Decide and Justify Your Response

You now know how to rank a tool’s risks and choose a response for each. But a stack of responses is not yet an answer to the one question that really matters: should someone actually use this tool? This chapter closes the method. You will turn a prioritized set of risks into a single clear recommendation, learn to defend it out loud, and then watch the whole review run from start to finish on one real case, even when some of the facts are still missing.

See Why the Last Step Is a Decision, Not a List

By now you can produce something that looks finished: a ranked list of risks, each with a response beside it. It feels like the end of the work. It is not. The person who relies on your review, whether that is you, a friend, or a whole group, does not want a list. They want a call. Should we use this tool, use it carefully, or leave it alone?

A recommendation is that call: a single, stated position on whether and how to use the tool, backed by the reasoning from your review. The difference between a list and a recommendation is commitment. A list lays out what could go wrong; a recommendation takes responsibility for what to do about it. This last step is where analysis becomes advice.

And a recommendation is only worth as much as your ability to stand behind it. Anyone can say “I don’t trust this app.” What makes your call useful is that you can explain, calmly and clearly, exactly why you reached it, and what you chose to live with along the way. That is the skill this chapter builds.

Choose the Shape of Your Recommendation

However many risks you have weighed, your final recommendation almost always takes one of three shapes. Learning these three shapes gives you a clear target to aim for once the analysis is done.

  • Use: the risks are low, or already well controlled, so you recommend adopting the tool as it is.

  • Use with safeguards: the tool is worth using, but only if certain protections are in place, so your recommendation comes with strings attached.

  • Avoid: at least one serious risk cannot be reduced enough or reasonably accepted, so you recommend not using the tool, or not using the part of it that causes the risk.

The middle shape is the one people reach for most, and it needs a precise piece of vocabulary. When you say “use with safeguards,” each protection you attach is a recommendation condition: a specific requirement that must be true for using the tool to be acceptable. “Use it, but only if members are warned never to rely on it for anything serious” is a recommendation condition. It turns a vague “be careful” into a clear, checkable rule.

Underneath all three shapes sits a single idea: a trade-off, which is what you give up in one place to gain more in another. Every recommendation weighs the good a tool does against the harm it might cause. Naming the trade-off out loud is what keeps your decision honest, because it forces you to admit both sides rather than pretending the tool is all benefit or all danger.

The table below lines up the three shapes so you can see, at a glance, when each one fits and what trade-off it represents.

Recommendation

Choose it when

The trade-off you are making

Use

Risks are low or already well controlled

You accept small risks in exchange for full, easy use of the tool

Use with safeguards

The tool is valuable but carries risks you can hold in check with conditions

You accept some effort and limits in exchange for keeping the tool’s benefits

Avoid

A serious risk cannot be reduced enough or reasonably accepted

You give up the tool’s benefits in exchange for removing the harm entirely

Justify the Call You Make

A recommendation without a reason is just an opinion. Justifying your call means showing the reasoning that leads to it, in a way someone who disagrees could follow. A strong justification does three things, in order.

First, it states the recommendation plainly: use, use with safeguards, or avoid. Second, it names the few top risks and the responses that drove the decision, not every risk you found, just the ones that actually moved the needle. Third, and most importantly, it names one residual risk you have knowingly chosen to accept, and explains why that is a fair trade. Recall from earlier that residual risk is the part that remains after you have done what you reasonably can. Naming it is not a weakness in your case; it is the strongest part of it, because it proves you saw the danger clearly and made a deliberate choice rather than an accidental one.

To “defend a recommendation out loud” simply means being able to say all of this to another person and have it hold up. If someone challenges your call, you can point to the risks you weighed, the responses you chose, and the one risk you decided to accept and why. That is a defensible decision.

Decide Even When the Information Is Incomplete

In real life you will almost never have every fact. A privacy policy is vague, you cannot test how accurate an AI really is, you do not know who the company shares data with. Waiting until you are certain is not an option, because the decision still has to be made. The skill is to decide well anyway.

Three moves let you do that.

  • State your assumptions openly, so anyone can see what you took for granted, for example “I am treating this as a general-information tool, not a professional service.”

  • Cover the gaps with recommendation conditions, so the very thing you are unsure about becomes a safeguard, for example “use it, on the condition that we re-check the privacy terms before sharing anything sensitive.”

  • Escalate when the missing information is beyond your authority to judge, handing that piece of the decision to whoever is better placed to make it.

Deciding under uncertainty is not guessing. It is making the most defensible call you can with what you know, being honest about what you do not know, and setting conditions so that the unknowns cannot quietly turn into harm.

Let’s Recap!

  • Every risk review ends in a recommendation, which is a single stated call on whether and how to use a tool, not just a list of risks.

  • A recommendation takes one of three shapes: use, use with safeguards, or avoid, and each represents a trade-off between a tool’s benefits and its harms.

  • A “use with safeguards” call carries recommendation conditions, the specific requirements that must be true for using the tool to be acceptable.

  • A strong justification states the call, names the top risks and responses behind it, and openly names the one residual risk you knowingly accept.

  • When information is incomplete, you decide anyway by stating your assumptions, turning unknowns into conditions, and escalating what is beyond your authority.

You have now seen the full method run from first risk to final, defensible recommendation. In the next chapter, see a complete risk review and then run one yourself on a compact case of your own.

Ever considered an OpenClassrooms diploma?
  • Up to 100% of your training program funded
  • Flexible start date
  • Career-focused projects
  • Individual mentoring
Find the training program and funding option that suits you best