Domain I · Area I-CA2 · Responsible AI use, grounding and model-risk control
I.7Assess AI use cases, limitations, bias and model risk
Working Draft version 1.1
Purpose and scope
This unit covers the capability to identify and assess risks arising from AI use in sustainability reporting, including hallucination, omission, bias, context loss, prompt sensitivity, model and version variability, inappropriate generalisation, automation bias, adversarial or injected instructions, vendor opacity and overreliance. It includes use-case risk classification, evaluation, restricted and prohibited uses, controls, monitoring, model or configuration change and incident response.
Applied competency statement
Can assess AI reporting use cases and model limitations, bias and other risks, define permitted, restricted and prohibited uses and establish proportionate evaluation, control, monitoring and change requirements.
Boundary and escalation
This unit owns AI use-case and model-risk assessment, permitted, restricted and prohibited use, evaluation and monitoring. F.1 owns general reporting-risk and control objectives and I.9 owns enterprise governance, inventory and lifecycle decisions. It does not constitute AI audit, regulated conformity assessment, cyber-security testing or specialist model validation.
Key quality risks
One risk rating applied to every AI use; model reputation treated as validation; bias considered only as demographic bias and not source, language, geographic, sector, survivorship or framing bias; prompt and context injection ignored; version updates accepted without regression testing; model output variability not assessed; low-frequency high-consequence error dismissed; high-risk legal, materiality, assurance or publication use permitted with a generic human-review statement; monitoring limited to usage volume; and incidents or unsafe uses not recorded or restricted.
I.7-K01
Understands how purpose, intended users, affected decisions, materiality, reversibility, scale, sensitivity, autonomy and human review influence use-case risk.
Knowledge Type: AI use-case risk · Normative Weight: Core
I.7-K02
Understands hallucination, omission, context loss, prompt sensitivity, stochastic variation, source and knowledge limits, model or version drift, latency, availability and vendor opacity.
Knowledge Type: Model and output limitations · Normative Weight: Core
I.7-K03
Understands source, training, language, geographic, cultural, sector, historical, selection, framing, confirmation and automation bias and the limits of generic fairness claims.
Knowledge Type: Bias and representativeness · Normative Weight: Core
I.7-K04
Understands prompt injection, malicious or irrelevant instructions in retrieved content, data poisoning, tool misuse, unsafe action execution and cascading automated errors.
Knowledge Type: Adversarial and workflow risks · Normative Weight: Core
I.7-K05
Understands use-case test sets, expected and unacceptable outcomes, accuracy and completeness measures, edge cases, robustness, regression, human-review effectiveness, incidents and monitoring.
Knowledge Type: Evaluation and monitoring · Normative Weight: Core
I.7-K06
Understands risk ownership, permitted and restricted use, exception approval, version and vendor changes, retirement and the distinction from legal assessment, algorithmic audit and specialist model validation.
Knowledge Type: Governance and professional boundary · Normative Weight: Core
I.7-S01
Define the AI use case, affected reporting decisions, users, data, model or service, autonomy, materiality, reversibility and control environment.
Skill Type: Core applied capability · Observable Output or Result: AI use-case and model-risk assessment
I.7-S02
Identify factual, completeness, bias, context, adversarial, security, privacy, vendor, operational and human-overreliance risks and assess their significance.
Skill Type: Risk analysis · Observable Output or Result: AI risk and failure-mode analysis
I.7-S03
Classify uses as permitted, restricted or prohibited and define required source, review, approval, specialist and technical safeguards.
Skill Type: Use restriction design · Observable Output or Result: Permitted, restricted and prohibited-use register
I.7-S04
Design representative tests, edge cases, unacceptable outcomes, regression and human-review checks and document results and residual limitations.
Skill Type: Evaluation and testing · Observable Output or Result: AI evaluation and test record
I.7-S05
Define incident, drift, performance, version, vendor and use-change monitoring and route remediation, restriction, suspension or retirement.
Skill Type: Monitoring and change control · Observable Output or Result: AI evaluation, monitoring and change plan
I.7-B01
Does not permit a high-consequence reporting use merely because a human reviewer is nominally present or the tool is widely used.
Behaviour Type: Risk-based restraint · Non-compensable Requirement: No
I.7-B02
Does not describe a model as neutral, accurate or validated without use-case-specific evidence and disclosed limitations.
Behaviour Type: Bias and limitation transparency · Non-compensable Requirement: No
I.7-B03
Does not assume that a model, vendor or configuration update preserves prior behaviour without proportionate regression and control review.
Behaviour Type: Change vigilance · Non-compensable Requirement: No
Typical tasks · 4
I.7-T01
Document the AI use case, model or service, users, data, decisions, scale, autonomy, review, reversibility and affected reporting outputs.
Primary Output Link: I.7-O01
I.7-T02
Analyse failure modes, bias, context, adversarial, operational, vendor, data and human-overreliance risks and prioritise them.
Primary Output Link: I.7-O01
I.7-T03
Define permitted, restricted or prohibited status and required tests, review, approval, security and specialist controls.
Primary Output Link: I.7-O02
I.7-T04
Evaluate normal and edge cases, monitor operation and changes and restrict, suspend, remediate or retire unsafe uses.
Primary Output Link: I.7-O03
Level 1 · Foundation
I.7-L1-01
Can complete an approved AI use-case risk checklist, identify common limitations and follow permitted, restricted and prohibited-use rules.
Indicator Dimension: Task execution
I.7-L1-02
Can recognise a high-risk, changed or poorly understood use and stop or escalate it before reporting use.
Indicator Dimension: Quality, judgement and accountability
Level 2 · Practitioner
I.7-L2-01
Can independently assess and test a moderately complex AI reporting use case and define proportionate restrictions, controls and monitoring.
Indicator Dimension: Task execution
I.7-L2-02
Can evaluate routine bias, variability and edge-case issues and explain residual risk, restrictions and change triggers to management and reviewers.
Indicator Dimension: Quality, judgement and accountability
Level 3 · Advanced Practitioner
I.7-L3-01
Can design or critically review enterprise AI use-case and model-risk governance across diverse models, vendors, reporting decisions and automated workflows.
Indicator Dimension: Method design and review
I.7-L3-02
Can challenge unsafe or overclaimed AI deployment, resolve significant bias, change and control failures and advise governance bodies on restriction, suspension, retirement and residual risk.
Indicator Dimension: Leadership and governance
Illustrative evidence · 6
I.7-E01
AI use-case and model-risk assessment.
Evidence Type: Work product
I.7-E02
Permitted, restricted and prohibited-use register.
Evidence Type: Work product
I.7-E03
AI evaluation, monitoring and change plan.
Evidence Type: Work product
I.7-E04
Risk, test-case, result, edge-case, version, incident, restriction, change and retirement trail.
Evidence Type: Process evidence
I.7-E05
Documented model, IT, security, privacy, legal, ethics, quality or management review and the practitioner's response.
Evidence Type: Review evidence
I.7-E06
Observed assessment and restriction of a high-risk or changed AI reporting use case.
Evidence Type: Observed performance
Assessment · 3
I.7-A-L1
Use-case risk classification, limitation identification and situational judgement
Use-case and consequence awareness; limitation and bias recognition; control and change awareness.
I.7-A-L2
Integrated AI-risk case and professional memorandum
Risk and failure-mode analysis; use restriction; evaluation and human-review controls; monitoring and communication.
I.7-A-L3
Complex model-risk governance case, portfolio and oral defence
Method design; consequence, bias and adversarial risk; restriction and retirement decisions; governance advice and oral defence.
| From | To | Type | Rationale |
|---|---|---|---|
| I.5 | I.7 | Risk and control linkage | Use-case, model and bias risk determine restrictions, testing and review depth. |
| I.6 | I.7 | Risk and control linkage | Use-case and model risk determine verification assertions, sample, edge cases and reverification triggers. |
| I.7 | F.1 | Risk and control linkage | AI use-case and model risks should be integrated into reporting risk and control-objective assessments. |
| I.7 | H.2 | Professional conduct and collaboration linkage | Professional scepticism helps identify automation bias, unsupported output and inadequate model-risk claims. |
| I.7 | H.3 | Professional conduct and collaboration linkage | Risk classification, restrictions and residual risk may require significant professional judgement. |
| I.7 | I.8 | Professional conduct and collaboration linkage | Data, privacy, security, prompt-injection and vendor risks form part of the AI use-case assessment. |
| I.7 | I.9 | Governance and role linkage | Permitted, restricted and prohibited use and monitoring are maintained through governance. |
| Role | Target level | Relevance | Evidence expectation |
|---|---|---|---|
| Corporate Sustainability Reporting Practitioner | Practitioner | Required? | A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output. |
| Sustainability Reporting Manager or Lead | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Sustainability Reporting Adviser or Consultant | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Sustainability Data, Systems and Controls Specialist | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Assurance Readiness and Reporting Quality Specialist | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Investor, Capital Markets and Ratings Disclosure Specialist | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |