Scope counts, not only risk
The same tool can need more formality as it grows. A chatbot for one course is not the same as one for every student. Expanding scope to more people, more data, or more units is a re-review trigger.
The five scores sum to a total between 5 and 25. The total measures the magnitude of risk and impact. A high score calls for more scrutiny and stronger safeguards, not automatic rejection. The cut-offs used here (5–10, 11–15, 16–20, 21–25) are representative; your institution may set different thresholds. The band then sets how formal the review process should be (see proportionality).
Example: the early warning system scores 17, High. Strong strategic fit (4) and operational potential (4), with moderate ethics, financial, and stakeholder scores (3 each). It should proceed only with strong safeguards and ongoing monitoring. See the full example.
Bands are a starting point for discussion, not a verdict. Two initiatives with the same total can carry very different risk profiles, so read the individual dimension scores and comments alongside the band.
The formality of review should match the risk and scope of the initiative. A low-risk pilot shouldn't wait months for a committee; a high-stakes system shouldn't get a quick sign-off. Too much process for small ideas drives people around governance. Too little for big ones exposes the institution.
| Element | Low | Moderate | High | Critical |
|---|---|---|---|---|
| Review format | Self-assessment with unit lead | One cross-functional meeting | Full team plus specialist reviews | Extended review; affected groups consulted |
| Documentation | Scored rubric and short description | Rubric, comments, draft KPIs & OKRs | All of that plus efficacy plan, exit criteria, risk mitigations | All of that plus alternatives analysis and impact assessment |
| Specialist input | Only if flagged | As needed (e.g., privacy) | Privacy, security, legal, accessibility | All relevant specialists, in writing |
| Decides | Unit lead | AI governance lead | AI governance council | Executive sponsors |
| Target time to decision | Days | About 2 weeks | About 4–6 weeks | As long as needed |
| Monitoring & re-review | End of pilot | Mid- and end-of-pilot | Ongoing; at least annually | Ongoing; time-limited approval |
The same tool can need more formality as it grows. A chatbot for one course is not the same as one for every student. Expanding scope to more people, more data, or more units is a re-review trigger.
Proportionality uses the total, but one severe dimension is enough to raise formality. A 5 on ethics or stakeholder impact escalates one level, whatever the total.
Band cut-offs, timeframes, and documentation levels are illustrative. Set them to fit your institution's capacity, and publish them so proposers know what to expect. Your governance structure also shapes them: a centralized model tends toward more formality for every band, a distributed one toward less.