AI Basics
AI risk framework: a board-level approach
AI risk is business risk. A board that governs AI risk the same way it governs any other risk is a board that understands what AI actually is. A board that treats AI as a technology risk is a board that will be surprised.
AI risk is not a new category of risk. It is business risk that happens to involve a new tool. A board that understands this governs AI the same way it governs any other significant business decision. A board that treats AI as a technology problem delegates it to IT and hopes for the best.
This guide covers the risk framework, how to assess AI risk at board level, and where the most common risks sit.
The risk categories
AI risk falls into four categories. A board that understands the categories can assess the risk without understanding the technology.
- Category one: Data risk. The data is wrong, incomplete, or inaccessible. The AI produces unreliable output.
- Category two: Decision risk. The AI makes a decision that affects a customer, an employee, or the business, and the decision is wrong.
- Category three: Governance risk. No one owns the system. No one monitors it. No one can explain it.
- Category four: Regulatory risk. The system does not meet the requirements of the JFSC, the GFSC, or the applicable regime.
Each category has a different impact and a different likelihood. The board's job is to assess both and decide whether the risk is acceptable.
How to assess AI risk
The assessment is simple in principle. For each AI system in the business, ask four questions.
First, what happens if the data is wrong? If the answer is a bad decision that affects a customer, the risk is high. If the answer is a minor inconvenience, the risk is low.
Second, what happens if the decision is wrong? If the answer is customer harm, financial loss, or regulatory action, the risk is high. If the answer is a corrected report, the risk is low.
Third, what happens if no one is monitoring it? If the answer is the system runs unchecked and errors accumulate, the risk is high. If the answer is the system is self-correcting, the risk is lower.
Fourth, what happens if the regulator asks? If the answer is the business cannot explain the system, the risk is high. If the answer is the business has documentation, the risk is lower.
"21% of organisations have no AI governance at all, and governance and risk is the fastest growing barrier to adoption."
Source: Deloitte, State of AI in the EnterpriseGovernance risk is the most common risk. It is also the most preventable. Appointing an owner and documenting the system eliminates most governance risk.
The risk matrix
Use a simple matrix to assess each AI system.
- High impact, high likelihood: Address immediately. The system needs governance, oversight, or rework.
- High impact, low likelihood: Monitor closely. The system is acceptable but requires ongoing oversight.
- Low impact, high likelihood: Fix the data or the process. The system is noisy but not dangerous.
- Low impact, low likelihood: Accept and monitor. The system is low risk.
The matrix forces the board to categorise each system. That prevents the board from treating all AI risk as equal. It is not. A chatbot that answers routine queries is not a credit scoring model that decides who gets a loan.
Where the risks sit
Three areas where AI risk is highest.
First, customer-facing systems. Any AI that makes decisions about customers, their accounts, their applications, or their complaints. The risk is customer harm, reputational damage, and regulatory action. These systems need the highest governance.
Second, financial systems. Any AI that affects the business's financial position, its reporting, or its compliance. The risk is financial loss, reporting errors, and regulatory penalties. These systems need financial oversight, not just technical oversight.
Third, operational systems. Any AI that affects production, logistics, or service delivery. The risk is operational disruption, safety issues, and quality problems. These systems need operational oversight.
"The 10-20-70 rule: 10% algorithms, 20% technology and data, 70% process change."
Source: BCGRisk governance is part of the seventy percent. It is process change. It requires the business to change how it monitors, how it reports, and how it holds people accountable.
The Isle of Man context
Isle of Man boards operate in a specific regulatory context. The JFSC issued AI governance guidance in July 2026. The GFSC is moving the same direction. The EU AI Act applies to firms with EU exposure.
For Isle of Man firms, the risk framework must address the applicable regime. A firm that does not know which regime applies to which system is a firm that has not assessed its risk properly.
The Island's size is an advantage for risk management. Fewer systems. Fewer people. Fewer moving parts. The risk assessment is simpler to complete and simpler to enforce.
"61% of CEOs say boards are rushing AI transformation, and around 40% of boards lack an informed view of how AI changes growth strategy."
Source: BCG, CEOs and Boards are aligned on AI in theory but divided in practiceRushing without a risk assessment is the most expensive mistake a board can make. The board's job is to understand the risk before approving the technology.
What the board should do
Three actions for every board.
First, inventory. List every AI system in the business. If the board does not know what systems exist, it cannot assess the risk.
Second, assess. For each system, answer the four questions. What happens if the data is wrong? What happens if the decision is wrong? What happens if no one monitors it? What happens if the regulator asks?
Third, govern. For each high-risk system, appoint an owner, set boundaries, and establish monitoring. For each medium-risk system, do the same with lighter oversight.
- Inventory: what exists?
- Assess: what is the risk?
- Govern: who owns it, and what are the boundaries?
- Review: quarterly, because the risk changes.
The framework is not complex. The execution is where most businesses struggle. The inventory requires someone to look. The assessment requires honest judgement. The governance requires someone with authority.
The honest assessment
Here is what most consultants will not say. Some AI systems have risks that cannot be mitigated without rework. A system that cannot explain its decisions has unmitigable governance risk. A system that no one understands has unmitigable oversight risk. A system that uses bad data has unmitigable data risk.
If the honest answer is that a system's risk is unacceptable, Fuzzelogic puts it in writing. We do not build systems that create unacceptable risk. We tell you which systems can be governed and which ones need to be rebuilt or stopped.
You already have AI in your business. You just do not know where. The risk framework tells you whether you are governing it. The honest answer is probably not.
Start with the assessment. Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it. When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak. www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950
Start with the assessment
Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it.
When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak.
www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950