Build Core Vocabulary and Method Foundations

In the last chapter you got the lay of the land. Now the method itself begins, and like most careful thinking, it starts with words. Before you can weigh a risk or decide what to do about one, you need a small set of precise terms and a clear picture of the five steps every risk review moves through. This chapter gives you both, so that everything you do later rests on solid ground.

See Why Precise Words Come First

In everyday talk, we call all sorts of things “risky,” “dodgy,” or “unsafe.” A friend says an app is “sketchy,” and we nod along without ever asking what could actually go wrong, how likely it is, or how badly it would hurt. That vagueness feels harmless, but it quietly stops you from thinking clearly. If a tool is simply “bad,” you cannot compare its problems, decide which one matters most, or explain your worry to anyone else.

A risk review replaces that fog with a few sharp words. When you can say “this app is likely to overcharge some families, and that would cost them real money,” you have turned a vague bad feeling into something you can weigh, rank, and act on. Precise words are not fussy jargon. They are what let you reason about a tool instead of just reacting to it, and that is why this chapter comes before any decision-making.

Define Risk, Likelihood, and Impact

Three words sit at the very center of everything that follows. Read them in order, because each one builds on the last.

A risk is something that could go wrong with a tool and cause harm: an unwanted outcome that may or may not happen. Notice the “may or may not.” A risk is not a problem you have already seen; it is one that could occur. In the parents’ grocery-share app from the introduction, “the app might overcharge a family” is a risk, whether or not it has happened yet.

Once you have named a risk, you weigh it along two dimensions. Likelihood is how probable it is that the risk actually happens. Impact is how serious the harm would be if it did. These are two separate questions, and keeping them apart is one of the most useful habits in this whole course. A risk can be very likely but trivial, like the app occasionally suggesting a dull menu, or very unlikely but severe, like the app leaking every member’s home address. You cannot judge a risk by likelihood or impact alone; you always need both.

Name What You Can Do About a Risk

Naming and weighing a risk is only useful if you can then do something about it. There are four broad responses, and you will meet them properly in the next chapter. For now, learn them as vocabulary so the words are familiar when you put them to work.

  • You can avoid a risk by not using the tool, or not using the part of it that creates the risk.

  • You can reduce a risk, also called applying a mitigation, which is any action that lowers a risk’s likelihood or its impact.

  • You can accept a risk, deciding to live with it because it is small enough or worth it.

  • You can escalate a risk, raising it to someone with more authority or information when the decision is beyond your own to make.

Two of these deserve a closer look now, because they carry a precise meaning you will lean on later. Escalation is the act of handing a risk upward, not because you are dodging responsibility, but because the right person to decide sits above you. And when you have done everything reasonable and some risk still remains, the part you knowingly choose to live with is called residual risk. Residual risk is not failure. Almost every useful tool leaves some behind, and a responsible user is simply someone who knows exactly what they are accepting and why.

Weigh Fairness, Privacy, and Consent

Not all harm looks like a broken feature. Some of the most serious risks in digital and AI tools are about how people are treated and how their information is handled.

Fairness means treating people equitably, without unjustly advantaging or harming some group. When a tool is unfair, the cause is often bias: a systematic tilt that makes the tool treat some people worse than others, again and again rather than by accident. If the grocery-share app consistently rounds costs up for larger families, that is bias, and the harm it causes is unfairness.

Privacy is a person’s right to control information about themselves: what is collected, who sees it, and what it is used for. Closely tied to it is consent, which is a person’s clear, informed agreement to how their data is collected and used. Consent only counts when people actually understand what they are agreeing to. The grocery-share app storing every member’s home address and quietly passing it to a partner service is a privacy risk, made worse because members never truly consented to that sharing.

Watch for the Risks That Are Special to AI

When a tool uses AI, it brings a few risks that ordinary software does not. You do not need to understand how AI works inside to respect these three traits.

The first is opacity: with many AI tools, you cannot see how they reached a given answer, which makes their mistakes harder to spot and to explain. The second is drift: an AI’s behavior can slowly change over time as its data or its underlying model changes, so a tool that behaved well last month may not behave the same way today. The third is hallucination, closely related to its cousin non-reproducibility: an AI can produce confident, fluent output that is simply wrong, and it may not even give you the same answer twice. If the grocery-share app’s AI suggests a menu that ignores a child’s known allergy, that is exactly this kind of failure, and its confident tone makes it more dangerous, not less.

Compare the Core Terms at a Glance

Here are the key terms side by side, with a short example drawn from the grocery-share app, so you can see them all in one place before you use them.

Term

What it means

Grocery-share example

Risk

An unwanted outcome that could happen and cause harm

The app might overcharge a family

Likelihood

How probable the risk is to happen

Overcharging happens most weeks

Impact

How serious the harm would be if it happened

A family loses real money

Mitigation

An action that lowers a risk’s likelihood or impact

Add a human check on each week’s totals

Residual risk

The risk you knowingly accept after doing what you reasonably can

A rare rounding error may still slip through

Escalation

Raising a risk to someone better placed to decide

Flagging the data-sharing to the group’s organizer

Fairness

Treating people equitably, without unjust harm to a group

Costs are split evenly for large and small families

Bias

A systematic tilt that treats some people worse

The app rounds up more often for big families

Privacy

A person’s control over information about themselves

Who can see each member’s home address

Consent

Clear, informed agreement to how data is used

Members agreeing before addresses are shared

Discover the Five Steps of a Risk Review

You now have the words. The risk review is the method that puts them to work: a repeatable way to look hard at a tool and reach a decision you can defend. It moves through five steps, always in the same order.

  • Identify: name the risks a tool carries, including the AI-specific ones, so nothing important stays hidden.

  • Assess: weigh each risk by its likelihood and its impact.

  • Prioritize: use those weights to decide which few risks matter most, so your effort goes where it counts.

  • Respond: choose a proportionate action for each risk that matters, whether to avoid, reduce, accept, or escalate it.

  • Justify: state your overall recommendation and explain the reasoning behind it, including any residual risk you have chosen to accept.

The order is not arbitrary. You cannot weigh a risk you have not yet named, and you cannot defend a decision you have not yet reasoned through. Identifying and assessing first give you the clear picture you need before you commit. For the grocery-share app, a full review would identify the overcharging, allergy, and data-sharing risks, assess how likely and how serious each one is, prioritize the ones that cause real harm, respond to each with a proportionate action, and finally justify a recommendation the whole parents’ group can stand behind.

Let’s Recap!

  • A risk is an unwanted outcome that could happen, and you weigh every risk by its likelihood and its impact.

  • You can respond to a risk in four broad ways: avoid it, reduce it with a mitigation, accept it, or escalate it.

  • Residual risk is the part you knowingly accept after doing what you reasonably can, and accepting it is normal, not failure.

  • Fairness, bias, privacy, and consent name the human harms a tool can cause, while opacity, drift, and hallucination name the risks special to AI.

  • A risk review runs five steps in order, identify, assess, prioritize, respond, and justify, and every later chapter builds on this sequence.

Now that you can name the pieces of risk and the five steps of a review, you are ready to start making decisions. The next chapter teaches you how to prioritize a mixed set of risks and match each one to a proportionate response.

Ever considered an OpenClassrooms diploma?
  • Up to 100% of your training program funded
  • Flexible start date
  • Career-focused projects
  • Individual mentoring
Find the training program and funding option that suits you best