Automation has moved into the engine room of risk management. Tools that calculate risk levels, prioritise tasks and suggest assessments are now common features of GRC platforms. But when you are standing in front of an auditor or the board, a critical question arises: how much of the assessment can you genuinely rely on the system to perform?
AI adoption is accelerating across Europe. According to Eurostat, 20% of EU enterprises with at least ten employees used AI technologies in 2025, up from 13.5% in 2024. AI-enabled and automated tools are also entering compliance and risk functions, where automated calculations and decision support are playing an increasingly prominent role.
However, automation and AI are not the same thing. A rules-based risk calculation using parameters defined by your organisation is not necessarily an AI system. The regulatory requirements depend on the technology involved and how it is used.
Enforcement of the EU AI Act began in August 2026, alongside new transparency requirements for certain AI systems. This makes it increasingly important for organisations to understand what their technology does, which data it uses and where human oversight remains necessary.
The debate about automated risk management is often presented as a binary choice: either trust the algorithm completely or reject automation and return to spreadsheets. The reality is more nuanced. The right approach depends on the nature of the task.
Good candidates for automation include:
Automation provides consistency and speed in areas where people can quickly lose track of the details.
Tasks that still require human judgment include:
These tasks require a business context that an algorithm lacks.
Build a Transparent Risk Assessment
Learn how to structure and document risk assessments while retaining control over the underlying data and conclusions.
→ Download the ISO 27005-based risk management guide
Ignore vague sales claims about ‘AI’. Instead, ask three specific questions when evaluating a risk management tool:
The purpose of automated risk management is not to remove people from the process. It is to support better decisions.
A well-designed system gives you an overview of relevant threats, previous incidents and existing controls. But your organisation should retain control over the values and context that determine the final assessment.
You should always be able to add a written explanation to an assessment, regardless of whether the underlying data comes from your organisation or the system. It is this professional rationale — not the number alone — that will stand up to scrutiny from auditors and management.
Where AI or automated processing affects individuals, GDPR and, where applicable, the EU AI Act may introduce additional requirements. Even when no automated decision about an individual is involved, clear documentation and transparency remain essential for auditability and sound governance.
In NorthGRC’s risk management module, automation supports your decisions — it does not replace them.
The platform gives you direct access to threat catalogues, incident histories and information about vendor security. However, the risk calculation is based on the values your organisation enters for likelihood and impact. The system helps qualify your decision; it does not make the decision for you.
The same principle applies to risks inherited from vendors. If a vendor weakness increases the actual exposure of an internal system, NorthGRC highlights the connection. The response and assessment of the business impact remain in your hands.