A design team has a probability and severity matrix template and a mitigation hierarchy ready to apply to a new AI system, and asks where stakeholder mapping fits in relation to them. A governance adviser is asked to explain the correct relationship between stakeholder mapping, the harm matrix, and the mitigation hierarchy in the design-stage risk process. Which explanation is correct?
- AStakeholder mapping helps identify who could be harmed, the harm matrix then ranks those identified risks by likelihood and severity, and the mitigation hierarchy guides how the prioritised risks are treated. Correct
- BStakeholder mapping and the harm matrix are interchangeable starting points, so a team may begin with either one and reach the same set of prioritised risks.
- CThe mitigation hierarchy should be applied before stakeholder mapping, because deciding how to treat risks early lets the team limit which stakeholders it then needs to consult.
- DStakeholder mapping and the harm matrix should each be completed once at the outset and then frozen, because revisiting them after treatment would reopen settled risk decisions.
Why A is correct: Identification must precede prioritisation, which must precede treatment, so mapping affected parties feeds the matrix that ranks the risks, and the hierarchy then determines how the highest-priority risks are addressed.
Why B is wrong: The two tools serve different stages and are tempting to treat as equivalent entry points, but a matrix can only rank risks that have first been identified, so they are not interchangeable.
Why C is wrong: Choosing treatments first is appealing as a shortcut, but treating risks before identifying who is affected reverses the logic and risks missing harms to stakeholders the team never mapped.
Why D is wrong: Stability sounds disciplined, but risk work is iterative and new information can change who is affected and how risks rank, so freezing the analysis is poor practice rather than a correct relationship.