AI Risk Register

Structured AI governance

Build a clear, accountable AI risk register

Document AI risks in cause–event–impact format, apply a transparent 5×5 matrix, assign owners and actions, and maintain a printable, exportable register for governance reviews.

Transparent by design.
Scores are deterministic, formulas are shown, and results depend on the information you enter.
How it works

Three steps from risk identification to action

1. Describe the risk

Capture the AI system, risk category, cause, event, impact, stakeholders, controls, owner and evidence.

2. Apply the matrix

Rate inherent and residual likelihood and impact from 1 to 5. The tool calculates both scores consistently.

3. Prioritise treatment

Use the result, KRI, due date and review date to focus governance attention and document follow-through.

AI risk entry

Complete the fields below. Required fields are marked with an asterisk.

Risk context
Example: Customer support response assistant.
Example: Because training data under-represents a customer group, the model may recommend inconsistent outcomes, causing unfair treatment and regulatory exposure.
Include users, customers, employees, vulnerable groups, regulators, partners or the public as relevant.
Inherent risk and controls
Likelihood before considering existing controls.
Impact before considering existing controls.
Describe preventive, detective, corrective and governance controls already operating.
Examples: test results, audit logs, approvals, model cards, incident reports or supplier assurance.
Residual risk, accountability and treatment
Define the metric, threshold and escalation trigger. Example: harmful output rate exceeds 0.5% in a rolling 7-day sample.
Working register

Browser-based AI risk register

Entries are stored only in this browser unless your site separately implements secure storage.

AI risk register entries. Activate column headings to sort.
Risk statementStakeholdersControlsEffectivenessTreatmentDueKRIReviewEvidenceAction
No browser entries yet.
Methodology

Defined 5×5 risk matrix

Likelihood and impact each use a five-point ordinal scale. Multiply the two values to produce a score from 1 to 25.

  • Low: 1–5
  • Moderate: 6–11
  • High: 12–19
  • Critical: 20–25

Residual risk is the risk remaining after existing controls are considered. Control effectiveness is recorded separately and does not automatically override the user-selected residual values, which keeps the logic transparent and auditable.

Limitations

The matrix supports consistency, not certainty. It does not model correlated risks, tail events, distributional effects, legal obligations, system-specific safety cases or organisational risk appetite. Review high-impact risks with relevant legal, security, privacy, safety, technical and domain specialists.

Accessible heat map

Five by five AI risk heat mapLikelihood increases from left to right and impact increases from bottom to top. Scores range from low to critical.51015202548121620369121524681012345Likelihood →Impact →1234554321
Frequently asked questions

AI risk register FAQs

What is an AI risk register?

It is a controlled record of AI-related risks, their causes, events, impacts, stakeholders, ratings, controls, owners, indicators, treatments, evidence and review dates.

How should a risk statement be written?

Use a cause–event–impact structure: because a condition exists, an event may occur, leading to defined consequences for people, operations, compliance, security, finances or reputation.

What is the difference between inherent and residual risk?

Inherent risk is assessed before controls. Residual risk is assessed after considering controls that are actually designed and operating.

How does the 5×5 matrix work?

Likelihood and impact are each rated from 1 to 5. Multiplying them produces a score from 1 to 25, mapped to Low, Moderate, High or Critical.

Does control effectiveness automatically calculate residual risk?

No. Control effectiveness is recorded as evidence about control strength, while residual likelihood and impact remain explicit user judgements. This avoids hiding assumptions.

What is a key risk indicator?

A KRI is a measurable signal with a threshold and escalation trigger, such as a harmful-output rate, override rate, drift measure, complaint count or security event level.

How often should AI risks be reviewed?

Review frequency should reflect risk severity, system change rate, control maturity, incidents, regulatory change and stakeholder exposure. High or rapidly changing risks need more frequent review.

Who should own an AI risk?

The owner should have authority and resources to manage the risk, approve treatment, escalate issues and ensure evidence is maintained. Technical contributors may support but should not be the only accountable party.

Can this register replace specialist assessments?

No. It supports structured governance but does not replace legal analysis, privacy impact assessments, threat modelling, safety cases, human-rights assessments, model validation or domain-specific assurance.

Where is browser register data stored?

Browser entries use localStorage on the current device. They are not transmitted externally by this page. Clearing browser data or using another device will remove or hide them.

How does duplicate detection work?

The browser register compares a normalised combination of AI system name, risk category and risk statement. Matching entries are blocked to reduce accidental duplication.

Can I import and export the register?

Yes. The page supports local CSV import, CSV export, JSON export and print. Imported files are processed in the browser and are not sent to an external service.

Privacy note: Calculations and browser register functions run locally in your browser unless the existing site deliberately implements secure server-side storage. The basic PHP submission recalculates the result on the server for no-JavaScript support; this file does not persist submitted risk data.