What it means
An AI risk review is a structured assessment of how an AI-enabled feature could affect data privacy, fairness, accuracy, transparency, security, compliance evidence, user trust, and operational outcomes. In HR software, a risk review may be done before purchase, before rollout, after major configuration changes, or during recurring governance reviews.
Why buyers should care
AI risk is contextual. The same feature can be low risk when drafting internal text and higher risk when influencing candidate movement, employee records, compensation context, or manager decisions. Buyers should not rely only on vendor claims. A risk review helps teams decide which controls, approvals, monitoring, and documentation are appropriate for the actual workflow.
Evaluation checks
Buyers should review the use case, data inputs, affected users, decision impact, human review, vendor documentation, audit trail, permissions, retention, and failure scenarios. Ask what happens when the AI is wrong, incomplete, biased, unavailable, or misused. The review should produce actionable controls, not only a general statement that AI is being used responsibly.
This glossary entry is buyer-oriented guidance, not legal, compliance, or financial advice.
