Skip to main content
Home/Framework/Consequence Profiling
Part 4 · Consequence Profiling

Consequence Profiling

How AIGMS™ decides how much governance an AI Activity needs. Five domains, a four-point scale and one rule that keeps the assessment honest.

Consequence Profiling answers one question for each AI Activity on the register: if this goes wrong, who or what absorbs it? The answer sets how much governance the Activity attracts, how often it is reviewed and who has to approve it.

It deliberately looks at consequence rather than likelihood. An organisation cannot reliably estimate how often a model will produce a bad output, yet it can describe with some confidence what the damage would be if it did. Profiling on consequence alone keeps the assessment honest and repeatable between people.

The five Consequence Domains

Each Activity is scored in all five domains. Scoring every domain matters, because the domain an organisation would not have thought of is usually the one that produces the highest score.

Domain 01

People Harm

Physical, psychological, financial or opportunity harm to an individual. Anything affecting employment, care, access to a service or treatment of a customer sits here.

Domain 02

Financial Exposure

Direct cost to the organisation through error, rework, contractual failure, penalty or lost revenue.

Domain 03

Legal and Regulatory Liability

Breach of a legal duty or a regulatory expectation, including data protection, equality and any sector obligation.

Domain 04

Reputational Damage

Loss of trust among clients, staff, partners or the public, including the damage caused by having no answer when challenged.

Domain 05

Operational Disruption

Interruption to the work itself if the Activity fails, changes or becomes unavailable.

The scoring rule

Highest, never average

The overall Consequence Rating is the highest individual domain score. Averaging would let a single severe consequence disappear behind four mild ones. There are no half scores, while a score that could plausibly sit at either of two levels is taken at the higher.

What each rating requires

The rating is not a label. It determines the number of Safeguards, the review frequency and who has to sign the Activity off.

Governance requirements by Consequence Rating
RatingSafeguardsReview frequencyWho approves
1 NegligibleCore Safeguards only, meaning the six in SG1 FoundationAnnualGovernance Lead
2 ModerateCore plus relevant Group Safeguards, typically 12 to 18 in totalSix-monthlyGovernance Lead
3 SignificantCore plus enhanced Safeguards from multiple Groups, typically 20 to 28QuarterlySenior Leadership
4 CriticalThe full applicable Safeguard suite, typically 32 to 42Monthly, with continuous monitoring where appropriateSenior Leadership, with documented rationale
Why the ranges matter. A worked example showing a Significant Activity with eight Safeguards is not a light-touch interpretation, it is an incorrect one. If the count falls outside the range for the rating, either the profile or the selection is wrong.

A worked profile

AIA-002, a tool that ranks job applications against role criteria and produces a suggested shortlist for a hiring manager to review.

Consequence Profile, AIA-002
DomainScoreReasoning
People Harm3Affects an individual's employment prospects
Financial Exposure2Rework and the cost of a poor hire
Legal and Regulatory3Equality Act 2010 and automated decision-making duties
Reputational3A discrimination claim would be public
Operational2Hiring continues manually if it fails

The result

Three domains score 3, so the overall Consequence Rating is 3 Significant even though two domains are only Moderate. That single figure then drives everything else.

  • 24 Safeguards selected across seven Groups, inside the 20 to 28 range
  • Quarterly review rather than annual
  • Senior Leadership approval rather than the Governance Lead alone
  • Level 3 AI Reviewer competence required for every manager reviewing the output
Had the organisation averaged the five scores it would have reached 2.6, rounded to Moderate, then governed a hiring tool with roughly a dozen Safeguards on a six-monthly cycle. The highest-score rule exists to prevent exactly that.

When to profile again

A profile is a statement about a moment. Six triggers require the Activity to be re-profiled without waiting for its scheduled review.

  1. Material modification to the Activity or how it is used
  2. Provider change, including a change of model or terms by the existing provider
  3. Data change, where different or more sensitive inputs start being used
  4. An AI Incident involving the Activity
  5. Regulatory change affecting the obligations that apply
  6. Scheduled review falling due at the frequency the rating requires
Trigger two catches most organisations out. Providers upgrade models without asking, so a tool assessed against one model version may behave differently on the next. A provider change is a re-profiling trigger even when nothing inside the organisation has changed at all.

Continue reading

Framework version 3.1  ·  Page last reviewed [[date]]  ·  Next scheduled review [[date]]
Material changes since the previous version See the framework overview

Put this into practice

The AIGMS packs contain the documents, registers, workbooks and training that turn the framework into a working system.