The DEN Risk Tiering Model: Proportionate AI Governance Explained

  • Post author:
You are currently viewing The DEN Risk Tiering Model: Proportionate AI Governance Explained

One of the most common AI governance mistakes is applying uniform oversight to every AI initiative — treating a meeting summarizer with the same rigor as an autonomous customer-facing chatbot. The result is either bureaucratic paralysis (over-governing low-risk tools) or dangerous under-governance (applying the same light-touch controls to high-risk systems that you’d apply to a note-taking assistant).

Proportionate AI governance is the principle that the level of oversight should match the level of risk — not the organizational enthusiasm for AI, not the budget available for controls, and not the seniority of the person sponsoring the initiative.

The DEN Risk Tiering Model provides a practical framework for classifying every AI initiative into one of three tiers and applying governance controls that are matched to the actual risk each initiative carries.

Why Proportionate Governance Matters

Consider two AI initiatives at the same mid-market organization:

  • Initiative A: An AI tool that helps the marketing team draft social media post ideas for human review and editing before anything is posted
  • Initiative B: An AI-powered chatbot that responds automatically to client inquiries about account status, billing, and service terms

Both use large language models. Both interact with text. But they are fundamentally different in their risk profile:

Initiative A has a human reviewing every output before any external consequence occurs. A bad AI draft is caught before it matters.

Initiative B acts autonomously. A wrong response to a client about their billing or service terms reaches the client immediately, may create a legal obligation, and cannot be recalled.

Applying the same governance requirements to both initiatives wastes resources (on Initiative A) and creates serious exposure (on Initiative B). Tiered governance addresses both problems.


The DEN Risk Tiering Model: Three Tiers

Tier 1 — Low Risk

Definition: AI tools used internally for assistive tasks where a human reviews every output before it is used. If the AI produces a wrong answer, the error is easily caught and corrected with minimal consequence.

Classification criteria (all three should apply):

  • The AI output is reviewed by the employee before any use or action is taken
  • The context is internal to the organization (not client-facing or regulatory)
  • An error in the output is easily identified and corrected without lasting consequence

Examples:

  • Meeting transcript summarization
  • Internal email drafting
  • Research and information gathering for internal use
  • Document formatting and editing assistance
  • Policy search and internal knowledge retrieval

Governance requirements for Tier 1:

ControlRequirement
Tool approvalTool must be on the Approved Tools Register
Data restrictionsRestricted data categories may not be entered (standard data classification rule applies)
Output reviewEmployee self-review — the person who generated the output verifies it before use
Incident reportingStandard incident path applies if something goes wrong
Periodic reviewIncluded in quarterly Approved Tools Register review

Who can approve a Tier 1 initiative: The AI Governance Owner, by adding the tool to the Approved Tools Register.


Tier 2 — Medium Risk

Definition: AI tools used in client-facing workflows or in operational automations where errors could have moderate consequences — affecting client relationships, operational decisions, or organizational reputation.

Classification criteria (any one is sufficient to classify Tier 2):

  • AI output is used in client-facing communications, deliverables, or reports
  • AI executes or initiates operational decisions without per-instance human review
  • An error in the output could affect client perception, operational efficiency, or business continuity

Examples:

  • AI-assisted proposal writing or client report drafting
  • Automated data processing and transformation pipelines
  • Marketing copy generation for external use
  • AI-drafted client email responses reviewed before sending
  • Customer segmentation and prioritization tools

Governance requirements for Tier 2:

ControlRequirement
Tool approvalTool must be on the Approved Tools Register with documented use cases
Data restrictionsRestricted data categories explicitly documented for this tool
Output reviewSupervisor or peer review required before any AI output is shared externally or acted upon operationally
Incident reportingStandard incident path; AI Governance Owner must be informed within 48 hours of any client-visible error
Periodic reviewQuarterly review of tool performance and output quality by the AI Governance Owner
Escalation pathClearly defined escalation contact if the tool produces a harmful or unexpected output

Who can approve a Tier 2 initiative: The AI Governance Owner, with documented use cases and data restrictions. Consult legal if client contract implications are unclear.


Tier 3 — High Risk

Definition: AI systems that operate with significant autonomy, handle personal data, influence legal or financial decisions, or interact directly with clients without per-instance human review of every output.

Classification criteria (any one is sufficient to classify Tier 3):

  • The AI system takes actions or sends communications autonomously without a human reviewing each instance
  • The AI system handles personally identifiable information (PII) or sensitive personal data
  • The AI output influences legal, financial, HR, or compliance decisions
  • An error in the AI output would be difficult or impossible to reverse without client or regulatory consequence

Examples:

  • Autonomous customer support chatbots that respond directly to client inquiries
  • AI-mediated intake or onboarding processes
  • HR decision support tools (hiring screening, performance evaluation)
  • Financial analysis systems influencing credit, pricing, or investment decisions
  • Legal document generation or interpretation tools
  • Compliance monitoring AI
  • Agentic AI systems — AI agents that autonomously plan and execute multi-step tasks (web browsing, sending emails, triggering workflows, calling APIs) with minimal per-step human review are Tier 3 by default. The autonomous action criterion is met regardless of the domain

Note on regulatory alignment: AI systems that influence decisions about employment, credit, housing, insurance, healthcare, or essential services fall into Tier 3 under the DEN Risk Tiering Model — and also into “high-risk” or “consequential decision” categories under emerging US state AI laws (including Colorado’s ADMT law, effective January 2027) and Canadian sector guidance (OSFI for financial services; PIPEDA and Quebec Law 25 for personal data in automated decisions). The NIST AI Risk Management Framework‘s highest-priority risk profile covers exactly these use cases. Organizations can treat Tier 3 classification as the practical operationalization of what regulators in both the US and Canada identify as high-stakes AI — the governance controls required by Tier 3 correspond directly to what responsible AI regulation expects organizations to have in place.

Governance requirements for Tier 3:

ControlRequirement
Risk assessmentWritten risk assessment documenting specific failure modes, data handling procedures, and escalation protocols — completed before deployment
Tool approvalFormal approval from the AI Governance Owner and, where required, legal/compliance sign-off
Data restrictionsExplicit data handling agreement with tool vendor (data processing agreement) required before deployment
Output reviewSubject matter expert (legal, HR, finance, compliance) review of AI outputs before they are acted upon
MonitoringContinuous performance monitoring with defined thresholds and automatic escalation
Audit trailFull audit trail of system decisions maintained for a defined retention period
Periodic reviewQuarterly legal and compliance review

Who can approve a Tier 3 initiative: The AI Governance Owner, with formal legal/compliance review. Executive sponsor sign-off recommended.


How to Apply the Risk Tiering Model

Step 1: For each AI initiative, answer the three classification questions:

  • Does a human review every output before any use, action, or external consequence? (If no → Tier 2 minimum)
  • Does the output affect clients, external stakeholders, or regulatory obligations? (If yes → Tier 2 minimum)
  • Does the system act autonomously, handle PII, or influence legal/financial decisions? (If yes → Tier 3)

Step 2: Classify under the highest tier for which any criterion applies. When in doubt, classify upward.

Step 3: Apply the governance controls required for the assigned tier before the initiative is approved to begin.

Step 4: Document the tier classification in the AI Initiative Canvas alongside the governance controls in place.


The Axis Boundary Tie-Breaking Rule

When classifying initiatives near the boundary between Tier 1 and Tier 2 (or between Tier 2 and Tier 3), apply the Axis Boundary Tie-Breaking Rule: classify under the higher tier.

The cost of over-governance is minor friction and a few additional review steps. The cost of under-governance is an incident that reaches a client, damages a relationship, or creates regulatory exposure.

When the tier is genuinely unclear, classify upward.

Full guide: How to build an AI governance framework →

Full guide: Responsible AI — the 6 dimensions every leader must govern →

Take the free Governance Assessment →

Return to Hub 2: The Complete Guide to AI Governance →


Frequently Asked Questions

Q: How do you classify AI initiatives by risk level? Classify AI initiatives using three questions: Does a human review every output before any consequence occurs? Does the output affect clients or regulatory obligations? Does the system act autonomously or handle sensitive personal data? Tier 1 applies when all three answers are “low-risk.” Tier 3 applies when any criterion for high risk is met. Tier 2 applies to everything in between.

Q: What is proportionate AI governance? Proportionate AI governance means applying oversight controls that match the actual risk of each AI initiative — not applying uniform heavy governance to all AI tools, which creates friction and discourages adoption, and not applying light-touch governance to high-risk systems, which creates exposure. The DEN Risk Tiering Model is the practical implementation of proportionate governance.

Q: Can a Tier 1 initiative become a Tier 3 initiative? Yes — and this happens more often than organizations expect. An AI tool that starts as a Tier 1 drafting assistant may be expanded to produce content that goes directly to clients without review, or to process client data that it was not originally approved to handle. Agentic AI features present a particular version of this risk: a tool initially deployed for Tier 1 drafting may later be given “agent” capabilities — autonomous tool-calling, email sending, workflow triggering — that automatically reclassify it as Tier 3. The AI Governance Owner should treat the addition of autonomous action capabilities as an automatic re-classification trigger. When an initiative’s scope or use case changes in any way that affects the three classification criteria, the risk tier must be re-evaluated before the expanded use begins.

Q: What makes something automatically Tier 3? Any one of three conditions: the AI system acts autonomously without a human reviewing each output before it takes effect; the system handles personally identifiable information or sensitive personal data; or the system’s output influences legal, financial, HR, or compliance decisions.

Q: Who has authority to approve a Tier 3 AI initiative? The AI Governance Owner must formally approve Tier 3 initiatives, with legal or compliance review. For initiatives with significant financial, legal, or regulatory exposure, executive sponsor sign-off is recommended. No Tier 3 initiative should go live without a completed written risk assessment.

Tariq Alam

AI Educator and Consultant passionate about helping organizations and professionals harness the power of data and AI for innovation and strategic decision-making. On DEN Agentic AI, I share insights and practical guidance on AI Strategies, AI Tools, AI Enablement, AI applications, and industry trends.

Leave a Reply