AI risk assessment checklist for SaaS: review a feature before launch
Assess an AI feature's intended use, affected people, data, failure modes and controls before release, then assign owners and revisit the risks as the product changes.
In this guide
How do you assess risk in a SaaS AI feature?
Review the complete product workflow, not just the model. Record the intended task, users and affected people, data sources, provider, interface, automation authority, likely failures and controls. NIST's AI Risk Management Framework groups activities under Govern, Map, Measure and Manage; its use is voluntary, not a certification, and NIST states that AI RMF 1.0 is being revised. Use the framework as a structured conversation and tailor it to the actual feature and its impact.
Define the use case and where the AI is allowed to act
Describe what problem the feature solves, who uses it, who may be affected, what inputs it sees and what output it produces. State what it must not do. Separate drafting or search assistance from decisions about eligibility, safety, employment, finances or access to services. Document when a person must verify an answer or approve an external action.
Map the full data and dependency path
List the application, model and provider, prompt and tools, retrieval sources, tenant boundary, human review, logs and downstream systems. Identify personal or confidential information, external actions, shared indexes and third-party dependencies. Ask what can change independently, who owns each component, what users have been told and how data is retained or deleted.
Identify who could be harmed and how
Consider inaccurate or missing answers, biased treatment, inaccessible interactions, language gaps, privacy exposure, prompt injection, excessive tool authority, fraud and service outages. Think about people who are not the direct account holder but may be affected by an output. Estimate severity and exposure using evidence; do not reduce a serious consequence to a single unexamined average score.
| Use case and limits | Affected people and data | Failure and impact | Control and verification evidence | Owner and release decision |
|---|---|---|---|---|
What should the AI pre-launch review measure?
Choose tests that match the real user task
Build representative evaluations for correct answers, missing evidence, refusals, language and accessibility variants, malicious inputs, out-of-scope requests and boundary cases. Measure the quality dimension that matters: source support, task completion, harmful errors, false refusals or unauthorized actions. Keep subgroup results visible where sample sizes allow, and document what the tests do not measure.
Set controls and stop conditions before testing
For each material risk, name a control, accountable owner and test. Controls might include server-side authorization, restricted tools, human approval, rate limits, source filters, a user correction route or a disable switch. Define what result blocks release, who can accept residual risk and how an exception expires. A disclaimer is not a substitute for a working safeguard.
Make the release decision explicit
Record the feature version, evaluated model and prompt, evidence reviewed, known limitations, mitigations, unresolved risks, approver and rollout scope. Start with a reversible deployment and monitor the agreed signals. NIST's Playbook is voluntary guidance with suggested actions, not a mandatory ordered checklist; select practices that fit the use case and retain a clear rationale for the decision.
How should an AI risk assessment stay current?
Reassess when a meaningful dependency or use changes
Review risk after changing the model, provider, system prompt, tools, retrieved corpus, target users or level of automation. A change that looks like routine configuration can alter privacy, accuracy or authority. Use change-impact review to decide which tests must rerun, who needs to approve and whether the release needs a staged rollout.
Connect incidents and user reports to the review
Feed confirmed failures, appeals, safety reports, accessibility barriers and privacy events into the risk register and evaluation suite after review. Track the risk, mitigation, owner, due date and evidence that the control works. Do not treat report counts as ground truth without considering exposure, reporting friction and changes in usage.
Keep the review proportionate and understandable
A small internal assistant and a feature that can affect a customer's rights or money need different scrutiny. Explain the rationale, evidence and remaining uncertainty in language product, engineering, security, support and affected-user representatives can understand. Reuse a common template, but avoid giving every AI feature the same risk score or approval path.
SaaS AI risk assessment: FAQs
Is the NIST AI RMF a legal requirement or certification?
The NIST AI RMF is voluntary guidance. It does not certify a product or settle which laws apply. Check the current rules, contracts and sector requirements for the product and jurisdiction with qualified advisers.
Can a model benchmark alone approve an AI feature?
No. A benchmark covers selected tasks and conditions. Review the full workflow, data, permissions, affected people, operational controls and failure recovery too.
Who should own the AI risk review?
Name a product owner and involve engineering, security, privacy, support and relevant domain reviewers. High-impact uses may need additional independent or leadership review based on the organization's risk policy.
When should a team repeat the assessment?
Repeat it when the use, model, provider, data, automation authority or affected population changes, and when incidents or evaluations show that existing assumptions no longer hold.
Related practical guides
Related issue guides
Sources and publication record
Draft prepared 27 September 2026; engineering, security and editorial review pending · Sources checked .
- Artificial Intelligence Risk Management Framework (AI RMF 1.0)National Institute of Standards and Technology
- NIST AI Risk Management Framework PlaybookNational Institute of Standards and Technology
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)National Institute of Standards and Technology
- Your data and model usage policies by endpointOpenAI Platform Documentation
- Evaluation best practicesOpenAI API documentation
- OpenAI API deprecationsOpenAI API documentation
- SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk ManagementNational Institute of Standards and Technology
- LLM06:2025 Excessive AgencyOWASP Gen AI Security Project