AI Risk Assessment Methodology
Every AI platform PMG uses has been assessed against a structured risk framework before it is approved for work purposes. This document details that framework: evaluation criteria, rating dimensions, and governance lifecycle.
1. Why We Assess AI Risk
PMG employs artificial intelligence to accelerate research, augment strategic analysis, and refine client deliverables. However, ungoverned AI deployment introduces substantial enterprise exposure across confidentiality, intellectual property integrity, compliance, and hallucinated advisory outputs.
Our assessment methodology provides a repeatable, objective, and auditable standard for evaluating third-party AI models, agentic workflows, and cloud architectures before any consultant or automated pipeline interacts with them.
Core Rule: No AI service may ingest, process, or synthesize PMG client data or proprietary firm assets unless it has attained an approved rating within this framework and holds active certification on our Approved Platforms Register.
2. The Five Evaluation Dimensions
Each platform is evaluated across five rigorous security and operational dimensions. Each dimension receives an individual risk score that informs the composite rating.
1. Data Privacy & Training
Examines whether user inputs/prompts are retained, logged, or used to train foundational models. Strict zero-retention or explicit enterprise opt-outs are required.
2. Provider Stability
Assesses vendor capitalization, SOC 2 Type II / ISO 27001 certifications, uptime track record, enterprise SLA guarantees, and long-term viability.
3. Decision Autonomy
Evaluates the degree of automated execution. Pure analytical suggestions present low risk; autonomous code execution or direct database mutations require strict sandboxing.
4. Jurisdiction Risk
Audits data center geolocation, cross-border transfer mechanisms, legal subpoena exposure, GDPR adequacy, and compliance with the EU AI Act.
5. Contextual Use Risk
Reviews the sensitivity of the specific use case: public market intelligence vs. confidential M&A restructuring, legal discovery, or financial forecasting.
3. The Four-Tier Rating Scale
Platforms are categorized into one of four distinct tiers based on composite evaluation scores. Each tier establishes clear, non-negotiable operational boundaries:
4. Governance & Review Lifecycle
AI platform risk is never static. Terms of service, model architectures, and data-retention schedules change without prior notice. PMG maintains a formal three-part lifecycle:
1. Initial Assessment
Conducted by the Systems Team in coordination with Legal and the Data Protection Officer prior to contract execution or organizational rollout.
2. Annual Recertification
Mandatory annual audit of all active tools against updated privacy policies, SOC 2 reports, and prevailing global regulations (e.g. EU AI Act).
3. Event-Driven Triggers
Immediate emergency review triggered upon vendor corporate acquisition, reported security breaches, or major product architecture shifts.
To request a platform evaluation or challenge an existing rating, submit a ticket via the IT Support Portal.
5. Scope & Limitations
This methodology evaluates platform-level risk (vendor architecture, storage, and legal terms). It operates alongside our complementary governance frameworks:
- Task-specific Ethics: Governed by the AI & Data Ethics Statement.
- Output Verification & Factuality: Governed by consultant peer review and validation protocols.
- Information Security & Access: Governed by PMG Global Information Security and Access Policies.