Consequence Profiling answers one question for each AI Activity on the register: if this goes wrong, who or what absorbs it? The answer sets how much governance the Activity attracts, how often it is reviewed and who has to approve it.
It deliberately looks at consequence rather than likelihood. An organisation cannot reliably estimate how often a model will produce a bad output, yet it can describe with some confidence what the damage would be if it did. Profiling on consequence alone keeps the assessment honest and repeatable between people.
The five Consequence Domains
Each Activity is scored in all five domains. Scoring every domain matters, because the domain an organisation would not have thought of is usually the one that produces the highest score.
People Harm
Physical, psychological, financial or opportunity harm to an individual. Anything affecting employment, care, access to a service or treatment of a customer sits here.
Financial Exposure
Direct cost to the organisation through error, rework, contractual failure, penalty or lost revenue.
Legal and Regulatory Liability
Breach of a legal duty or a regulatory expectation, including data protection, equality and any sector obligation.
Reputational Damage
Loss of trust among clients, staff, partners or the public, including the damage caused by having no answer when challenged.
Operational Disruption
Interruption to the work itself if the Activity fails, changes or becomes unavailable.
Highest, never average
The overall Consequence Rating is the highest individual domain score. Averaging would let a single severe consequence disappear behind four mild ones. There are no half scores, while a score that could plausibly sit at either of two levels is taken at the higher.
What each rating requires
The rating is not a label. It determines the number of Safeguards, the review frequency and who has to sign the Activity off.
| Rating | Safeguards | Review frequency | Who approves |
|---|---|---|---|
| 1 Negligible | Core Safeguards only, meaning the six in SG1 Foundation | Annual | Governance Lead |
| 2 Moderate | Core plus relevant Group Safeguards, typically 12 to 18 in total | Six-monthly | Governance Lead |
| 3 Significant | Core plus enhanced Safeguards from multiple Groups, typically 20 to 28 | Quarterly | Senior Leadership |
| 4 Critical | The full applicable Safeguard suite, typically 32 to 42 | Monthly, with continuous monitoring where appropriate | Senior Leadership, with documented rationale |
A worked profile
AIA-002, a tool that ranks job applications against role criteria and produces a suggested shortlist for a hiring manager to review.
| Domain | Score | Reasoning |
|---|---|---|
| People Harm | 3 | Affects an individual's employment prospects |
| Financial Exposure | 2 | Rework and the cost of a poor hire |
| Legal and Regulatory | 3 | Equality Act 2010 and automated decision-making duties |
| Reputational | 3 | A discrimination claim would be public |
| Operational | 2 | Hiring continues manually if it fails |
The result
Three domains score 3, so the overall Consequence Rating is 3 Significant even though two domains are only Moderate. That single figure then drives everything else.
- 24 Safeguards selected across seven Groups, inside the 20 to 28 range
- Quarterly review rather than annual
- Senior Leadership approval rather than the Governance Lead alone
- Level 3 AI Reviewer competence required for every manager reviewing the output
When to profile again
A profile is a statement about a moment. Six triggers require the Activity to be re-profiled without waiting for its scheduled review.
- Material modification to the Activity or how it is used
- Provider change, including a change of model or terms by the existing provider
- Data change, where different or more sensitive inputs start being used
- An AI Incident involving the Activity
- Regulatory change affecting the obligations that apply
- Scheduled review falling due at the frequency the rating requires
Continue reading
Material changes since the previous version See the framework overview
Put this into practice
The AIGMS™ packs contain the documents, registers, workbooks and training that turn the framework into a working system.