Prioritising AI projects: impact, effort, risk

Ten candidate projects and budget for two. A scoring method on impact, effort and risk that gives an order, a first project, and reasons for the rest to wait.

3 minread 598words last updated

The short answer

A list of AI ideas is easy to produce and impossible to act on. What turns it into a plan is a score on three dimensions for each candidate: how much it would give back per month, how much it would take to build, and what happens when it is wrong. The order that falls out is usually surprising: the exciting projects sink, and a dull one with high impact, low effort and low risk rises to the top. Build that one first.

The three dimensions

DimensionAskHighLow
ImpactHours or money returned per month, measured against the current processMany hours across several people; direct revenue effectOccasional task; convenience
EffortWhat it takes to build: data preparation, integrations, process mapping, testingData scattered, several systems, undefined processData reachable, one system, process written down
RiskWhat happens when it is wrong once in fifty times, and who noticesCustomer-facing, money, legal, sensitive dataInternal, checked by a person, reversible

Reading the grid

  1. High impact, low effort, low risk: first. It exists in nearly every list. Email triage, invoice reading, follow-up reminders, report assembly. Dull, and the fastest return you will see.
  2. High impact, low effort, high risk: second, with a person in the loop. The system prepares; a person decides. The risk drops as logs show what it gets right.
  3. High impact, high effort: third. Usually the project everyone wanted to start with. It needs the data, the access and the habits that the first two build. Start it when they exist.
  4. Low impact, anything else: not now. Write it down and move on. The list is not a commitment.

What changes the scores over time

  • Effort falls as foundations are built: data brought into reachable systems, integrations in place, processes documented by earlier projects.
  • Risk falls as evidence accumulates: months of logs showing a system classifying correctly make it reasonable to let it act on more.
  • Impact changes as the business changes: a process that mattered last year may be gone; a new one may dominate.

Re-score quarterly. It takes an hour with the same people, and it keeps the plan honest.

What this means for you

Take your list of ideas, score each on impact, effort and risk with the reasons written down, and build the one in the top-left corner first. Let it produce the evidence, the access and the habits. Then re-score. The impressive project is still on the list, and by the time you reach it, it is both cheaper and safer than it was on day one.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

How do we estimate impact without building it?

Measure the current process: hours per week across everyone who does it, and any direct money effect such as quotes lost to slow follow-up. Impact is what the project would give back. If nobody can measure the current process, that is itself a low score, because success could not be shown either.

What counts as risk?

What happens when the system is wrong once in fifty times, and who notices. A wrongly sorted email is low risk. A wrong price sent to a customer is high. Risk also includes data: projects that need sensitive data to leave the company score higher until that is solved.

Should we ever start with the high-effort project?

Only if it is the reason the business exists and nothing smaller would teach you anything. Otherwise the small project first builds the access, data and habits the large one needs, and produces the evidence that funds it.