Run a 30-Minute AI Workflow Risk Clinic Before Launch
Use four questions—data, decision, damage and detectability—to decide whether an AI workflow can proceed, needs controls or should stop.

Most AI workflow reviews fail at one of two extremes. A team launches after a quick demo, or governance asks for a document so broad that nobody can connect it to the real task. A 30-minute risk clinic creates a useful middle step: one workflow, one evidence sheet and one explicit decision.
The clinic is not legal approval and it does not replace a formal impact assessment. It is an operational triage that exposes the questions a pilot must answer before live work begins.
Review the workflow, not the model in the abstract
NIST’s AI Risk Management Framework organises work around Govern, Map, Measure and Manage, while its generative AI profile adapts those ideas to risks specific to generative systems. The practical lesson is simple: risk depends on context. The same model may be suitable for drafting fictional training examples and unsuitable for deciding who receives an interview.
The four D clinic
Data
What enters the tool? Mark personal, confidential, licensed and security-sensitive information. Use synthetic or minimised data wherever possible.
Decision
Does AI suggest wording, recommend an action or determine an outcome? Name the human who owns the final decision.
Damage
What happens if the output is wrong, biased, disclosed or acted on too quickly? Consider people, money, rights, operations and reputation.
Detectability
Can a competent reviewer spot the error before harm occurs? State the evidence, test or second source they will use.
The 30-minute agenda
One clinic, one page
- 1
Minutes 0–5: draw the hand-offs
Write the input, AI action, output, reviewer and downstream use. If the team cannot draw the workflow, it is not ready to assess.
- 2
Minutes 5–17: answer the four D questions
Invite the process owner, one likely user and one risk, privacy or security partner. Record disagreements rather than smoothing them over.
- 3
Minutes 17–24: choose controls
Pick the smallest controls that address the identified failure: data masking, source restrictions, human approval, sampling, logging or an escalation rule.
- 4
Minutes 24–30: make the call
Choose proceed to a bounded test, revise and return, route to formal review, or stop. Assign an owner and a date for the next check.
Reading is a start. Practice makes it stick.
Start learning| Proceed to bounded test | Route or stop | |
|---|---|---|
| Data | Approved, minimised or synthetic | Unclear authority, sensitive input or excess collection |
| Decision | AI assists and a named human decides | AI effectively determines a consequential outcome |
| Damage | Reversible and limited | Material effect on rights, safety, employment or finances |
| Detectability | Errors can be checked before use | Errors are hard to see until after harm |
| Evidence | Test cases and success criteria exist | The team is relying on a persuasive demo |
Worked example: an internal policy explainer
A people team wants an assistant to draft answers from approved leave policies. Data is limited to policy text and fictional questions. The tool drafts; an HR adviser approves every answer. Damage is moderate because wrong advice could affect an employee, but errors are detectable by checking the cited policy section. The clinic approves a bounded test with source citations, a visible ‘draft’ label, no employee records and an escalation path for individual cases.
Employment use needs extra care
The European Commission identifies AI systems used for recruitment as high-risk under the EU AI Act. A short clinic can flag that boundary, but it cannot convert a high-risk use into a low-risk one.
Evidence to keep
- The one-page workflow map and named owner
- The four D answers and unresolved questions
- The decision and its rationale
- The approved data boundary and review rule
- The test cases, failures and next review date
- Choose a proposed workflow and write its input and output in one sentence.
- Mark where a human decision currently happens.
- Write the most credible harmful failure—not the most dramatic one.
- Name how a reviewer would detect that failure.
- Bring the page to the clinic and spend the meeting on disagreements.
Good governance should make the next safe action obvious. The four D clinic gives teams a repeatable way to move from enthusiasm to a bounded decision. Bokili can turn each control—data choice, verification, human approval and escalation—into short practice before the workflow reaches live work.
Sources
- NIST AI Risk Management Framework — NIST
- NIST AI RMF Playbook — NIST
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — NIST
- AI Act enters into force — European Commission
Reading is a start. Practice makes it stick.
Bokili turns skills like this into ten-minute missions for your whole team, with instant feedback and progress you can see.
Start learningKeep reading

AI Course for Beginners: Build One Safe Work Sample
Choose one low-consequence task, protect the inputs, define a quality bar and build a verified first AI work sample.

Separate Generation From Decision: A Two-Pass AI Template
Use AI to expand and challenge options, then make and record the accountable human choice in a separate pass.

AI Training for Employees on Shifts: A Frontline Playbook
Design AI training for employees in retail, operations and field roles with short practice, safe examples, fast feedback and next-shift transfer.