Reference Framework

AI Risk Assessment Methodology

Every AI platform PMG uses has been assessed against a structured risk framework before it is approved for work purposes. This document details that framework: evaluation criteria, rating dimensions, and governance lifecycle.

Contents

1. Why We Assess AI Risk

PMG employs artificial intelligence to accelerate research, augment strategic analysis, and refine client deliverables. However, ungoverned AI deployment introduces substantial enterprise exposure across confidentiality, intellectual property integrity, compliance, and hallucinated advisory outputs.

Our assessment methodology provides a repeatable, objective, and auditable standard for evaluating third-party AI models, agentic workflows, and cloud architectures before any consultant or automated pipeline interacts with them.

Core Rule: No AI service may ingest, process, or synthesize PMG client data or proprietary firm assets unless it has attained an approved rating within this framework and holds active certification on our Approved Platforms Register.

2. The Five Evaluation Dimensions

Each platform is evaluated across five rigorous security and operational dimensions. Each dimension receives an individual risk score that informs the composite rating.

1. Data Privacy & Training

Examines whether user inputs/prompts are retained, logged, or used to train foundational models. Strict zero-retention or explicit enterprise opt-outs are required.

2. Provider Stability

Assesses vendor capitalization, SOC 2 Type II / ISO 27001 certifications, uptime track record, enterprise SLA guarantees, and long-term viability.

3. Decision Autonomy

Evaluates the degree of automated execution. Pure analytical suggestions present low risk; autonomous code execution or direct database mutations require strict sandboxing.

4. Jurisdiction Risk

Audits data center geolocation, cross-border transfer mechanisms, legal subpoena exposure, GDPR adequacy, and compliance with the EU AI Act.

5. Contextual Use Risk

Reviews the sensitivity of the specific use case: public market intelligence vs. confidential M&A restructuring, legal discovery, or financial forecasting.

3. The Four-Tier Rating Scale

Platforms are categorized into one of four distinct tiers based on composite evaluation scores. Each tier establishes clear, non-negotiable operational boundaries:

Tier 1Pre-Approved

Minimal Risk

Full enterprise agreement with contractually guaranteed zero-retention, dedicated private tenancy, or local client-side execution.

  • ✓ No model training on inputs
  • ✓ Full client data permitted
  • ✓ SOC 2 Type II certified
  • ✓ Annual compliance check
Tier 2Standard Use

Limited Risk

Commercial enterprise accounts with verifiable privacy toggles and standard commercial liability protections.

  • ✓ Verified training opt-out
  • ✓ Standard business data allowed
  • ! Highly sensitive IP excluded
  • ✓ Bi-annual audit review
Tier 3Restricted

High Risk

Consumer-tier products, unverified telemetry pipelines, or services lacking enforceable corporate privacy terms.

  • ! Requires DPO/Legal approval
  • ! Strictly synthetic/public data
  • ! Mandatory session logging
  • ! Quarterly recertification
Tier 4Prohibited

Unacceptable Risk

Services that openly train on user inputs without opt-out, operate in non-compliant jurisdictions, or violate fundamental security baselines.

  • ✕ Strict enterprise block
  • ✕ Zero firm or client data
  • ✕ Network-level DNS filtering
  • ✕ Immediate blacklisting

4. Governance & Review Lifecycle

AI platform risk is never static. Terms of service, model architectures, and data-retention schedules change without prior notice. PMG maintains a formal three-part lifecycle:

1. Initial Assessment

Conducted by the Systems Team in coordination with Legal and the Data Protection Officer prior to contract execution or organizational rollout.

2. Annual Recertification

Mandatory annual audit of all active tools against updated privacy policies, SOC 2 reports, and prevailing global regulations (e.g. EU AI Act).

3. Event-Driven Triggers

Immediate emergency review triggered upon vendor corporate acquisition, reported security breaches, or major product architecture shifts.

To request a platform evaluation or challenge an existing rating, submit a ticket via the IT Support Portal.

5. Scope & Limitations

This methodology evaluates platform-level risk (vendor architecture, storage, and legal terms). It operates alongside our complementary governance frameworks:

  • Task-specific Ethics: Governed by the AI & Data Ethics Statement.
  • Output Verification & Factuality: Governed by consultant peer review and validation protocols.
  • Information Security & Access: Governed by PMG Global Information Security and Access Policies.