# Risk Tiering Worksheet

**System name:** [Name]
**Case ID:** [ID]
**Assessed by:** [Name]
**Date:** [Date]

## Risk Indicator Scoring

Start at Tier 1. For each "yes" answer, move up one tier (cap at Tier 4). The triage designee may adjust based on context and judgement.

| # | Question | Yes / No | If Yes: +1 Tier |
|---|----------|----------|-----------------|
| 1 | Affects access to services, benefits, or opportunities? | | |
| 2 | Could cause physical, financial, or reputational harm? | | |
| 3 | Operates in a regulated domain? | | |
| 4 | Uses sensitive personal data? | | |
| 5 | Automated decision-making without human review? | | |
| 6 | Novel use of AI for the organization? | | |

**Count of "Yes" answers:** ___

## Tier Assignment

| Tier | Risk Level | Criteria |
|------|-----------|----------|
| **Tier 1** | Low | Internal use only, decision support, no personal data, low consequence of error |
| **Tier 2** | Medium | Customer/employee-facing with human oversight, personal data with consent, moderate consequence |
| **Tier 3** | High | Affects rights/opportunities, automated decisions with significant impact, sensitive data, regulated domain |
| **Tier 4** | Prohibited / Executive Escalation | Prohibited by law or policy, unacceptable risk, exceeds council risk appetite |

**Calculated tier (based on score):** [ ] Tier 1 [ ] Tier 2 [ ] Tier 3 [ ] Tier 4

**Adjusted tier (if different):** [ ] Tier 1 [ ] Tier 2 [ ] Tier 3 [ ] Tier 4

**Reason for adjustment (if any):**

---

**Review pathway:**

- [ ] Tier 1: Self-serve with templates. Champion confirms.
- [ ] Tier 2: Champion review with lightweight assessment.
- [ ] Tier 3: Full council review with impact assessment, model card, and security review.
- [ ] Tier 4: Escalated to executive sponsor. May be blocked.
