Compliance

risk classification

Categorization of systems as low, high, or excessive risk.

Definitions (5)

The process of categorizing AI systems as low, high, or excessive risk, each tier carrying distinct governance obligations such as reporting, auditing, or prohibition. Classification guides required oversight, audit frequency, and mitigation measures under the CNJ governance model.

An India‑specific framework to categorise AI systems according to potential harms and impact, used to determine proportional oversight, required mitigations, documentation and incident reporting obligations; to be developed and applied under the MeitY Action Plan.

The statutory taxonomy that classifies AI systems into risk tiers (e.g., low, high, excessive) based on their potential to affect rights, safety or legal interests; the classification determines applicable obligations such as algorithmic impact assessments, conformity/certification and liability presumptions, with methodological criteria to be specified by regulation.

The bill's framework that classifies AI uses into four categories—unacceptable, high, limited, and insignificant risk—which determines applicable prohibitions, pre-deployment obligations (e.g., impact assessments, certification), and intensity of oversight and mitigation measures.

A structured classification process that evaluates each AI application by factors such as financial impact, regulatory relevance, client impact, autonomy, model complexity and data sensitivity to determine proportional controls, testing and supervision required.