A structured assessment of an AI system’s actual risk profile — not a generic checklist, but an evaluation grounded in what the system does, what data it touches, and what happens when it fails or is misused.

What gets assessed

Risk AreaWhat Is Examined
TechnicalModel access control, prompt injection surface, tool-call permission boundaries, output validation.
DataWhat data the system trains on, retrieves, or logs; KDPA lawful-basis alignment.
OperationalFailure modes, human-in-the-loop coverage for consequential decisions, monitoring and alerting.
Third-partyVendor/API dependency risk, data residency, model-provider terms of service.

What you receive

Frequently asked questions

How is this different from an AI security review?

AI security reviews focus on technical exploitability (prompt injection, access control). This is broader — it scores overall likelihood and impact across technical, data, operational, and third-party risk, producing a prioritised register rather than a single findings list.

Do you assess AI systems we haven't deployed yet?

Yes — a pre-deployment risk assessment is often more valuable, since findings can shape the architecture before launch rather than requiring rework afterward.

What does "scored by likelihood and impact" actually mean?

Each risk is rated on how likely it is to occur and how severe the consequence would be if it did — so remediation effort goes to the risks that matter most first, not just the ones that are easiest to describe.

Does this cover third-party AI vendor risk?

Yes — vendor and API dependency risk, data residency, and model-provider terms of service are part of the standard assessment scope.

Related

AI Governance Kenya (service) · AI Security Kenya (service) · Guide: Securing AI Agents · AI Risk Assessment: A Practical Framework (field note) · In-development project roadmap · HarLyn Digital Partners

START HERE

Engagements begin with a fixed-scope scoping call.

Request a Scoping Call →