Risk Classification
Initiative risk tier assignments with required controls, sign-off requirements, and outstanding control tracking. High and Critical tiers require additional gate sign-off.
1
Critical
2
High
1
Medium
11
Outstanding Controls
Risk Tier Definitions
AI Copilot Programme
Critical RiskEnterprise-wide AI programme with potential to affect employment decisions, customer-facing outputs, and regulated processes. Classified Critical due to AI output quality risk in regulated contexts, data governance gaps, and absence of a ratified Responsible AI policy.
M365 Copilot Rollout
High RiskAI tooling affecting all 900 employees with data privacy implications, job displacement anxiety, and AI output quality risk. Classified High due to employee impact scale and AI-specific risks.
Org Restructure
High RiskAffects 900 employees across all departments with role changes, reporting line changes, and redundancy risk. Classified High due to employee relations risk and regulatory employment law obligations.
ITSM Platform Migration
Medium RiskTechnology platform migration with moderate employee impact and standard security requirements. Classified Medium — no AI-specific risks, no employment law implications, contained scope.