AI-Assisted Writing Governance
AI Writing Task Risk Assessment
Decide whether and how AI may assist a writing task by evaluating data, factual, audience, rights, security, misuse, and accountability risks.
Free editable Markdown · AI governance teams, editors, and content leads ·
Accessible HTML preview
Blank template
The downloaded file contains the same fields in editable Markdown.
Task and workflow
- Project and task ID
- [Enter]
- Proposed AI step
- [Describe narrowly]
- Human steps before and after
- [Describe]
- Tool/service and account type
- [Enter]
- Output audience and channel
- [Enter]
- Scale and frequency
- [Enter]
- Can a person reject before use?
- [Yes / No / Partly]
- Consequence of a plausible error
- [Describe]
Input and output risk
- Input data classes
- [Public / Internal / Confidential / Personal / Regulated / Security]
- Rights or license limits
- [Describe]
- Retention, training, and sharing status
- [Verified facts or Unknown]
- Material claim types
- [Product / Health / Legal / Financial / Safety / Other]
- Affected or vulnerable groups
- [Describe relevant context]
- Identity or impersonation concern
- [Describe or None]
- Foreseeable misuse
- [List]
- Irreversible or high-scale effect
- [Describe]
Risk and safeguard record
Duplicate per material risk.
- Risk scenario
- [Cause, event, impact]
- Likelihood evidence
- [Low / Medium / High and basis]
- Impact
- [Low / Medium / High and basis]
- Existing control
- [Describe]
- Additional safeguard
- [Redact / Restrict / Verify / Review / Log / Other]
- Control owner and test
- [Name, evidence]
- Residual risk
- [Describe]
Decision and monitoring
- Decision
- [Prohibit / Redesign / Pilot / Approve with controls / Approve]
- Permitted tool and data
- [Exact scope]
- Prohibited behavior
- [List]
- Required review and approver
- [Who checks what]
- Disclosure and provenance
- [Requirements]
- Stop conditions
- [Incident, failure rate, data change, other]
- Approval owner and expiry
- [Name/date]
- Monitoring and incident route
- [Enter]
How to use this template
- Break the proposed workflow into concrete AI and human steps with outputs and decision points.
- Classify inputs, audience, claims, scale, reversibility, and consequence for each AI-assisted step.
- Identify privacy, security, rights, factual, fairness, misuse, and accountability risks.
- Select a decision and specify enforceable safeguards, evidence checks, owners, and stop conditions.
- Approve a time-bounded pilot or use case, monitor incidents, and reassess on material change.
Decompose the workflow before assigning risk
“Use AI for an article” is too broad to assess. Separate source collection, prompt preparation, generation, editing, fact-checking, translation, approval, and publication. Define exactly what the system may produce and whether a person can reject it before anyone relies on it. A brainstorming task using public facts differs from drafting individualized health guidance, impersonating a real person, or processing customer records. Note the intended audience, scale, channel, reversibility, and consequence of a plausible error. Classify each step independently when the risks differ.
Inspect inputs, claims, and foreseeable misuse
Inventory personal, confidential, regulated, copyrighted, security-sensitive, and unpublished material. Check whether the selected service, account, region, retention, training, and access controls permit those inputs. Then consider what the output could assert or enable: fabricated facts, discriminatory assumptions, misleading authority, unsafe instructions, privacy leakage, fraud, academic misconduct, or targeted persuasion. High fluency can make unsupported content more believable. Record which risks can be reduced by redaction, source-bound prompting, restricted distribution, expert review, or tool choice and which make the task inappropriate.
Make the decision operational
Choose prohibit, redesign, pilot, approve with controls, or approve as standard. Name the owner, allowed data classes, approved service, review tier, disclosure rule, logging requirement, and stop conditions. Controls must be observable: “human review” should say who checks which properties against what evidence before which release. Test a representative sample in a controlled environment before scaling. Preserve residual risk honestly and set an expiry, because tool behavior, policies, audiences, and regulations change. Incident reporting and revocation paths should exist before a project begins.
See the fields in context
Fictional example: public help-article outlines
The team, service, and policy below are invented and do not authorize any real AI use.
- Task: Generate outline alternatives from already published fictional help pages.
- Risk: A proposed outline may invent a product step or omit an important limitation.
- Control: The prompt uses source IDs; output remains internal; a product owner compares every retained step with current behavior.
- Decision: Approve a small pilot with public inputs only and no automated publication.
- Stop condition: Pause if restricted text is submitted or reviewers repeatedly find invented procedures.
Frequently asked questions
Is every AI writing task high risk?
No. Risk depends on the task, inputs, audience, claims, scale, and controls. Low consequence does not remove the need for appropriate data handling.
Can “human in the loop” be a sufficient safeguard?
Only when the person's role, expertise, time, evidence, authority, and required checks are defined and actually supported.
Should the assessment cover a whole tool or one project?
Vendor review can establish shared facts, but each use case still needs assessment because data and consequences differ.
When must an approved task be reassessed?
On tool, model, data, audience, scale, workflow, policy, incident, or regulatory changes and at the stated expiry.