Summary
Picture two requests sitting on your desk this week. One is an internal writing assistant helping a team draft meeting notes. The other is an agent authorized to change customer records. Send both through the same review process, and you get two predictable failures. The right level of artificial intelligence (AI) governance depends on what a use case can see, decide, change, and expose. Treating them identically punishes one and endangers the other.
A public research workflow raises different concerns than a system processing medical or financial information. Applying one control standard to everything creates the same two failures every time. Your low-risk workflows get trapped in reviews that add little protection, and your high-risk workflows receive generic controls that miss their real consequences.
The National Institute of Standards and Technology’s (NIST) AI Risk Management Framework supports a risk-based approach, recommending more oversight for systems carrying less risk tolerance. The European Union’s AI Act uses risk categories for the same reason, applying different legal obligations across different uses. Your internal governance model should support those legal requirements, not replace them. Let the governance decision follow the use case itself. The product name, model provider, or department can never determine the tier on its own.
Keep internal tiers and legal classifications separate
An internal tier helps you manage your own AI portfolio. A legal classification determines actual obligations under applicable law, and the two can diverge in both directions. A use case can score low internally while still triggering a specific legal requirement. A use case can also fall outside any named legal category while still creating real customer or reputational exposure. Weigh applicable law, contractual obligations, company policy, and public expectations together in your internal governance. Never let a favorable internal score reduce a mandatory legal or contractual control.

Use five factors to set the tier
Score five factors from one to five each: data sensitivity, decision impact, system autonomy, external exposure, and reversibility. A low score means less governance pressure. A high score means more. The total score sets an initial tier, and hard gates override that number whenever a specific condition demands it regardless of the math.
Data sensitivity
This factor measures the possible harm from unauthorized access, exposure, or reuse, covering both the input and whatever the workflow generates. A workflow can receive public data and still produce a confidential strategic recommendation. Put the complete information path in the review, not only the starting point.
- One point: the workflow uses public information approved for the stated purpose.
- Two points: the workflow uses internal information with limited expected harm.
- Three points: the workflow uses selected confidential information inside an approved environment.
- Four points: the workflow uses substantial confidential information or limited restricted information.
- Five points: the workflow uses restricted information with serious legal, human, financial, or security consequences.
Trigger specialist review before scoring continues whenever a factor earns a five-point rating. Keep some restricted information, credentials, government IDs, protected medical data, outside general AI workflows entirely, relying on masked values or references instead.
Decision impact
This factor measures how the output can affect people, finances, operations, and company commitments, judged against the final business action, not the output’s apparent tone. A model-generated summary looks low-impact until a manager uses it to deny an employee’s promotion.
- One point: the output supports low-impact administrative or creative work.
- Two points: the output influences routine internal work with limited consequences.
- Three points: the output influences customer, financial, or operational decisions with manageable effects.
- Four points: the output can create material customer, employee, financial, or reputational consequences.
- Five points: the output can affect rights, employment, safety, essential services, or legal obligations.
A five-point rating places the use case in the highest tier automatically. Keep human authorization mandatory for the final decision regardless of how well the system performs.
System autonomy
This factor measures the authority a workflow holds after producing an output. Drafting a recommendation carries far less autonomy than sending it directly to a customer. Autonomy can also build through connected systems, since a model can lack direct authority while its output automatically triggers another application downstream. Follow that complete chain in your review, not only the visible step.
- One point: the system offers optional assistance without changing records or completing actions.
- Two points: the system prepares work for human review and approval.
- Three points: the system completes low-impact internal actions inside defined limits.
- Four points: the system completes external or consequential actions with limited human involvement.
- Five points: the system makes or executes material decisions without case-level human approval.
A five-point rating requires executive and specialist review. Keep some autonomous actions outside your company’s risk tolerance regardless of technical capability.
External exposure
This factor measures who receives, experiences, or depends on the output, including people affected indirectly who never see it at all. An internal recommendation can still create real external effects the moment another system applies it to a customer.
- One point: the output stays inside a low-risk internal workflow.
- Two points: the output reaches a small group of qualified employees.
- Three points: the output reaches wider internal users or supports routine customer work.
- Four points: the output reaches customers, partners, regulators, or the public.
- Five points: the output directly affects identifiable people’s rights, employment, finances, or safety.
Build stronger controls into external communication whenever recipients might reasonably assume the company already verified it. Include a correction or appeal route wherever people experience material effects.
Reversibility
This factor measures whether you can restore the complete situation after an error, not only the database value. A record can roll back cleanly while a customer has already acted on the incorrect message it produced. An employee may have already experienced the decision it created too.
- One point: errors are easy to identify and reverse completely.
- Two points: errors are reversible with limited effort and consequence.
- Three points: correction requires several steps or creates moderate disruption.
- Four points: errors are difficult to reverse completely.
- Five points: errors can create permanent, widespread, or serious human and business effects.
Give a difficult-to-reverse action stronger review before execution. Test recovery before launch, rather than assuming an undo button covers it.
Turn five factors into one tier
The five factors form a 100-point governance score. Data sensitivity carries 20 points, decision impact 25, autonomy 20, external exposure 20, and reversibility 15. Score each factor from one to five, divide by five, and multiply by its weight. A decision-impact rating of four earns 20 of its 25 possible points.
- 20 to 39 points: Tier One. Low impact, low autonomy, limited exposure, strong reversibility.
- 40 to 59 points: Tier Two. Internal business risk, confidential information, or moderate authority.
- 60 to 79 points: Tier Three. Effects on customers, finances, employees, or important operations.
- 80 to 100 points: Tier Four. High impact, high autonomy, restricted data, or difficult-to-reverse conditions.
The score guides the decision. Hard gates keep it from hiding an unacceptable condition underneath a comfortable average.
Let hard gates override the score
Several conditions require Tier Four review or outright prohibition regardless of the weighted total. These include a use case that appears prohibited under applicable law, and a workflow using restricted data without an approved environment. A system making adverse employment decisions without qualified human authorization also qualifies. The same is true for a system that determines access to credit, healthcare, or housing. The same applies to systems that can create material contractual commitments, release significant payments, control safety-related equipment, or delete important records without recoverable controls.
If the business owner, data owner, or risk owner remains unnamed, that is a gate on its own. The EU AI Act separately identifies prohibited practices and high-risk obligations that need qualified counsel’s analysis, not an internal score. A Tier Four classification identifies a use case that has earned your company’s highest level of scrutiny. It does not mean automatic approval.

Know what each tier requires
Tier One covers narrow, low-impact use cases using public or low-sensitivity information. A person decides whether to use the output, and errors create limited inconvenience. The business owner can approve it under existing policy, with no separate committee review required. The employee reviews the output through normal professional judgment rather than a formal queue. Monitor usage, cost, and reported incidents on a quarterly or semiannual cycle. Documentation is a short use case card: purpose, owner, approved product, permitted data, and next review date.
Tier Two covers meaningful internal work with limited external exposure. A person stays responsible for consequential decisions, and the workflow may update low-impact internal records. Approval should include the business, process, and data owners, plus a governance or privacy reviewer whenever confidential data enters the picture. The review model can shift from full review during the pilot to sampled review once performance stabilizes. Monitor adoption, correction severity, and business outcomes monthly, with immediate escalation for material incidents. Documentation extends to a full workflow record with test results and defined exception paths.
Tier Three covers consequential business workflows touching confidential data, external audiences, or real system authority. Approval needs representation from the business function, technology, data ownership, security, privacy, and the affected operational team, documenting approval, conditional approval, restriction, or rejection explicitly. Full review applies to material commitments, pricing exceptions, and external claims. Stable normal cases can earn sampled or escalation-only review once the evidence supports it. Monitor weekly or monthly depending on volume, with continuous detection for high-impact alerts. The documentation package includes a formal impact assessment, representative test results, and an audit schedule.
Tier Four covers restricted or high-impact uses with serious human, legal, financial, or safety consequences, some of which should stay prohibited outright. Approval needs the accountable executive, legal counsel, compliance, security, and independent risk representation, sometimes an executive risk committee. Material decisions require qualified human authorization from a reviewer who can understand the system’s limits, recognize automation bias, and stop the workflow. Case-level human presence cannot compensate for weak evidence or unclear authority on its own. Monitoring is continuous: independent audits, red-team exercises, and executive reporting. Documentation is a complete system dossier covering legal review, known limitations, decision records, and a formal retirement plan.

Watch one workflow span every tier at once
Consider an AI-supported customer renewal process. Formatting public company information for internal preparation is Tier One. Summarizing approved account history for the assigned account owner is Tier Two. Recommending a renewal strategy using confidential commercial information is Tier Three. Changing contractual pricing or sending a binding offer without approval is Tier Four.
Separate these activities in the workflow rather than averaging them into one score. A single blended rating can quietly hide the one action that deserves the highest scrutiny. Score every meaningful output, decision, and action on its own terms. Let the governance tier follow the highest-risk action inside the workflow, not the average of everything around it.
Keep data sensitivity and decision impact as separate scores too. Sensitive data does not always create a high-impact decision. A controlled summary of confidential records for an authorized employee can stay low-impact. Public data can still drive a high-impact decision, the way a hiring model built on public professional profiles still affects real employment access. Confidential data needs access and retention controls. Consequential decisions need human oversight and appeal routes. Neither control group substitutes for the other.
Apply the same pattern across your functions
Marketing spans every tier. An assistant converting an approved article into internal drafts is Tier One. Confidential campaign analysis is Tier Two, and customer-specific offers using account and pricing data are Tier Three. An autonomous system changing eligibility or regulated claims for individual customers is Tier Four. Sales follows the same arc from public account research through binding commercial commitments. Separate research, recommendation, communication, and commitment into distinct governance decisions rather than one blanket approval.
Finance needs a clean split between processing and authority. Formatting a reporting template is Tier One. A workflow releasing material payments or changing accounting treatment is Tier Four, regardless of how routine the surrounding automation looks. Human resources carries the narrowest defaults of any function. A system making adverse employment decisions without meaningful human authorization needs legal, compliance, and executive review before any pilot begins. Operations moves from routine status updates toward safety-related control. An autonomous system touching critical infrastructure or emergency instructions needs a governance model built around peak volume, failure, and recovery, not convenience.
End every review in one of five decisions
A review should end in one of five outcomes:
- Approval within the documented purpose and controls.
- Conditional approval requiring specific work before launch.
- Pilot approval within a limited population and a firm decision date.
- Restriction, where the business need stays valid but specific data or actions remain prohibited.
- Rejection, where the exposure cannot come down to an acceptable level. NIST’s guidance explicitly includes approval, conditional approval, disapproval, and decommissioning as legitimate governance outcomes, not only a pass-fail gate.
Trigger reassessment when conditions materially change
An approved use case can drift into a higher tier after launch without anyone deciding that on purpose. Trigger reassessment after any change to the business purpose, data classification, affected population, model or provider, permissions, level of autonomy, or a material incident. A marketing assistant approved for internal drafts that later starts publishing automatically has increased its own autonomy and exposure. A sales assistant that starts pulling customer service records has increased its data sensitivity. Never let the original approval stretch automatically to cover the expanded use.
Run this decision tree for the initial tier
Does the use case appear prohibited or legally restricted? If yes, stop and get specialist review immediately. Does the workflow use confidential or restricted information? If yes, start at Tier Two at minimum. Can the output materially affect customers, employees, finances, safety, or legal obligations? If yes, start at Tier Three.
Can the system complete actions without case-level human approval? If yes, assess Tier Three or Four based on the action itself. Does the output reach customers, regulators, or the public? If yes, assess Tier Two or Three based on impact. Can you reverse errors completely and quickly? If not, raise the tier by at least one level before finalizing the score.
Run this 30-day process to assign the first tier
Week one. Define the use case. Map the workflow from trigger through completed business action, and identify the data, users, and affected people involved.
Week two. Score the five factors with evidence behind every rating, then apply the hard gates before anything else proceeds.
Week three. Design the tier requirements. Assign the approval group, review model, monitoring plan, and documentation, then define pilot limits and reassessment triggers.
Week four. Test the controls with representative work and realistic system connections, including monitoring, escalation, and shutdown procedures. Approve the tier once the operating evidence supports it. Enter the use case into your AI register with its owner and next review date.
What you tell them at the end
AI governance needs proportion, not uniform friction applied everywhere. Low-risk assistance should move through a fast, clear approval path. Consequential business workflows need cross-functional approval and real operating evidence behind them. High-impact uses need executive accountability and independent validation before anyone calls them safe.
The five-factor model gives you one consistent basis for making that call. Greater risk earns greater oversight, and lower risk earns clear boundaries without unnecessary delay. A governance model succeeds the moment employees can understand it and leaders can apply it the same way twice. Your owners also need to be able to operate it after approval.

