Pilot, 40% of policies
Next review
14 Dec 2026
Controls
4 of 6

History

  • Tier raised to High3 Sep 2026, S. Okafor
  • Assessment completed20 Aug 2026, Risk team
  • Discovered on Databricks12 Aug 2026, connector

Controls required for a High tier asset

4 of 6 in place
Evidenced OR-12 Change control for models
Evidenced CPS 234 data classification
Implemented OR-21 Incident escalation
Implemented Output review by underwriter
OR-07 Provider due diligence
Not started Bias testing on declined quotes
Risk dimensions

A tier you can explain to a regulator

Six dimensions, scored one to five, with a written rule for the tier. Inherent and residual risk sit on one matrix, so the effect of each control is visible.

DimensionWhat it asks
Data sensitivityDoes the system touch personal, financial or health information?
AutonomyDoes it recommend, decide with review, or act on its own?
External actionsCan it send, pay, change records or contact customers?
Financial impactWhat is the cost of a wrong output or action?
Customer impactCould a customer be treated unfairly or harmed?
Critical system accessDoes it reach systems that support critical operations?

Classification, impact and accountability

Risk work produces records that later controls and evidence depend on, so it is kept with the AI system rather than in a separate spreadsheet.

  • Classification against regulatory categories, such as EU AI Act risk tiers
  • Impact assessments recorded with the system they cover
  • Accountable executive and FAR key function per system
  • Review dates that follow the tier
Copilot

Reassessment when things change

When a release changes what an agent can do, the copilot reads the change record, release notes and decision receipts, proposes score changes with their sources and shows the controls that would follow. Scores change only when a person confirms.

Northwind Mutual ⌄Console › Risk › Risk assessments › Underwriting risk summariserSearch ⌘KCopilotProductionModelPolling

Underwriting risk summariser

Serving endpoint on Databricks. Version 2.3 released 28 Sep 2026.

High riskHistory
OverviewRiskControls 6Cyber 2Evidence 11Runtime

Risk dimensions

2 proposed changes
Data sensitivity5
Autonomy23
2 → 3 Approves quotes under $5k without review since v2.3
External actions12
1 → 2 Can now email brokers (tool added 28 Sep, change CR-4471)
Financial impact4
Customer impact4
Critical system access3

What changed in v2.3

  • MediumNew tool: send email to broker
  • HighAuto-approve quotes under $5,000
  • LowModel upgraded, same provider

Controls

4 of 6 in place
Evidenced OR-12 Change control for models
OR-07 Provider due diligence
OR-15 Human approval above threshold
CopilotRisk · Underwriting risk summariser×
Working onReassess Underwriting risk summariser after v2.3
  1. Read change CR-4471 and the v2.3 release notes
  2. Compared tool access before and after
  3. Checked 1,204 decision receipts from 30 days
  4. 2 score changes need your confirmation
  5. Update required controls for the new scores
Needs your approval
Raise autonomy from 2 to 3Source: v2.3 release notes · 412 auto-approvals

Tier stays High. Adds control OR-15, human approval above threshold.

ConfirmEditSkip
✓Confirmed by Alex Morgan · version 7 saved
Raise external actions from 1 to 2Source: CR-4471 · email tool added

Adds a tool permission review and an outbound email control.

ConfirmEditSkip
Scores change only when a person confirms. Every change is versioned.
Ask why, or point at a dimension↵

Let's connect

Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.