AI Risk Register Template

How to Use

Copy and adapt this register for your organization. Each risk should be scored, assigned an owner, and tracked through your existing GRC processes.

Template

IDRiskCategoryLikelihoodImpactInherent RiskControlResidual RiskOwnerStatus
AI-001Prompt injection in customer chatbotTechnicalHighHighCriticalInput/output filtering, system prompt hardeningHighAppSec LeadOpen
AI-002Training data contains PIIPrivacyMediumHighHighData scanning, anonymization pipelineMediumData PrivacyOpen
AI-003Shadow AI adoption by employeesOperationalHighMediumHighAI acceptable use policy, DLP, CASBMediumCISOOpen
AI-004Third-party model API outageAvailabilityMediumMediumMediumMulti-provider fallback, cachingLowPlatform EngOpen
AI-005Model generates biased outputsComplianceMediumHighHighBias testing, human review, monitoringMediumAI EthicsOpen
AI-006Poisoned open-source model deploymentSupply ChainLowCriticalHighModel provenance, hash verification, sandboxingMediumML EngOpen
AI-007Model extraction via APIIP/TechnicalLowHighMediumRate limiting, output perturbation, monitoringLowAPI SecurityOpen
AI-008Non-compliance with EU AI ActRegulatoryMediumHighHighRisk classification, documentation, audit trailMediumLegal/GRCOpen
AI-009Hallucination in financial advisory toolIntegrityHighHighCriticalHuman-in-the-loop, output verification, disclaimersHighProductOpen
AI-010Employee uploads sensitive data to ChatGPTData LeakageHighHighCriticalDLP, approved AI tool list, training, endpoint controlsMediumSecurity OpsOpen

Scoring Guide

Likelihood: Low (unlikely) | Medium (possible) | High (probable)

Impact: Low (minor) | Medium (moderate disruption) | High (significant damage) | Critical (existential/regulatory)

Risk = Likelihood × Impact

Integration

This register should feed into your existing:

  • Enterprise Risk Management (ERM) system
  • GRC platform (ServiceNow, Archer, etc.)
  • Board-level risk reporting
  • Audit planning