# Initial risk assessment

## Context

- Use case / version:
- Evaluator(s):
- Date and next review:
- Jurisdictions / sectors:
- Switzerland scope and FADP role:
- EU scope and AI Act role:

## Classification

- Impact R0–R3 and rationale:
- Autonomy A0–A4 and rationale:
- AI task, interaction, knowledge, and deployment profile:
- Organization’s role in the AI value chain:
- Categories of affected people:
- Scale and frequency:

## Data

- Categories and sensitivity:
- Provenance and usage rights:
- Purpose:
- Location / transfers:
- Retention / deletion:
- Subprocessors:
- Reuse for training or improvement:

## Transparency and affected-person rights

- How people learn they are interacting with AI:
- How synthetic content is identified and its provenance retained:
- Human channel, challenge, and recourse:
- Automated individual decision and natural-person review:
- Switzerland-specific conclusion and source date:
- EU-specific conclusion and source date:

## Harm scenarios

| Scenario | Person / asset | Likelihood | Severity | Control | Residual risk | Owner |
|---|---|---|---|---|---|---|
| | | | | | | |

## Required assessments

- [ ] Legal qualification
- [ ] Data-protection impact assessment
- [ ] Fundamental-rights / non-discrimination assessment
- [ ] Threat model
- [ ] Security review
- [ ] Procurement / supplier review
- [ ] Independent audit

## Decision

- Accept / treat / transfer / avoid:
- Conditions:
- Authority accepting the residual risk:
- Date and signature:
