Free templates

AI Risk Register

A simple register for tracking each AI use case, the risks it carries, who owns it, and what you are doing about it.

A risk register is just an honest list of what could go wrong and what you are doing about it. For AI, that list changes as you adopt more tools, so it helps to keep it in one place rather than only in the heads of your team. This template gives you the columns to fill in for each AI use case, a way to rate how serious each risk is, and a few worked examples to copy. Keep it short enough that people will actually maintain it.

Inside the editable version

  • An editable spreadsheet-style table with the columns laid out
  • A plain scoring guide for likelihood and impact
  • Worked example rows you can adapt or delete
  • A review cadence you can set to a date that suits your team

The template

What a risk register is for

This register lists each way [Company] uses AI, the risks that use creates, and what you are doing about each one. It exists so that risks are written down, owned by a named person, and reviewed on a schedule rather than remembered only when something breaks. Keep one row per use case. A use case is a specific job a tool does, such as drafting client emails or summarizing support tickets, not a tool in the abstract.

Columns to fill in for each row

For every AI use case, record: the use case (what the tool does and for whom), the tool or model used, the data it touches, the main risk in one sentence, the likelihood that the risk happens, the impact if it does, the resulting risk level, the control or mitigation you have in place, the owner responsible, the status (open, in progress, accepted, or closed), and the date you last reviewed it. Keep each entry to a sentence or two so the whole register stays readable at a glance.

How to score likelihood and impact

Rate likelihood as low, medium, or high: low means it would be a surprise, medium means it happens occasionally, high means it is likely without a control. Rate impact the same way: low means a minor inconvenience, medium means real cost or rework, high means harm to a client, a breach of a rule, or serious damage to the business. Set the risk level by combining the two, treating anything high on either axis as needing attention. Do not over-engineer the scoring. A consistent, honest guess that everyone understands beats a precise number nobody trusts.

Example: drafting client communications

Use case: staff use an approved tool to draft client emails. Data touched: client names and the topic of the message, no regulated data. Main risk: the draft contains a wrong fact or commitment that a client relies on. Likelihood: medium. Impact: medium. Risk level: medium. Control: a person reviews and edits every draft before it is sent, and nothing regulated is entered. Owner: [name]. Status: in progress. Last reviewed: [date].

Example: a tool with access to live data

Use case: a tool is connected to a live system so it can look up customer records to answer questions. Data touched: customer personal data. Main risk: the tool exposes the data of one customer to another, or takes an action that should have had a human check. Likelihood: low. Impact: high. Risk level: high. Control: access is scoped to the minimum records the task needs, every action is logged, and any change to a record requires human approval. Owner: [name]. Status: open. Last reviewed: [date].

Keeping the register alive

Review the register on a set cadence, for example monthly while you are adopting tools quickly and quarterly once things settle. Add a row whenever a new AI use case starts, and close a row when a use case stops or a risk is fully resolved. Bring the register to any meeting where AI decisions get made, so the conversation starts from the real list rather than from memory. A register that is never updated gives false comfort, so a shorter register you actually maintain is worth more than a long one you do not.

This is a starting template, not a finished policy. Adapt it to how your business actually works, and have it reviewed by the right people before you rely on it.

Want this built into how your AI actually runs?

A template is a starting point. A short working session turns it into a plan: where AI creates leverage for you, and what guardrails to put in place first.

Book a working session