Skip to the content.

AI use case risk assessment template

Complete this template before deploying any new AI use case in HR. Submit to the HR Technology governance review process.

Intake date: [DATE] Submitter: [NAME, TITLE] Target launch date: [DATE]


1. Use case overview

Name:

One-sentence description:

HR function(s) affected:

Estimated users: [Number of HR team members using the tool] / [Number of employees affected by its outputs]

Tool / vendor: [Name, or “internally built”]

AI approach:


2. Data inventory

What employee data does this use case access or process?

Data type Source system Sensitivity Purpose
[e.g., Job title, tenure] [HRIS] Low [Context for recommendations]
[e.g., Performance ratings] [Performance system] High [Training signal]
[e.g., Survey responses] [Survey tool] High [Sentiment analysis]

Does this use case process any of the following?

Data type Yes/No Notes
Protected category data (race, gender, age, disability, religion, national origin)    
Health or medical information    
Financial or compensation data    
Immigration status    
Communications data (email, Slack, calendar)    
Biometric or behavioral data    

If any “Yes” above: Stop and consult Privacy and Legal before proceeding.

Data retention:


3. Decision impact assessment

Does this use case influence or produce outputs that affect any of the following?

Employment decision Involved? Human review step?
Candidate screening or ranking    
Interview selection    
Offer generation    
Performance rating    
Promotion or advancement recommendation    
Compensation change    
Learning path assignment    
Termination or PIP    
Leave approval    
Disciplinary action    

If any employment decision is involved: Document the human review step explicitly. An AI use case may not autonomously execute any item in this list without a documented human review gate.


4. Fairness and bias assessment

Describe how the AI produces its outputs: [Brief description of the model, scoring approach, or generation method]

Which groups could be disadvantaged if the model performs unevenly? [List protected characteristics or demographic groups relevant to this use case]

Pre-deployment fairness testing:

Post-deployment monitoring plan:


5. Transparency and employee notice

Will employees know AI was used in this process?

Can employees request human review of AI outputs that affect them?


6. Risk classification

Score the overall risk level:

Factor Low Medium High
Employment decisions affected None Advisory input Direct decision
Data sensitivity Aggregate / low-sensitivity Personal, non-sensitive Sensitive personal data
Employee visibility Internal only Affects employee experience Affects employee status
Regulatory exposure Minimal Some (state AI laws, GDPR) High (Title VII disparate impact, CCPA/CPPA ADMT, IL HB 3773, CO ADMT Act, TX TRAIGA)
Autonomy level Human-in-the-loop throughout Human reviews AI output AI acts autonomously

Overall risk rating: [ ] Low [ ] Medium [ ] High

Note on regulatory exposure: federal EEOC enforcement of AI-related disparate impact has been deprioritized since April 2025, but the underlying Title VII liability and private litigation risk have not changed, and state laws are getting more specific, not less. The practical shift is toward private suits, Mobley v. Workday is the case practitioners now cite as the template for AI hiring discrimination claims against vendors, not just employers. See the AI literacy curriculum’s regulatory landscape module for the current detail on each: Colorado’s SB 24-205 was repealed and reenacted by SB 26-189 (May 2026) as the Automated Decision-Making Technology Act, now effective 1 January 2027 with a narrower scope, don’t cite the old bill number or timeline. Enforcement of both SB 24-205 and SB 26-189 is currently stayed: a federal magistrate judge blocked enforcement in April 2026 pending a ruling on xAI’s constitutional challenge and completion of the AG’s rulemaking (due by January 1, 2027). Treat January 2027 as a compliance deadline, not a confirmed enforcement start date, and check the docket before telling anyone this law is live. California runs two separate regimes (FEHA algorithmic discrimination rules, effective October 2025, and CPPA ADMT regulations, effective January 2027), not one generic “CCPA” reference. Texas TRAIGA (HB 149) took effect January 1, 2026 and is narrower than Illinois or Colorado, it reaches intentional discrimination, not disparate impact; the AG’s online complaint portal for TRAIGA is live at texasattorneygeneral.gov. Note TRAIGA’s disclosure and complaint provisions are scoped to “consumers,” a term the statute defines to exclude someone “acting in a commercial or employment context,” so lean on the separate intentional-discrimination prohibition, not the consumer complaint mechanism, for HR use cases. Score this row on legal exposure, not on how actively a federal agency is currently enforcing it.


7. Approval

Reviewer Sign-off required Approved Date
HR Technology Lead Always    
HR Leadership Medium + High    
Legal / Employment Counsel Medium + High    
Privacy / Data Protection If personal data involved    
CISO / Security If external vendor or new data access    

8. Launch conditions

Before this use case goes live: