Describe
Confirm purpose, system boundaries and actual workflow.
Blanche assesses AI use in its real business context so management can see which risks need control, deeper review or documented acceptance.
It should cover the system's purpose, data, users, affected people, supplier, limitations, decision influence, possible harm, human oversight, security, legal context and available controls.
The same AI product can present very different risks in different settings. A drafting assistant used for internal notes is not equivalent to a feature used to screen candidates, flag fraud or influence access to a service.
Blanche documents the intended purpose, users, data, affected groups and consequences before assessing likelihood, impact and control strength.
A practical assessment considers inaccurate output, bias, privacy, confidentiality, cybersecurity, intellectual property, supplier dependence, transparency and over-reliance on automation. It also checks whether a person can detect and correct an error before harm occurs.
The output identifies risks, existing safeguards, recommended treatment, owners and review dates. Uncertain classification or legal questions are clearly marked rather than hidden inside an overall score.
Where a use may be high-risk, affect fundamental rights or require a DPIA, the assessment can show why a deeper specialist review is needed.
Confirm purpose, system boundaries and actual workflow.
Map harms, causes, affected groups and dependencies.
Assess likelihood, impact and existing control strength.
Assign actions, owners, evidence and a review point.
No. A DPIA is a GDPR process focused on high-risk personal data processing. An AI risk assessment can cover a wider set of operational, human, supplier and regulatory risks. Both may be needed.
No. A business risk score is not a legal classification. Applicability and high-risk status require a separate role and classification analysis.
Review it when the intended purpose, model, supplier, data, affected people or decision influence changes, and at a proportionate regular interval.
Yes. The review can use available contracts, product documentation, supplier answers, internal workflow evidence and testing, while clearly recording information gaps.
Tell us briefly how your organisation uses AI. We will review the context and confirm the most useful next step before discussing scope.
No assessment or estimate is required before you enquire.