Five decisions, not two: how an assessment should end
An assessment whose only possible conclusions are "approved" and "not approved" is not an assessment. It is an approval process with a report attached, and everyone in the room knows which answer is expected.
Ask what an AI risk assessment produces and you will usually be told: a report. Ask what the report concludes and the answer narrows to two options — the system can go ahead, or it cannot.
Two options is the problem. It makes the assessment a gate, and a gate that stands between a team and a launch date has a predictable failure mode. The pressure is not to assess honestly; it is to find a form of words that lets the gate open.
What the two-outcome model does to the work
When only “yes” and “no” are available, everything ambiguous resolves toward yes. Risks that are real but manageable get written down softly, because writing them down firmly implies a “no” that nobody is prepared to give. Controls that do not yet exist are described as planned. Residual risk is characterised as acceptable without anyone naming who is accepting it.
The document that results is not dishonest, exactly. It is a document written by people who had two boxes and needed one of them to be tickable.
The five outcomes
Every assessment we run ends in one of five recorded positions. The list is short enough to remember and specific enough that choosing between the options requires thinking.
Proceed. Residual risk is acceptable as designed. Nothing further is required before the system operates.
Proceed with controls. Acceptable once named controls are in place and owned by named people. This is the most common outcome by some distance, and it is the one the two-outcome model destroys — under “yes or no” it becomes a “yes” with an unenforceable list attached.
Redesign. The residual position cannot be reached from this architecture. Not a refusal, a redirection: the thing being asked for may well be achievable, but not this way.
Escalate. A specialist or legal assessment is required before anyone can responsibly decide. Saying this plainly is often the most useful thing an assessment can do, and it is usually the outcome people are most reluctant to record, because it looks like not having an answer.
Do not proceed. The impact cannot be controlled to an acceptable level.
Why “do not proceed” has to be on the list
It is fair to point out that this outcome is rare. It is, and that is the point.
An assessment process that has never once concluded “do not proceed” has not demonstrated that everything assessed was safe. It has demonstrated that the conclusion is not available. The moment a team learns that the worst realistic outcome is a list of conditions, the assessment stops being a constraint and starts being an administrative step.
Keeping the option live — naming it, printing it, treating it as a genuine possibility — is what makes the other four outcomes mean anything. It is the same reason a control that has never failed a test has not been tested.
Getting to a position somebody will sign
The five outcomes only work if the assessment underneath them can be defended. In practice that means walking the same chain every time, in the same order: context, people, data, model, decisions, controls, residual risk. Seven stages, and the order matters — starting at the model, which is where teams instinctively start, produces an assessment of a component rather than of a system doing something to somebody.
Two habits do most of the work:
Test controls rather than collecting claims. “Access is restricted” is a claim. Attempting the access and recording what happened is a test. Assessments built on claims fail at exactly the moment they are needed, which is after an incident, when somebody checks.
Write the residual position in the language of the person signing. An accountable executive is being asked to accept something. They cannot accept a paragraph about model drift. They can accept “if this fails, the realistic consequence is X, the control that catches it is Y, and Z owns it”.
The conditional signature is a real outcome
The best result we see is not an unqualified approval. It is an executive who signs with three conditions attached and an owner against each — because that is a person who understood what they were accepting, and a set of obligations somebody can be held to later.
That is what a decision looks like when the process permits more than two of them. And it is the argument for building governance that produces positions rather than verdicts: an organisation that can say “yes, with these three things” moves faster than one that can only say yes or no, and it can defend the answer afterwards.