Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

New risk categories for AI change risk assessment

Hello community!

We have some exciting news to share: two new risk categories for AI Change Risk Assessment in Jira Service Management are now generally available. Business Risk and Security & Compliance Risk are here, and they give your change approval teams a lot more to work with before hitting that approve button. Read on to learn more about the new enhancements!


What's new for AI Change Risk Assessment

AI Change Risk Assessment enables you to review change requests and surface risk scores, plain-language summaries, and suggested mitigation steps -- right inside Jira Service Management. You can enable and configure risk categories to fit your team's setup, and the assessment pulls from change details, linked services, deployment history, and more to build a comprehensive picture of risk.

Today, we're adding two new dimensions to that picture:

Business risk

Technical reviews are important, but they don't always catch what a change could mean for the business. Business Risk can help fill that gap by surfacing financial and reputational factors based on your organization’s inputs and standards that deserve attention before a change goes through.

Here's what it looks at:

  • Financial exposure: potential revenue impact, cost of downtime, or SLA penalties tied to affected services

  • Reputational risk: changes that touch customer-facing systems or high-visibility services where disruption could affect customer trust

  • Stakeholder impact: service owners, business stakeholders, and others who need to know about a potential disruption

The result is a business-level view alongside the technical one, so approvers have more business context at hand before making the final call.

Screenshot 2026-08-21 at 7.54.43 PM.png

Security & Compliance Risk

Security & Compliance Risk reviews your change request against your organization's connected security protocols, privacy guidelines, and industry standards, helping flag potential violations get flagged before they reach production.

It checks for:

  • Security protocol gaps: whether the change aligns with your organization's security standards and accepted industry practices

  • Privacy concerns: potential exposure under data privacy regulations like GDPR or CCPA

  • Missing approvals: required sign-offs referenced in your knowledge base, linked tickets, or change description that haven't been obtained yet

Changes that touch sensitive systems or data as defined by your organization get flagged for deeper review, which helps reduce compliance surprises down the road.

Screenshot 2026-08-21 at 7.54.31 PM.png

How all four risk categories work together

AI Change Risk Assessment now evaluates changes across four dimensions. Each one contributes to an overall risk score with a plain-language summary and recommended next steps, so your approvers get one clear view instead of four separate conversations.

 Risk category What it covers 
Technical Code quality, deployment history, rollback plans, failed deployments, data migration
Operational  Scheduling conflicts, service graph impact, infrastructure downtime, rollback complexity
Business Financial exposure, reputational risk, stakeholder impact
Security & Compliance  Security protocol gaps, privacy concerns, missing required approvals

Get started and share your feedback

Business Risk and Security & Compliance Risk are available now on Jira Service Management Cloud. Getting set up takes just a few steps:

  1. Go to your Change Management project settings in Jira Service Management

  2. Navigate to Rovo Ops > AI Risk Assessment and enable the new risk categories

  3. Check out the enable and configure guide for step-by-step instructions

We'd love to hear what you think. Drop a comment below and let us know:

  • How Business Risk or Security & Compliance Risk is shaping your change approval decisions

  • Any cases where the assessment missed the mark or flagged something unexpected

  • What additional signals, integrations, or risk categories you'd like to see next

We'll be watching this thread closely and using your input to shape what we build next for change management in Jira Service Management!

Thanks for being part of the community! 

0 comments

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events