Determine the potential consequences of the AI system's deployment, intended use, and foreseeable misuse. Use the result in the AI risk assessment. The organisation's process can also use it to inform whether the proposed or operating AI system can proceed, needs design or control changes, requires conditions or escalation, or should stop. The assessment should identify positive and negative consequences, who can experience them, their likelihood and severity where the chosen method uses those measures, and how the organisation will address them.
Assess deployment, intended use, reasonable foreseeable misuse, predictable failures, human involvement, data and technology, and the technical, societal, and jurisdictional context. Consider individuals, relevant demographic or other groups, and societal effects rather than limiting the assessment to model accuracy or organisational loss.
Define who performs the assessment, who supplies specialist or affected-party input, who approves the resulting decision, and what counts as a significant change. Preserve assumptions and evidence gaps so the approval authority can distinguish a supported conclusion from an unresolved question.