Track 05Operational GuardrailsLocked by prerequisiteRecommended

Risk Assessment & Risk Recognition

Develop the ability to recognise AI risk during ordinary work and to select controls that are proportionate to patient, product and process impact.

6 lessons · 5 frameworks · 4–5 hours · 0/6 complete · 0/6 exercises recorded

Locked by prerequisite

This track opens once its prerequisites are complete. Prerequisites are sequenced deliberately: each one supplies a competency this track assumes you already hold.

  • Track 01 — AI Fundamentals
  • Track 02 — AI Governance & Regulatory Expectations

Orientation

Why this matters

Formal risk assessments happen before deployment. Risk itself happens on a Tuesday afternoon, to whoever is using the tool. Recognition in the moment is the control that formal assessment cannot provide.

What you will be able to do (5)

  • Categorise AI risk in life-sciences terms
  • Assess patient, product and process impact for a specific use
  • Distinguish data, model and output risk and their different controls
  • Select controls proportionate to the assessed risk
  • Recognise emerging risk during routine use and escalate it with evidence

Aligned with (5)

ICH Q9(R1) — quality risk managementNIST AI Risk Management Framework 1.0ISO/IEC 23894 — AI risk management guidanceEU AI Act — risk tiering conceptsGAMP 5 (2nd Edition) — risk-based approach

Maps to published expectations. Competency demonstrated through assessment.

Regulatory alignment indicates that curriculum topics map to published regulatory expectations. It does not constitute agency approval, certification, legal advice or a determination of organizational compliance.

View source evidence, status and applicability

ICH Q9(R1) — quality risk management

Harmonised guidelineICH regions; implemented through regional frameworks
ICH Q9(R1) — Quality Risk Management
Relevant provisions
Sections 4–6 and Annexes I–II
Status and date
Step 4, 18 January 2023. Implementation depends on the relevant regional authority and regulated activity.
Why it maps
Supports the track's stated mapping to ICH Q9(R1) — quality risk management without transferring duties beyond the source's scope.
Applicability limit
Supplies quality-risk principles. It does not independently classify an AI system or prescribe one universal control set.

Primary source last verified 2026-08-24

NIST AI Risk Management Framework 1.0

Voluntary frameworkNon-sector-specific; international use
NIST AI Risk Management Framework 1.0
Relevant provisions
GOVERN, MAP, MEASURE and MANAGE functions
Status and date
26 January 2023. Voluntary; AI RMF 1.0 is under revision as of August 2026.
Why it maps
Provides a voluntary operating structure for the risk-management decisions practised in the lesson.
Applicability limit
Provides risk-management outcomes and practices. It does not create a legal mandate unless adopted through contract, policy or another authority.

Primary source last verified 2026-08-24

ISO/IEC 23894 — AI risk management guidance

Consensus standardInternational consensus standard
ISO/IEC 23894:2023 — Guidance on AI risk management
Relevant provisions
Clauses 5–8: principles, framework and AI risk-management process
Status and date
February 2023. Voluntary guidance unless adopted by contract or policy.
Why it maps
Supplies a recognised management or assurance practice; it is identified as non-binding unless separately adopted.
Applicability limit
Supports integration of AI-specific risks into organisational risk management; it is not a sector-specific legal rule.

Primary source last verified 2026-08-24

EU AI Act — risk tiering concepts

Binding lawEuropean Union
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Relevant provisions
Article 6 and Annex III — classification; Articles 9–15 — high-risk requirements
Status and date
Official Journal, 12 July 2024. Entered into force 1 August 2024; phased application through 2 August 2027.
Why it maps
Connects the lesson to the Act's conditional duties while preserving classification, role and application-date limits.
Applicability limit
Specific duties depend on system classification, actor role, territorial scope and the applicable date. No duty should be extended beyond those conditions.

Primary source last verified 2026-08-24

GAMP 5 (2nd Edition) — risk-based approach

Industry guidanceInternational industry practice
ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd ed.
Relevant provisions
Lifecycle, intended use, critical thinking, supplier involvement and risk-based assurance
Status and date
July 2022. Non-binding unless adopted by an organisation, contract or authority.
Why it maps
Supplies a recognised management or assurance practice; it is identified as non-binding unless separately adopted.
Applicability limit
Widely used industry guidance. It must not be described as legislation or a regulator-issued mandate.

Primary source last verified 2026-08-24

Full source register and editorial method →

Credential

Life Sciences AI Risk Recognition Badge

Duration

4–5 hours

Audience

  • Quality, validation and manufacturing professionals
  • Functional leaders accountable for AI-enabled processes
  • All users of AI in GxP-relevant work

Prerequisites

  • Track 01
  • Track 02

Behaviours practised (3)

UnderstandVerifyEscalate
An AI tool that has performed well for eight months begins producing summaries that are subtly shorter. No alert fires. No threshold is breached. The first person who can notice is the analyst reading the output — and only if they know what they are looking for.

Badge requirements (5)

  1. Complete all six lessons and their knowledge checks
  2. Achieve at least 80% across the final badge assessment
  3. Answer every safety-critical question correctly
  4. Produce a control set containing preventive, detective and corrective controls
  5. Produce an escalation record identifying affected records and interim action

Lessons (6)

Final badge assessment

Life Sciences AI Risk Recognition Badge

  • Risk categorisation and impact

    Mixed multiple-choice and select-allSafety-critical

    Categorise and size risk across six AI uses spanning clinical, quality and manufacturing.

  • Control selection

    Match a control to a risk

    Select proportionate preventive, detective and corrective controls for four AI uses.

  • Escalation determination

    Choose the correct escalation pathSafety-critical

    Determine the correct route and interim action for four observations of differing severity.

  • Practical exercise — escalation record

    Practical exercise

    Produce a complete escalation record for a risk affecting approved records.

Next recommended track

← All tracks