1. Write down this year's objectives
Three to five, in plain language: win new customers, protect margin, launch a product, retain key clients. Every risk you assess hangs off one of these.
Three ways to do it, compared.
The five steps, what a complete entry needs, and how the three main routes stack up. Start from your objectives, not an AI tool list.
People mean two things by this phrase. One is checking an AI system you are adopting: its data, its accuracy, its vendor. The other is working out what AI has changed about the risks your business already carries: which ones got bigger or cheaper to exploit, which are new, and which openings a competitor could reach first. This page is about the second, because it is the bigger question and the one almost nothing answers well. The first still gets covered: your own AI use belongs on the register too, and step 4 below puts it there.
Most of what an assessment finds is not new. AI is not a new risk on your register; it is the largest single driver of the risks already there. Invoice fraud has been on registers for decades; what changed is that a convincing voice on the phone no longer proves the caller is your supplier. The risk is old. The assumptions underneath it moved. That is why a useful assessment starts from your objectives, not from a list of AI tools.
Choose your route
By hand. A spreadsheet or a document, using the five steps below. Free, and fine for a first pass. The catch: it tends to be done once and reviewed rarely, every update is manual work, and the scores age quietly.
A typical risk tool. Good at holding the register: entries, owners, reminders. The catch for this job: it stores what you type. Working out what AI has changed about each risk is still on you.
An AI-native, objective-led platform. Starts from what your business is trying to achieve, maps the risks under each objective, and scores what AI is driving, so the picture stays current. Drova's Index does this in about ten minutes, free. It is ours, so test that on your own business rather than taking our word for it.
If a board or regulator needs an external report, a consultancy still has its place, and formal frameworks like the NIST AI RMF can come later. Neither is needed to start.
Three to five, in plain language: win new customers, protect margin, launch a product, retain key clients. Every risk you assess hangs off one of these.
Under each objective: the risks on your register if you keep one, plus the ones everyone knows about but nobody wrote down. Most businesses land on 10 to 25 entries.
Has AI changed how fast this could happen, what it costs to do, or who could plausibly do it? Any yes means the old score is stale. This matters more than adding anything new.
Data pasted into public AI tools, unapproved AI use, AI output reaching customers or decisions, AI-written phishing, deepfake and voice-clone fraud. Skip any that genuinely do not apply.
An assessment without names and dates is a document, not a decision. Quarterly review is a sensible default while AI is moving this quickly.
The artefact
Every risk you assess should carry eight things:
A worked example. Objective: protect margin. Risk: invoice fraud. What moved: voice cloning defeats phone verification of bank-detail changes. Score: was Low, now High. Owner: the CFO. Safeguard: dual-channel verification, no voice-only approval. Review: quarterly.
Where should these live? Wherever your risks live, ideally your risk register, so the scores stay current, rather than another standalone document. If the honest answer is that they would end up in a spreadsheet nobody reopens, that is exactly the job the Index does for you.
Watch for
Starting from the tools. A list of AI software tells you what you bought, not what you are exposed to. Most AI exposure comes from other people's use of AI, not yours.
Only scoring the threat side. The same shift that makes a competitor faster can make you faster. An assessment that only finds danger misses the half your board actually wants to talk about.
Treating it as done. The most dangerous entry in most registers is an old score nobody has re-asked. Whatever cadence you choose, the review date is the safeguard.
How Drova helps
The method on this page is yours to run any way you like. If you would rather it ran itself: Drova's AI Disruption Index does the five steps from your objectives down. It maps the risks standing between you and what you are trying to achieve, scores how hard AI is driving each one, and drafts a safeguard for every risk it raises. About ten minutes, free, and what comes back is your picture, not your industry's.
FAQs
That depends where you run it. By hand, gathering the entries, scoring each one and drafting safeguards across a register takes real time, and every quarterly review adds more. Drova's Index generates one from your objectives in about ten minutes.
They overlap but are not the same. Assessing an AI system checks the tool: its data, accuracy and vendor. An AI risk assessment looks across your whole business at what AI has changed, including your own AI use. If you run the five steps on this page, step 4 covers the essentials of the first as entries on your register.
Every risk standing between you and this year's objectives, re-scored for what AI has changed, plus the new AI risks that apply to you: data pasted into public AI tools, unapproved AI use, AI answers reaching customers or decisions, AI-written phishing, and deepfake or voice-clone fraud.
Someone accountable for outcomes, not only for the document. In most businesses that is the CEO, CFO or COO, with each individual risk owned by whoever owns the objective it threatens.
Quarterly while AI capability is moving at its current pace. Annual review, the default on most registers, is how scores go stale without anyone noticing.
No. The five steps on this page are a defensible first pass. A consultancy earns its place when a board or regulator needs an external report, and the NIST AI RMF adds formal rigour later if you want it.
Your risks, mapped from your objectives, with a safeguard drafted for each. Free.