Implementation Playbooks3 min read

Run a 30-Minute AI Workflow Risk Clinic Before Launch

Use four questions—data, decision, damage and detectability—to decide whether an AI workflow can proceed, needs controls or should stop.

Bokili Editorial· Verified August 18, 2026
ShareX
Four colleagues examine one AI workflow through lenses for data, decision, damage and detectability

Most AI workflow reviews fail at one of two extremes. A team launches after a quick demo, or governance asks for a document so broad that nobody can connect it to the real task. A 30-minute risk clinic creates a useful middle step: one workflow, one evidence sheet and one explicit decision.

The clinic is not legal approval and it does not replace a formal impact assessment. It is an operational triage that exposes the questions a pilot must answer before live work begins.

Review the workflow, not the model in the abstract

NIST’s AI Risk Management Framework organises work around Govern, Map, Measure and Manage, while its generative AI profile adapts those ideas to risks specific to generative systems. The practical lesson is simple: risk depends on context. The same model may be suitable for drafting fictional training examples and unsuitable for deciding who receives an interview.

The four D clinic

1

Data

What enters the tool? Mark personal, confidential, licensed and security-sensitive information. Use synthetic or minimised data wherever possible.

2

Decision

Does AI suggest wording, recommend an action or determine an outcome? Name the human who owns the final decision.

3

Damage

What happens if the output is wrong, biased, disclosed or acted on too quickly? Consider people, money, rights, operations and reputation.

4

Detectability

Can a competent reviewer spot the error before harm occurs? State the evidence, test or second source they will use.

The 30-minute agenda

One clinic, one page

  1. 1

    Minutes 0–5: draw the hand-offs

    Write the input, AI action, output, reviewer and downstream use. If the team cannot draw the workflow, it is not ready to assess.

  2. 2

    Minutes 5–17: answer the four D questions

    Invite the process owner, one likely user and one risk, privacy or security partner. Record disagreements rather than smoothing them over.

  3. 3

    Minutes 17–24: choose controls

    Pick the smallest controls that address the identified failure: data masking, source restrictions, human approval, sampling, logging or an escalation rule.

  4. 4

    Minutes 24–30: make the call

    Choose proceed to a bounded test, revise and return, route to formal review, or stop. Assign an owner and a date for the next check.

Reading is a start. Practice makes it stick.

Start learning
Proceed to bounded testRoute or stop
DataApproved, minimised or syntheticUnclear authority, sensitive input or excess collection
DecisionAI assists and a named human decidesAI effectively determines a consequential outcome
DamageReversible and limitedMaterial effect on rights, safety, employment or finances
DetectabilityErrors can be checked before useErrors are hard to see until after harm
EvidenceTest cases and success criteria existThe team is relying on a persuasive demo

Worked example: an internal policy explainer

A people team wants an assistant to draft answers from approved leave policies. Data is limited to policy text and fictional questions. The tool drafts; an HR adviser approves every answer. Damage is moderate because wrong advice could affect an employee, but errors are detectable by checking the cited policy section. The clinic approves a bounded test with source citations, a visible ‘draft’ label, no employee records and an escalation path for individual cases.

Employment use needs extra care

The European Commission identifies AI systems used for recruitment as high-risk under the EU AI Act. A short clinic can flag that boundary, but it cannot convert a high-risk use into a low-risk one.

Evidence to keep

  • The one-page workflow map and named owner
  • The four D answers and unresolved questions
  • The decision and its rationale
  • The approved data boundary and review rule
  • The test cases, failures and next review date
Practise before the meeting
  1. Choose a proposed workflow and write its input and output in one sentence.
  2. Mark where a human decision currently happens.
  3. Write the most credible harmful failure—not the most dramatic one.
  4. Name how a reviewer would detect that failure.
  5. Bring the page to the clinic and spend the meeting on disagreements.

Good governance should make the next safe action obvious. The four D clinic gives teams a repeatable way to move from enthusiasm to a bounded decision. Bokili can turn each control—data choice, verification, human approval and escalation—into short practice before the workflow reaches live work.

Sources

  1. NIST AI Risk Management FrameworkNIST
  2. NIST AI RMF PlaybookNIST
  3. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNIST
  4. AI Act enters into forceEuropean Commission
ShareX

Reading is a start. Practice makes it stick.

Bokili turns skills like this into ten-minute missions for your whole team, with instant feedback and progress you can see.

Start learning

Keep reading