AI-007

AI Use-Case Intake, Risk Classification and Approval

Register proposed AI use cases, classify risk and route proportionate reviews before release.

AI Value 13 min read Full playbook Illustrative — outcomes not guaranteed
At a glance
Challenge
AI use cases need consistent intake, ownership and risk-based approval before release.
Approach
Register cases, classify risk and route proportionate reviews with explicit ownership and control requirements.
Primary KPI
Active AI use cases registered, risk-classified and owned.
Impact
Reduced shadow AI and faster proportional approvals.
01

Executive Summary

A central intake and approval process is needed so active AI use cases are visible, risk-classified and owned before they reach production.

This playbook focuses on ai use-case intake, risk classification and approval and gives it a use-case-specific workflow, system boundary, control set and KPI model.

AI helps classify use cases against intake questions and risk signals, but authorised reviewers determine the final tier, required controls and approval outcome.

02

Business Challenge

Without a common intake path, AI use cases emerge through business units, technology teams and vendors with inconsistent documentation and little traceability.

Approval needs to be proportional: low-risk use cases should move quickly, while higher-risk cases need security, privacy, legal and architecture review before release.

03

Enterprise Scenario

A governance function overseeing AI demand across business and technology teams through a central intake, review and register process.

The work is triggered when shadow AI appears, approvals are inconsistent or higher-risk use cases are being designed before review functions engage.

The operating environment requires proportionality: low-risk cases need speed, while higher-risk cases need stronger evidence and review depth.

04

Specific Risks

Business risks by domain, with the risk and its impact
DomainRiskImpact if unaddressed
Governance Shadow AI is not registered Active use cases operate outside oversight.
Security Sensitive data or user groups are screened too late Controls are bolted on after design choices are made.
Legal Obligations are not reviewed for higher-risk cases Release may create avoidable regulatory or contractual exposure.
Operational Owners are missing or unclear No one is accountable for lifecycle decisions once the case is live.
05

Workflow

AI helps classify use cases against intake questions and risk signals, but authorised reviewers determine the final tier, required controls and approval outcome.

The workflow is designed to create a visible, owned register of active AI cases rather than a one-time approval exercise.

Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.

AI Use-Case Intake, Risk Classification and Approval workflowA use-case-specific operating workflow for ai use-case intake, risk classification and approval, from submission to reassessment.01SubmissionOUTPUTUse case captured02Owner assignmentOUTPUTAccountable sponsor named03Data and userscreeningOUTPUTInitial control questions04Risk tieringOUTPUTProposed classification05Security, privacy,legal andarchitecture reviewOUTPUTControl findings06Controls definedOUTPUTRequired mitigations07DecisionOUTPUTApprove, change or stop08RegisterOUTPUTActive case recorded09ReassessmentOUTPUTRisk status refreshed

Representative operating workflow for this scenario. Sequence, thresholds and review depth should scale with transaction volume, data sensitivity and control risk.

06

Systems and Data

Intake forms, review workflows, policy references and the live use-case register need consistent identifiers and ownership fields.

Submissions are screened for owner, data and user context, then routed by risk tier into review steps and decision logging before they enter the active register.

Systems

  • AI intake portal
  • Risk questionnaire
  • Review workflow
  • Use-case register
  • Architecture and policy records

Data used

  • Use-case purpose
  • Data types
  • User groups
  • Model and integration pattern
  • Owner and budget details
07

Human Controls

Changes in scope, data sensitivity or user population should trigger reassessment instead of allowing the original approval to stand unchanged.

  • Submission cannot proceed without a named business owner.
  • Risk tiering drives which review functions must approve or advise.
  • Approval decisions record required controls and review rationale.
  • Higher-risk cases are reassessed when scope, data or user populations change.
  • The active register is reviewed for stale, duplicate or unowned cases.
08

Governance and Operating Cadence

Governance triggers include unregistered live use cases, overdue reassessments, unresolved control findings or repeated duplicate submissions.

Ownership

The AI governance function owns the intake process, but each use case requires a named business owner and technical owner.

Decision rights

AI can assist risk classification; only authorised review functions approve or reject the case.

Cadence

Standing governance forums maintain throughput while preserving review depth for material cases.

Escalation

Unregistered production use, unresolved control findings and ownerless cases are escalated promptly.

09

Success Metrics

Primary KPI

Active AI use cases registered, risk-classified and owned

Measures whether the governance process has real coverage.

Illustrative target: 100% of production AI cases registered

Supporting KPIs

Approval cycle time by risk tier Illustrative target: tier-based SLAs met ≥ 90% Checks whether governance remains proportional.
Shadow AI cases brought into register Illustrative target: upward then declining trend Shows whether hidden demand is being surfaced.
Control findings closed before release Illustrative target: 100% of critical findings Protects release integrity.
Cases with overdue reassessment Illustrative target: < 5% Tests whether governance keeps pace with change.
Illustrative KPI model

Targets are illustrative and should reflect risk appetite, review capacity and the volume of active AI demand.

10

Business Impact

Potential business impact
  • Reduced shadow AI
  • Faster proportional approvals
  • Clearer traceability from intake to decision
  • Less downstream rework from late control discovery
  • Stronger ownership of active AI services

Outcomes are not guaranteed and depend on source quality, control discipline and operating context.

11

Related Playbooks

Playbooks that are commonly delivered alongside, before or after this one.

Important — please read

This playbook describes a typical implementation approach and a representative operating model. It is illustrative guidance, not a statement of results. Any figures, targets or ranges shown are illustrative and are intended to support planning discussions rather than to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate, contracts, data quality and organisational context of each engagement.

No client names, client data, engagement detail or confidential delivery material is disclosed anywhere in this library. Technology named in these pages appears only as an illustrative example of a capability category and does not imply a partnership, certification or recommendation.

Book a Value Discovery

A free 30-minute session to pressure-test where the value actually sits in your software, SaaS and AI estate — and what it would take to get to it.