Practical guide
AI fluency for enterprise risk managers: test a risk scenario
Build a fictional risk scenario that separates initiating events, controls, consequences and assumptions before prioritization.
Enterprise risk managers can use AI to structure risk scenarios while checking that fluent descriptions do not become unsupported likelihood estimates. This fictional exercise examines an unverified AI summary entering an executive brief. It produces a scenario and evidence plan, not a quantified enterprise risk assessment or a prediction of incidents.
Write a specific scenario chain
A risk label becomes actionable when it shows the event, pathway and consequence.
The fictional scenario begins when an AI summary misstates a supplier deadline. The author does not compare it with the source. A reviewer relies on the brief, and an executive chooses an infeasible sequence. The consequence under examination is avoidable replanning, not every possible supplier risk.
Ask AI to separate initiating event, control gap, intermediate decisions and consequence. Do not add a breach, financial loss or probability that the packet does not supply. Keep alternative pathways visible where they would change the control choice.
Map controls to points in the chain
A general policy may not show where this scenario can be interrupted.
The exercise offers source-linked drafting, an author claim check and a reviewer decision check. The first improves traceability; the second compares material statements; the third examines whether the recommendation remains feasible. Describe what each can detect and what it leaves unresolved.
Do not label any control effective merely because it exists on paper. Record the evidence needed to examine its operation, such as a reviewed brief and the corresponding source. AI can propose controls but cannot prove they are implemented.
Keep likelihood and impact unknown when evidence is absent
A risk matrix should not manufacture numbers to fill every cell.
The packet contains one synthetic scenario and no event history, exposure count or consequence data. Therefore likelihood and magnitude remain unmeasured. Use qualitative questions about reach, reversibility and decision timing to plan evidence rather than assigning a red score from intuition.
If an owner supplies a risk tolerance, record its source and scope. Do not infer the organization’s tolerance from the severity of the narrative. A vivid story is useful for testing a pathway but is not frequency evidence.
Test the scenario with a changed control
A counterfactual should reveal which dependency the control actually addresses.
Now supply a brief where every material deadline statement links to a source, but the source itself is outdated. Traceability makes the issue easier to inspect but does not ensure currency. Add a source-version check at the relevant point rather than claiming source links solve the whole scenario.
Ask which downstream controls still matter after the change. Preserve defense in depth where different failures remain possible. Do not report a reduction in likelihood without observed evidence of the changed process.
Deliver a scenario record and evidence agenda
The output should help an owner decide what to examine next.
Include chain, affected decision, proposed controls, unresolved likelihood and impact, outdated-source counterexample and evidence requests. Name the roles that would own decisions in the fictional setting without assigning real authority.
Review causal discipline and uncertainty handling. The verification capability guide examines a worker checking one output; this resource examines how control points around that work connect to an enterprise risk scenario.
Sources and scope
NIST: AI risk management. Skills England: workplace AI foundations.
These references provide background, not validation or endorsement of this exercise. The case details, calculations and suggested review questions are original instructional material. Use them to discuss observable work, not to infer customer outcomes, professional credentials or performance in every setting. Before adapting the exercise, confirm the relevant facts, approved tools, data permissions and decision owners. If you change the case, revisit the expected answers and checks as well. These examples describe practice tasks, not a promise that a particular product includes the fictional features.
Sources: [1] [2]
Sources
- 1.AI RMF Core · NIST
- 2.AI foundation skills for work benchmark · Skills England