Skip to main content
Category: Trustworthy AI Principles

Proportionality

Also known as: proportionality principle
Simply put

Proportionality is the idea that a response or measure should be balanced against the situation it addresses, rather than being excessive or insufficient. In its most general sense, it describes a matching or consistent relationship between two things. The way the term is applied varies significantly depending on the field, from mathematics to human rights law to the use of force in international law.

Formal definition

Proportionality is a principle whose meaning is strongly context-dependent across disciplines. In mathematics, it refers to the relationship between two equivalent ratios, expressed as a proportion, such that one quantity varies consistently with another. In human rights law, proportionality involves identifying the available options and selecting the one least restrictive of a person's rights. In international law, it dictates that the use of force be balanced against the threat or grievance that provoked it. The evidence provided does not establish a settled definition specific to AI governance or model risk management, and practitioners should treat any such application as an extension of these general principles rather than a fixed, authoritative definition. Where the term appears in AI or risk contexts, its precise scope should be confirmed against the governing framework or guidance in use.

Why it matters

Proportionality is a term that experts encounter across multiple disciplines with meaningfully different definitions, and this is precisely why it demands careful handling. The evidence establishes distinct usages in mathematics (a consistent relationship between two equivalent ratios), human rights law (selecting the option least restrictive of a person's rights), and international law (balancing the use of force against the threat or grievance that provoked it). These are not interchangeable, and treating them as a single unified concept invites the kind of conceptual slippage that undermines precise regulatory and operational reasoning.

For practitioners in AI governance and model risk management, the significance is largely a matter of caution. The evidence provided does not establish a settled, authoritative definition of proportionality specific to AI governance or model risk management. Where the term surfaces in AI or risk contexts, it should be understood as an extension of the general principle of matching a response to the situation it addresses, rather than as a defined term with fixed scope. Assuming a precise AI-specific meaning that the governing framework does not actually supply is a common and consequential error.

The practical stakes are that misapplied proportionality language can either overstate or understate what a framework requires. Because the term's meaning is strongly context-dependent, its precise scope should always be confirmed against the specific framework, guidance, or legal instrument in use before it is relied upon to justify a control, an exemption, or the intensity of an oversight measure.

Who it's relevant to

AI governance and policy specialists
Those drafting or interpreting governance policies may encounter proportionality language borrowed from legal or general usage. They should confirm the intended meaning against the specific framework in use rather than assuming a fixed AI-specific definition, since the evidence does not establish one.
Legal and compliance professionals
Practitioners working across human rights, international law, or regulatory contexts should be alert that proportionality carries distinct, discipline-specific meanings. In human rights law it concerns selecting the least restrictive option, while in international law it concerns balancing force against a threat or grievance; these are not interchangeable.
Model risk managers and auditors
Those who see proportionality invoked to justify the intensity of a control or the scope of oversight should treat it as an extension of a general balancing principle rather than a settled term, and should verify its precise scope against the governing guidance before relying on it.

Inside Proportionality

Risk-based calibration
The core idea that the intensity of governance, controls, validation, and oversight applied to a model or AI system should be scaled to the level of risk it presents, rather than applied uniformly across all systems.
Risk tiering or classification
A structured approach to categorizing models or AI systems by factors such as materiality, complexity, potential for harm, and business impact, which then determines the depth of required controls. Note that specific tiering schemes vary by organization and are not standardized across frameworks.
Materiality and impact assessment
Consideration of the significance of a model's use, including financial exposure, affected populations, and consequences of error, as inputs to how much scrutiny is warranted. Definitions of materiality differ between banking model risk contexts and broader enterprise AI contexts.
Regulatory basis
Proportionality appears as a stated or implied principle in several instruments, including risk-based approaches discussed in the NIST AI Risk Management Framework (a voluntary framework issued by NIST), tiered obligations in the EU AI Act (binding EU law), and the expectation in model risk guidance such as SR 11-7 that oversight be commensurate with risk. The precise formulation and legal weight differ by instrument and jurisdiction.
Documentation of rationale
The practice of recording why a given level of control was deemed appropriate for a given risk level, so that proportionality decisions are traceable and defensible rather than ad hoc.

Common questions

Answers to the questions practitioners most commonly ask about Proportionality.

Does proportionality mean that low-risk AI systems require no governance or oversight at all?
No. Proportionality, as commonly applied, calibrates the intensity of controls to the assessed level of risk rather than switching oversight on or off. Lower-risk systems typically warrant lighter-touch measures, but this is usually distinct from an exemption from all governance. Some baseline expectations, such as inventory, ownership, and periodic reassessment, often still apply. Where a specific framework or regulation actually exempts a category of system, that exemption is a feature of that instrument, not a general implication of proportionality itself.
Is proportionality a single, uniform standard that applies the same way across all frameworks and jurisdictions?
No. Proportionality is a shared principle rather than a single harmonized rule, and its operational meaning varies by context. The way it is expressed and enforced can differ between voluntary standards, supervisory guidance, and binding law, and between sectors such as banking model risk management and broader enterprise AI governance. Treating one framework's articulation of proportionality as authoritative across all others is a common error. Confirm how the specific applicable instrument defines and scopes proportionality before relying on it.
How do organizations typically decide what level of control is proportionate for a given AI system or model?
Many organizations base this on a risk assessment or tiering exercise that considers factors such as the system's use case, potential impact on individuals or the business, materiality, complexity, and the degree of autonomy in decision-making. The resulting risk tier is then mapped to a corresponding set of control expectations. The specific factors and thresholds used are typically defined in internal policy and can vary considerably between institutions, so the criteria should be documented and applied consistently.
How is a proportionate approach usually documented so it can withstand review or audit?
In practice, organizations tend to record the rationale for the assigned risk tier, the criteria used to reach it, and the specific controls applied as a result. Documenting why a lighter-touch approach was considered appropriate is often as important as documenting the controls themselves, because reviewers and auditors typically assess whether the calibration was reasoned and consistent rather than simply whether controls exist. Contested or borderline classifications may warrant additional explanation.
How does proportionality interact with the three lines of defense?
Proportionality can influence the depth and frequency of activity across the lines of defense without altering their distinct roles. For example, the intensity of first-line controls, the rigor of second-line review or challenge, and the scope of third-line assurance may all be scaled to the assessed risk. The separation of responsibilities among the lines is generally maintained regardless of tier; proportionality typically affects how much scrutiny each line applies, not whether the lines exist.
How often should proportionate risk classifications and control levels be reassessed?
There is no single universally mandated cadence. Many governance and model risk programs reassess classifications periodically and also upon trigger events, such as a change in use case, a material change to the model, a shift in data, or observed performance degradation, since these can alter the risk profile and therefore the level of control that is proportionate. The appropriate frequency is typically set in policy and may itself be scaled to risk, with higher-risk systems reviewed more often.

Common misconceptions

Proportionality means low-risk systems require no governance or controls.
Proportionality typically calls for lighter-touch, not absent, controls for lower-risk systems. Some baseline oversight, inventory, and accountability commonly remain expected regardless of tier, and misclassifying a system as low risk can itself create risk.
A single proportionality or risk-tiering scheme applies across all regulations and standards.
Risk categorization and the obligations attached to each level differ between instruments such as the EU AI Act, the NIST AI RMF, and model risk guidance like SR 11-7. These are issued by different bodies, carry different legal weight (binding law versus voluntary framework versus supervisory guidance), and are not interchangeable.
Applying proportionate controls to a high-risk system eliminates its risk.
Proportionality governs how much control effort is allocated relative to risk; it manages and reduces risk but does not remove it. Residual risk typically remains even after controls calibrated to the risk level are applied.

Best practices

Establish a documented risk-tiering methodology with defined criteria (such as materiality, complexity, and potential for harm) so that the level of controls applied to each model or AI system is consistent and traceable.
Record the rationale behind each proportionality decision, including why a given control intensity was judged appropriate, to support internal review and external examination.
Map your proportionality approach to the specific instruments that apply to your context, recognizing that the EU AI Act, the NIST AI RMF, and model risk guidance such as SR 11-7 differ in scope, jurisdiction, and legal weight.
Maintain baseline governance and inventory for all systems regardless of tier, so that lower-risk classifications do not become gaps in oversight.
Periodically revisit risk classifications, since a model's risk profile can change with new use cases, data, or business impact, and an initial tier may no longer reflect current exposure.
Distinguish inherent risk from residual risk when calibrating controls, and communicate that proportionate controls reduce rather than eliminate risk.