Skip to content
  • There are no suggestions because the search field is empty.

Risk Model Fundamentals

 What this article covers

This article covers the core mechanics of the Trustible risk model that every user should understand before working with a use case's risk score:

  • How the Risk Questionnaire differs from a vendor questionnaire
  • The five risk categories and what each one measures
  • How an individual category score is calculated
  • How the Overall Risk Level is calculated from the five categories
  • How to review exactly why a use case scored the way it did

 Risk questionnaire vs. vendor questionnaire

These two tools measure different things, and mixing them up is the most common source of confusion.

  • The Trustible Risk Questionnaire measures inherent risk: how risky the AI use case is by nature, based on what it does, what data it touches, and who it affects.
  • A vendor questionnaire is a controls checklist: it measures whether a third-party vendor has the safeguards in place, not how risky the use case itself is.

A use case can score High inherent risk even if the vendor has excellent controls, and a use case can score Low inherent risk even from a vendor with a thin controls program. Keep the two separate in your reporting and conversations.

The five risk categories

Every AI use case is scored across five categories. Each category reflects a different kind of harm:

  • Performance: the risk that the AI system is inaccurate, inappropriate for the task, or fails during operation.
  • Data Privacy: the risk associated with the personal, sensitive, or regulated data the system processes.
  • Cybersecurity: the risk tied to system access, model source, network exposure, and how the system could be misused or attacked.
  • Ethical: the risk of unfair, biased, or harmful outcomes, including impact on vulnerable populations.
  • Legal: the risk of regulatory, contractual, or liability exposure created by the use case.

How a category score is calculated

Each answer you give in the Risk Questionnaire is tied to one or more attributes (for example, Generative AI, Direct User Input, Analysis Tool). Attributes trigger rules, and each triggered rule adds or subtracts risk points in the categories it applies to. Some rules trigger on a single attribute; combination rules trigger only when two specific attributes appear together, which lets the model capture compounding risk without a lengthy list of one-off questions.

A category's final score falls into a range: Very Low, Low, Medium, High, or Very High. You can see the exact point total and every rule that contributed to it at any time (see “Reviewing how a score was calculated” below).

How the overall risk level is calculated 

Key point: The Overall Risk Level is the average across the five category scores. It is not additive, and a single High or Very High category does not automatically push the Overall rating to High on its own. 

This is by design: it keeps the model consistent and prevents any one category from silently dominating the result. If your organization wants a severe condition in one category to move the Overall rating, the way to do that within the model is to increase the weighting of the rule tied to that condition so it raises the score across every category it touches by enough to shift the average. This keeps the logic transparent and auditable rather than adding a hidden override step.

Trustible does not currently offer a native “risk floor” or override rule that forces the Overall rating to match a single category regardless of the average. If this matters to your program, raise it with your Customer Success Manager. It has been logged as product feedback (see the Outstanding Functionality Log).

Recommended vs. confirmed values

The rule-driven score is always a recommendation. A human reviewer confirms the Overall Risk Level on the use case record, and this human-in-the-loop step is intentional. Before an Overall Risk Level has been confirmed, the confirmed/overridden values and the reviewer's rationale are visible directly on the Risk tab. Once the Overall Risk Level is confirmed, you can see that same information again by selecting the edit pencil on the Risk tab.

Reviewing how a score was calculated

Every risk category has a small lightbulb icon next to it on the use case record. Selecting it opens the Risk Rule Explanation view, which lists every rule that triggered for that category, the number of points it contributed, and the attribute(s) that caused it to fire. This is the fastest way to answer “why did this use case score the way it did,” and it works the same way whether you are questioning a Low score or a High one.

Frequently asked questions

Q: If a severe condition is triggered, does that guarantee a High overall rating?

A: Not automatically. The Overall rating is always the average of the five categories. To make a severe condition drive the Overall rating to High, increase that rule's weighting so it raises the score in every category it touches by enough to shift the average.

Q: Is the overall score additive or normalized?

A: Normalized. Trustible averages the five category scores; it does not add them together.

Q: Does completing the Risk Questionnaire mean the answers have been validated, or only that every question was answered?

A: Only that every required question was answered. Trustible does not natively assess whether an answer is accurate or well-supported; that judgment remains part of the reviewer's role, typically during the Review Loop task.

Q: Can we keep a small number of hard escalation points outside the scoring model?

A: This depends on what you need. If you want a condition to always force a High rating regardless of score, that is a rule-weighting exercise as described above. If you want a condition to simply trigger a task for someone to review manually, that can be configured through workflow triggers. Reach out to support@trustible.ai to design the right approach.