Risk Tiering
Risk tiering is the practice of sorting things—such as AI use cases, models, or third-party vendors—into different levels, or tiers, based on how much risk each one poses to an organization. Grouping items this way helps an organization decide where to focus its attention, applying more oversight to higher-risk tiers and lighter oversight to lower-risk ones. The specific criteria and number of tiers vary by organization and by what is being tiered.
Risk tiering is a categorization process that ranks entities—commonly AI initiatives and use cases, or external vendors and suppliers—into discrete tiers according to their assessed potential impact, severity, and criticality. In an AI governance context, it typically involves classifying AI use cases by their potential impact on the organization to prioritize risk management and oversight resources; in a third-party risk context, it categorizes vendors according to the types of third-party risk most significant to the organization and their threat criticality. The evidence indicates that tiering supports prioritization of oversight rather than uniform treatment, though the specific scoring methods, tier definitions, and thresholds differ across the sources and are not standardized. Note that this entry reflects operational and vendor-oriented descriptions in the evidence; it does not establish a single authoritative definition, and the criteria for assigning tiers are context- and organization-dependent. Sector-specific meanings (for example, AI governance use-case tiering versus third-party/vendor tiering) should not be conflated.
Why it matters
Organizations typically face more AI use cases, models, and third-party vendors than they can subject to intensive oversight. Risk tiering addresses this by directing scarce governance and validation resources toward the entities that pose the greatest potential impact, rather than applying uniform scrutiny across the board. As the evidence describes, tiering supports the prioritization of oversight—allowing higher-risk tiers to receive deeper review, testing, and monitoring while lower-risk tiers receive proportionately lighter treatment.
Because tier assignment drives how much attention an item receives, the criteria used to assign tiers carry real consequences. A use case or vendor placed in too low a tier may escape the level of oversight its actual risk warrants, while over-tiering can waste resources and create review bottlenecks. The evidence indicates that scoring methods, tier definitions, and thresholds are not standardized and differ across sources and organizations, so the reliability of a tiering scheme depends heavily on how the criteria are defined and applied within a given context.
It is important not to conflate the distinct applications of tiering reflected in the evidence. AI governance use-case tiering ranks AI initiatives by their potential impact on the organization, while third-party (vendor) tiering categorizes external suppliers by the types of third-party risk most significant to the organization and their threat criticality. These serve related but different purposes, and the criteria appropriate for one may not transfer to the other. Tiering is also a prioritization mechanism, not a control that eliminates risk; it helps allocate oversight but does not by itself reduce the underlying risk of any tiered item.
Who it's relevant to
Inside Risk Tiering
Common questions
Answers to the questions practitioners most commonly ask about Risk Tiering.