AI value and risk
Measure the value of every AI system against the risk it carries
Boards ask the same question in many forms: is our AI paying back? The return is easy to estimate. Most organisations have no figures for the risk. Modulos prices the risk of each AI system in euros and sets it against the value the system is expected to deliver.
Value-to-risk ratio for one AI system
Expected annual valuePriced risk
Priced risk = Σ (likelihood × impact) across the risk categories
A ratio above 1 means the expected value is larger than the exposure. Build and running costs stay in the business case you already have. The ratio adds the risk layer that the business case lacks.
Portfolio view
Compare every system on the same axes
Six AI systems in an illustrative insurer's portfolio, plotted by expected annual value against priced risk. Systems above the diagonal have a ratio above 1. The further above the line, the more value they deliver per euro of exposure.
| System | Value | Priced risk | Ratio |
|---|---|---|---|
| Copilot rollout | €600K | €180K | 3.3× |
| Fraud detection | €2.1M | €700K | 3.0× |
| Claims triage | €1.2M | €434K | 2.8× |
| Dynamic Pricing Engine | €2.8M | €3.1M | 0.9× |
| Customer chatbot | €400K | €520K | 0.8× |
| CV screening | €250K | €610K | 0.4× |
The system that looks best is the one that should worry you
The Dynamic Pricing Engine has the highest expected value in the portfolio. Ranked on value alone, it is the first project to fund. Priced on risk, it falls below the diagonal: the expected loss is larger than the expected value, and the amounts are far bigger than for any other system.
Without a risk figure, companies approve AI projects because of high expected returns and do not see the high expected losses that come with them. That is why value on its own is a weak basis for an AI investment decision.
What the ratio changes
With the risk priced, the Dynamic Pricing Engine stays on the roadmap with a condition. Its status moves from “approve” to “approve when the exposure is reduced”, with specific controls, a target ratio and a date.
Fraud detection and claims triage rank lower on value, but they move up because they deliver more value per euro of exposure. The decision is now defensible to the board, the regulator and the auditor, because the trade-off is written down.
Why this is new for AI
Every other investment has a return model
A new plant, a marketing campaign or a software rollout comes with a business case, a cost model and a review cycle. AI investments often arrive without any of that. Most organisations can name their AI projects. Far fewer can say what each one returns, what it costs to run and what it could cost if it fails.
The value is the easy half
Revenue uplift, hours saved and cases processed can be estimated with ordinary business analysis. The cost side is harder, because the costs of AI go beyond licences and compute. They include the effect on the company's reputation, legal position and operations when a system behaves badly. Those costs are real and often large, but they are almost never in the business case.
Finance, risk and technology leaders use different words for this need: AI ROI, value realisation, measurable outcomes, KPIs. The request is the same. They want to know how effective each AI investment is before the money is committed, and every quarter after.
The risk profile
The costs that belong in every AI business case
Each AI system carries exposure in each of these categories. Priced one by one and added together, they give the risk profile of the system in money. That total is the priced risk in the ratio.
Reputational
Customer harm, public incidents and media coverage that damage trust and revenue. This is often the largest single impact and the slowest to recover from.
Legal and compliance
Fines, remediation orders and litigation under the EU AI Act, GDPR, DORA and sector rules. Registration and documentation duties already apply to high-risk systems.
Technical
Model drift, outages, lower accuracy and security weaknesses in the model or its supply chain. These costs appear as rework, downtime and emergency fixes.
Operational
Process failures when a system is wrong at scale: manual rework, backlogs, missed service levels and the staff time needed to recover.
Ethical
Bias, unfair outcomes and decisions that cannot be explained to the people affected. These turn quickly into legal and reputational cost.
Governance
Missing owners, missing evidence and controls that exist on paper only. Weak governance makes every other category more likely.
The method
From risk profile to value-to-risk ratio
The arithmetic is simple on purpose. The benefit comes from doing it for every system, with the same method, and keeping the figures current.
- 01
Register the system and its value
Every AI system in the inventory has an economic value field: the annual benefit the business expects from it, in euros.
- 02
Price the risk
For each risk category, estimate the annual likelihood of a failure and its financial impact. Likelihood multiplied by impact gives the expected loss for that category.
- 03
Calculate the ratio
Divide the expected annual value by the priced risk. The result is one number per system that you can compare across the whole AI portfolio and put in front of a board.
- 04
Track it
When controls take effect and runtime checks confirm behaviour, likelihoods fall and the ratio rises. If behaviour gets worse, the ratio falls and the system is flagged before the loss happens.
Decide before you invest
With a priced risk profile next to the expected value, you can rank candidate projects on one scale. The decision then depends on which system returns the most per euro of exposure, and less on who argues best in the steering committee.
Track after you invest
The same figures become the KPIs for the system in production. You check expected value against realised value and update the priced risk when controls mature or incidents occur. A quarterly review shows whether each investment is on plan, improving or getting worse.
How Modulos helps
The platform prices, links and tracks the risk
A spreadsheet works for one project. A real AI portfolio needs an inventory, a risk engine and current evidence, all in one place. Modulos connects them in one AI governance platform.
Scout finds every system
Scout discovers AI across cloud accounts, code and connected tools, so the inventory includes the systems nobody declared.
Learn more about scout finds every systemRisk is priced in euros
The Risk Agent estimates exposure per system and across the organisation in money, on a schedule you set.
Learn more about risk is priced in eurosControls are linked to evidence
Each system is linked to its controls, evidence and risks across the EU AI Act, ISO/IEC 42001 and NIST AI RMF. Shared controls are assessed once.
Learn more about controls are linked to evidenceDecisions are recorded
Investment approvals, risk acceptances and reviews are stored against the system, so the decision trail is ready for the board and the auditor.
Learn more about decisions are recorded
Want to try the arithmetic on one system first? Use the AI risk calculator.
Questions and answers
Value-to-risk in practice
What is the AI value-to-risk ratio?
It is the expected annual value of an AI system divided by its priced risk, which is the expected annual loss across the risk categories. A ratio above 1 means the expected value is larger than the exposure.
Does the ratio replace the business case?
No. The ratio leaves out build and running costs because the existing business case already covers them. It adds the risk term that most business cases lack. If you prefer one number, you can add running cost to the denominator.
Where do the likelihood and impact figures come from?
They come from your business data, incident history and control evidence. In Modulos, the Risk Agent builds an estimate for each threat on each system and shows the reasoning, so a reviewer can check and change each input.
What should we do with a system below 1?
A low ratio is a reason to reduce the exposure before you scale the system. Set the controls that lower the likelihood or the impact, agree a target ratio and a date, and review the figure again when the evidence changes.
Analyst recognition
Modulos was named in the inaugural Gartner® Magic Quadrant™ for AI Governance Platforms, published 16 June 2026. Read the full announcement.
“Organizations that invest in third-party AI governance products are 1.9 times more likely to report the highest levels of value.”
Gartner, Magic Quadrant for AI Governance Platforms, Lauren Kornutick, Sumit Agarwal, Priya Sundararaman, Nader Henein, Brandon Medford, 16 June 2026. GARTNER is a registered trademark and service mark, and MAGIC QUADRANT is a registered trademark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Next step
Put a number on your AI portfolio
In a 30-minute call we take one of your systems through this method and show how the figures look in the platform.