1. Describe the risk
Capture the AI system, risk category, cause, event, impact, stakeholders, controls, owner and evidence.
Document AI risks in cause–event–impact format, apply a transparent 5×5 matrix, assign owners and actions, and maintain a printable, exportable register for governance reviews.
Capture the AI system, risk category, cause, event, impact, stakeholders, controls, owner and evidence.
Rate inherent and residual likelihood and impact from 1 to 5. The tool calculates both scores consistently.
Use the result, KRI, due date and review date to focus governance attention and document follow-through.
Complete the fields below. Required fields are marked with an asterisk.
Entries are stored only in this browser unless your site separately implements secure storage.
| Risk statement | Stakeholders | Controls | Effectiveness | Treatment | Due | KRI | Review | Evidence | Action | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| No browser entries yet. | |||||||||||||||
Likelihood and impact each use a five-point ordinal scale. Multiply the two values to produce a score from 1 to 25.
Residual risk is the risk remaining after existing controls are considered. Control effectiveness is recorded separately and does not automatically override the user-selected residual values, which keeps the logic transparent and auditable.
The matrix supports consistency, not certainty. It does not model correlated risks, tail events, distributional effects, legal obligations, system-specific safety cases or organisational risk appetite. Review high-impact risks with relevant legal, security, privacy, safety, technical and domain specialists.
It is a controlled record of AI-related risks, their causes, events, impacts, stakeholders, ratings, controls, owners, indicators, treatments, evidence and review dates.
Use a cause–event–impact structure: because a condition exists, an event may occur, leading to defined consequences for people, operations, compliance, security, finances or reputation.
Inherent risk is assessed before controls. Residual risk is assessed after considering controls that are actually designed and operating.
Likelihood and impact are each rated from 1 to 5. Multiplying them produces a score from 1 to 25, mapped to Low, Moderate, High or Critical.
No. Control effectiveness is recorded as evidence about control strength, while residual likelihood and impact remain explicit user judgements. This avoids hiding assumptions.
A KRI is a measurable signal with a threshold and escalation trigger, such as a harmful-output rate, override rate, drift measure, complaint count or security event level.
Review frequency should reflect risk severity, system change rate, control maturity, incidents, regulatory change and stakeholder exposure. High or rapidly changing risks need more frequent review.
The owner should have authority and resources to manage the risk, approve treatment, escalate issues and ensure evidence is maintained. Technical contributors may support but should not be the only accountable party.
No. It supports structured governance but does not replace legal analysis, privacy impact assessments, threat modelling, safety cases, human-rights assessments, model validation or domain-specific assurance.
Browser entries use localStorage on the current device. They are not transmitted externally by this page. Clearing browser data or using another device will remove or hide them.
The browser register compares a normalised combination of AI system name, risk category and risk statement. Matching entries are blocked to reduce accidental duplication.
Yes. The page supports local CSV import, CSV export, JSON export and print. Imported files are processed in the browser and are not sent to an external service.