Civil servants deploying artificial intelligence in public services gained a standard scoring grid this month as guidance for the AI Risk Management Toolkit landed with five-point likelihood and impact scales mapped to the Orange Book’s risk-management chapters.
The 44-page document, dated 8 September and published under the legacy Department for Science, Innovation and Technology branding, arrives as Prime Minister Andy Burnham’s Office of the Prime Minister and Cabinet absorbs the AI Security Institute and standing up Lord Vallance’s AI Taskforce.
What teams must do
Procurement and digital units are told to treat AI as a lifecycle problem — from use-case identification through retirement — rather than a one-off model approval. Workbook prompts ask whether training data drift, explainability gaps or vendor lock-in could break a service, and require risks to be multiplied into scores for monitoring dashboards.
The toolkit explicitly cross-references the Cyber Assessment Framework, signalling that AI deployments touching citizen data will face the same assurance language as critical national infrastructure. Multidisciplinary teams — data scientists, lawyers, comms officers — are expected to sign off before a model touches live casework.
Politics and ownership
DSIT no longer exists as a separate department after Burnham’s summer reshuffle; AI minister Kanishka Narayan now sits in cabinet and reports into the OPMC. Narayan told Reuters in August that binding regulation remains on the table if voluntary testing of frontier models fails, but this month’s paperwork is softer: templates, not statutes.
Why it matters outside London
Councils buying chatbots for planning queries and NHS trusts experimenting with triage assistants will inherit the same workbook. Suppliers bidding on framework agreements should expect evidence requests on bias testing and incident playbooks, not just accuracy benchmarks on slide decks.
Vallance’s taskforce is tasked with cross-government adoption, not just writing rules. If departments cannot show monitored risk scores, central funding gates may tighten — even without a new AI Act on the statute book.
Next steps
Officials plan training webinars for accounting officers in October. Vendors with live public-sector pilots should align product roadmaps to continuous monitoring, because the guidance is explicit: there is no “final” safe version of a learning system, only documented controls and rollback paths.
Procurement ripple
Framework suppliers on G-Cloud and DOS contracts should expect annex requests mapping model cards to the workbook’s nine risk categories. Legal teams are drafting addenda that require vendors to notify departments within 72 hours of safety incidents, mirroring financial services operational resilience rules.
Local authorities running planning chatbots may lag Whitehall departments in compliance, but ICO enforcement memos already cite inadequate impact assessments. The workbook gives them a template to avoid duplicate consulting spend.
Institute move
Absorbing the AI Security Institute into the OPMC centralises pre-deployment testing of frontier models under Vallance’s taskforce. Startups worry that moving teams out of a dedicated science department slows hiring; the government counters that reporting to the prime minister shows seriousness.
Audit follow-up
The National Audit Office signalled it will sample AI pilots in HMRC and DWP for adherence to the workbook next spring. Departments that cannot show risk registers may find their ML projects paused during spending reviews, regardless of ministerial enthusiasm for automation.
Looking ahead
Teams on all sides said they would publish more detail when schedules firm up, and that stakeholders should expect incremental updates rather than a single document that answers every outstanding question.
Markets, voters and patients will treat silence as a signal, so the pressure to clarify timelines before the budget or the next fixture remains high.
Until then, the practical advice for readers is to watch primary sources—regulator notices, FA team sheets, issuer terms and trust board papers—rather than relying on second-hand summaries alone.
Officials reiterated that figures could be revised as more data arrives, and that anyone making financial or travel decisions should confirm numbers against the latest published tables before acting.
