Part of the AI Regulation News hub.
The UK government has published non-binding guidance asking public sector AI teams to have their AI risk work led, ideally, by a named AI governance officer and to score every identified AI risk for likelihood and impact on a one to five scale
It still carries the vocabulary of a framework. The abbreviation RMF survives in the published text, and so does the word Framework in the file name of the workbook it ships with.
Bottom line: Guidance. It binds nobody. Nothing in the toolkit creates a legal obligation on a department, a supplier or an AI deployer, and the publication does not claim otherwise.
Who this affects: Public sector AI delivery, data science and engineering teams, departmental risk and assurance functions, commercial and procurement officers buying AI, and suppliers bidding for UK government AI work who may be asked about it.
Issue date: Published 8 September 2026 on GOV.UK. The workbook file that ships with it is named for version 1.1 and dated 22 May 2026, so the attached artefact predates the publication.
What changed: A government AI risk method is now published in one place: a guide, a set of risk identification questions across nine categories, a workbook and a risk monitoring dashboard, aligned to the Orange Book risk management processes.
Analysis: The substance is a scoring method and a named role. Our view is that the named role is the part with consequences, because it converts a diffuse question about AI risk into a person who owns it.
Primary sources: AI Risk Management Toolkit (publication page) · AI Risk Management Toolkit: guidance
- Instrument (EN)
- AI Risk Management Toolkit
- Authority
- Department for Science, Innovation and Technology. GOV.UK lists DSIT as the sole publishing organisation; the guidance separately names the Government Digital Service as the body encouraging a central AI risk log
- Jurisdiction
- United Kingdom, public sector
- Status
- Published guidance. GOV.UK labels the publication Guidance and records it as first published 8 September 2026
- Bindingness
- Non-binding. It imposes no legal duty on any department, supplier or deployer, and no enforcement mechanism appears in it
- Issue date / next deadline
- Published 8 September 2026. No deadline, consultation close or review date is stated
- Document
- Guidance in HTML, plus an AI Risk Management Framework workbook in XLS and ODS, both versioned V1.1 and dated 22 May 2026 in the file names
- Primary source
- https://www.gov.uk/government/publications/ai-risk-management-toolkit/ai-risk-management-toolkit-guidance
What the toolkit is, in its own words
The guidance opens by saying the toolkit is intended to support anyone involved in the design, operation, procurement and delivery of products empowered by or enabled by AI, and that it will benefit multi-disciplinary project teams navigating AI adoption, naming data science, engineering, project delivery, IT, change management and communications professionals.
It positions itself inside existing government machinery rather than beside it. The guidance says the toolkit aligns with the risk management approach in the Orange Book and is designed to implement Section D of that book, covering risk identification and assessment, risk treatment, risk monitoring and risk reporting. It also says the tools are designed to work with other established toolkits including the Cyber Assessment Framework.
Four components ship together: a guide to AI risk assessment, a set of critical questions, a workbook to record risks and treatment actions, and an AI risk monitoring dashboard. The guidance says an existing risk register may be used instead of the workbook if it tracks enough information for risks, mitigations and owners to be observed and updated.
None of this binds. It is guidance, and the piece you are reading treats every sentence of it as guidance, including the sentences written in the imperative.
The scoring method, which is the part with teeth in a business case
Impact and likelihood are each scored from 1 to 5, and the guidance says the risk score is the product of the two. It offers a five point likelihood scale with probability ranges attached: rare at under 5 per cent, unlikely at 5 to 20 per cent, possible at 20 to 50 per cent, likely at 50 to 80 per cent, and almost certain above 80 per cent.
The guidance acknowledges the difficulty this creates. It says there is a lack of historical data to derive assumptions from and offers four estimation methods: historical data analysis, model analysis, expert judgement, and experimentation and monitoring during Alpha and Beta stages. Under model analysis it names specific metrics, including accuracy, precision and recall for a classification model, precision for a recommendation engine and BERTscore for a language model.
On impact it splits quantifiable from non-quantifiable, and where a risk may produce several outcomes it offers two options: weight the outcomes to produce an overall score, or take the highest impact score. Those two methods do not always produce the same number, and the guidance does not say which to prefer.
Treatment options are set out in four categories: avoidance, limiting exposure, transference to third parties better placed to manage the risk, and acceptance where the risk sits within organisational tolerance. The guidance adds that an often overlooked option is a clear response plan for when a risk does occur.
Nine risk categories, and where automated decisions appear
The guidance lists nine categories for risk identification: financial, legal and regulatory compliance, appropriate transparency and explainability, fairness, accountability and governance, contestability and redress, technical robustness, security, and risks to people and the environment.
Automated decisions appear inside the financial category, where the guidance refers to potential financial implications from automated decisions. Contestability and redress is its own category, framed around whether a user or affected party can contest an output or seek redress, and whether accessible and transparent redress mechanisms exist.
Appendix 1 turns each category into questions. Among them the guidance asks which legal regimes have been considered at a minimum and lists human rights law, equality law including the public sector equality duty, data protection law giving UK GDPR as the example, intellectual property, the Social Value Act and applicable AI laws giving the EU AI Act as the example. It separately names the EHRC and the ICO and their guidance.
That list is a question, not a compliance schedule. The guidance asks whether those regimes were considered; it does not state what any of them requires, and neither do we.
The named role, and the central log
Nothing in this guidance obliges any department or supplier to staff anything, because the publication is guidance and creates no duty, but the wording repays reading as written rather than in paraphrase. The guidance says that "[a] multi-disciplinary team, referred to as the AI risk management team, is required to effectively drive active risk identification and management activities", and that "[y]our team should ideally be led by an identifiable individual known as an AI governance officer". It describes that officer as responsible for the implementation and oversight of processes, activities and policies relating to the use of AI within the organisation, directorate or team.
It then lists the other people it expects in that team: senior leaders who set risk appetite and tolerance, data teams, AI practitioners, the security team, legal and compliance professionals, business domain experts, and end users including both direct and indirect stakeholders.
There is also a reporting ask that suppliers and departments should notice. The guidance says the Government Digital Service encourages departments to keep a central log of AI risks and to share these with GDS and the DSIT central AI risk toolkit team, to help prioritise where investment in causal mapping and treatment design would give the most benefit. Encourages is the operative verb; nothing in the guidance compels the sharing.
On risk appetite the guidance is candid that this is the hard part. It says the appetite should ideally align with the department's wider appetite and be signed off at departmental board level, and that defining risk appetite is the most challenging aspect of any risk toolkit.
A wording conflict worth recording
The GOV.UK publication page and the guidance itself do not say the same thing in the same place. The publication page, under the heading Why risk management matters, reads: "You must understand and justify AI risks and treatment strategies to use AI responsibly and ethically." The guidance document says instead that "A clear understanding and justification of AI risks and treatment strategies is key to using AI responsibly and ethically."
We report the conflict rather than picking the stronger version. Neither sentence creates a legal obligation, because the publication is guidance in both places, but a summary page written in the imperative and a guidance document written in the indicative will be quoted differently by different readers.
A second observation, and this one is ours. The published text still carries the vocabulary of a framework, and the publication does not explain why. The guidance refers to the "Risk Management toolkit (RMF)" found in the Orange Book, where RMF is the abbreviation for a framework, and Appendix 1 repeatedly asks whether "legal toolkits" have been considered in places where the sense plainly requires legal frameworks. The workbook that ships with the publication is named AI Risk Management Framework workbook V1.1. We note the pattern because a reader searching the text for the word framework will not find what they expect, not because it changes any substance.
What we did not verify
What we opened: the GOV.UK publication page for the AI Risk Management Toolkit, including its metadata recording first publication at 8 September 2026, and the full guidance document at the publication's HTML path, read from the purpose section through the appendix 1 risk identification questions.
What we did not open: the AI Risk Management Framework workbook in either the XLS or the ODS format, the AI risk monitoring dashboard as an artefact, the Orange Book, the Cyber Assessment Framework, the AI Playbook for government, and the AI Standards Hub materials that the guidance links to. We did not read the whole of appendices 2 to 4, so we do not summarise the risk appetite statements, the full list of potential risk impacts or the treatment suggestions.
What we refuse to claim: we do not say any department, supplier or deployer is required to use the toolkit, score risks on its scale, appoint an AI governance officer or share a risk log, because the publication is guidance and states no obligation. We do not say it applies to the private sector. We do not say it is the government's first AI risk publication, because the document does not say so and it expressly builds on the Orange Book and sits alongside the AI Playbook. We give no count of departments using it, because the publication gives none.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
If you sell AI into UK government, assume the nine categories in appendix 1 become the shape of the questions in your next procurement, and, as our judgment rather than anything the guidance says, that contestability and redress is the category a supplier is least likely to have an evidence-ready answer for. If you run a public sector AI project, the sentence that will cost you time is the one asking for an identifiable individual to lead the risk work. Nothing here compels either thing. Guidance that is easy to quote tends to get quoted anyway.
Source File
Open the guidance and confirm four things: the likelihood table with its five probability bands, the sentence naming the AI governance officer as the leader of the AI risk management team, the nine risk categories in the AI risk identification section, and the passage saying GDS encourages departments to keep a central log of AI risks and share it.
A clear understanding and justification of AI risks and treatment strategies is key to using AI responsibly and ethically. ยท AI Risk Management Toolkit: guidance, Purpose of the toolkit, published 8 September 2026
FAQ
Does the toolkit oblige anyone to do anything?
No. It is published as guidance. It states no legal duty, names no enforcement route and sets no deadline. The imperative wording on the GOV.UK summary page does not change that.
Who is the AI governance officer and is the role mandatory?
The guidance describes an identifiable individual who ideally leads the AI risk management team and is responsible for implementation and oversight of processes, activities and policies relating to AI use in the organisation, directorate or team. The guidance uses ideally, and the publication creates no requirement to appoint anyone.
How does the scoring work?
Likelihood and impact are each scored from 1 to 5 and multiplied to give the risk score. The guidance attaches probability bands to the likelihood scale, from under 5 per cent for rare to above 80 per cent for almost certain, and where a risk may produce several outcomes it allows either weighting the outcomes to calculate an overall risk impact score or using the highest impact score.
Does it apply to companies outside government?
The publication is addressed to public sector AI adoption and refers throughout to departments and the Orange Book, which is government risk guidance. It contains nothing that extends it to private sector organisations, though suppliers bidding for government work may be asked about it.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.