AI-007
AI Use-Case Intake, Risk Classification and Approval
Register proposed AI use cases, classify risk and route proportionate reviews before release.
- Challenge
- AI use cases need consistent intake, ownership and risk-based approval before release.
- Approach
- Register cases, classify risk and route proportionate reviews with explicit ownership and control requirements.
- Primary KPI
- Active AI use cases registered, risk-classified and owned.
- Impact
- Reduced shadow AI and faster proportional approvals.
Executive Summary
A central intake and approval process is needed so active AI use cases are visible, risk-classified and owned before they reach production.
This playbook focuses on ai use-case intake, risk classification and approval and gives it a use-case-specific workflow, system boundary, control set and KPI model.
AI helps classify use cases against intake questions and risk signals, but authorised reviewers determine the final tier, required controls and approval outcome.
Business Challenge
Without a common intake path, AI use cases emerge through business units, technology teams and vendors with inconsistent documentation and little traceability.
Approval needs to be proportional: low-risk use cases should move quickly, while higher-risk cases need security, privacy, legal and architecture review before release.
Enterprise Scenario
A governance function overseeing AI demand across business and technology teams through a central intake, review and register process.
The work is triggered when shadow AI appears, approvals are inconsistent or higher-risk use cases are being designed before review functions engage.
The operating environment requires proportionality: low-risk cases need speed, while higher-risk cases need stronger evidence and review depth.
Specific Risks
| Domain | Risk | Impact if unaddressed |
|---|---|---|
| Governance | Shadow AI is not registered | Active use cases operate outside oversight. |
| Security | Sensitive data or user groups are screened too late | Controls are bolted on after design choices are made. |
| Legal | Obligations are not reviewed for higher-risk cases | Release may create avoidable regulatory or contractual exposure. |
| Operational | Owners are missing or unclear | No one is accountable for lifecycle decisions once the case is live. |
Workflow
AI helps classify use cases against intake questions and risk signals, but authorised reviewers determine the final tier, required controls and approval outcome.
The workflow is designed to create a visible, owned register of active AI cases rather than a one-time approval exercise.
Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.
Representative operating workflow for this scenario. Sequence, thresholds and review depth should scale with transaction volume, data sensitivity and control risk.
Systems and Data
Intake forms, review workflows, policy references and the live use-case register need consistent identifiers and ownership fields.
Submissions are screened for owner, data and user context, then routed by risk tier into review steps and decision logging before they enter the active register.
Systems
- AI intake portal
- Risk questionnaire
- Review workflow
- Use-case register
- Architecture and policy records
Data used
- Use-case purpose
- Data types
- User groups
- Model and integration pattern
- Owner and budget details
Human Controls
Changes in scope, data sensitivity or user population should trigger reassessment instead of allowing the original approval to stand unchanged.
- Submission cannot proceed without a named business owner.
- Risk tiering drives which review functions must approve or advise.
- Approval decisions record required controls and review rationale.
- Higher-risk cases are reassessed when scope, data or user populations change.
- The active register is reviewed for stale, duplicate or unowned cases.
Governance and Operating Cadence
Governance triggers include unregistered live use cases, overdue reassessments, unresolved control findings or repeated duplicate submissions.
Ownership
The AI governance function owns the intake process, but each use case requires a named business owner and technical owner.
Decision rights
AI can assist risk classification; only authorised review functions approve or reject the case.
Cadence
Standing governance forums maintain throughput while preserving review depth for material cases.
Escalation
Unregistered production use, unresolved control findings and ownerless cases are escalated promptly.
Success Metrics
Active AI use cases registered, risk-classified and owned
Measures whether the governance process has real coverage.
Supporting KPIs
Targets are illustrative and should reflect risk appetite, review capacity and the volume of active AI demand.
Business Impact
- Reduced shadow AI
- Faster proportional approvals
- Clearer traceability from intake to decision
- Less downstream rework from late control discovery
- Stronger ownership of active AI services
Outcomes are not guaranteed and depend on source quality, control discipline and operating context.
Related Playbooks
Playbooks that are commonly delivered alongside, before or after this one.
This playbook describes a typical implementation approach and a representative operating model. It is illustrative guidance, not a statement of results. Any figures, targets or ranges shown are illustrative and are intended to support planning discussions rather than to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate, contracts, data quality and organisational context of each engagement.
No client names, client data, engagement detail or confidential delivery material is disclosed anywhere in this library. Technology named in these pages appears only as an illustrative example of a capability category and does not imply a partnership, certification or recommendation.
Book a Value Discovery
A free 30-minute session to pressure-test where the value actually sits in your software, SaaS and AI estate — and what it would take to get to it.