What an AI risk register is

An AI risk register is a living record of AI-specific risks, their owners and controls. It turns a general intention to be careful into a concrete, reviewable list.

Why ordinary IT risk registers may not be enough

An IT register is a good base, but AI adds use-case risks such as inaccurate or fabricated output, inappropriate information handling and loss of meaningful human oversight. These deserve explicit entries.

What to record for each AI risk

AI system or use case

Identify the tool and the specific task, not just AI in general.

Potential impact

Describe what could go wrong and who is affected.

Likelihood and consequence

Rate both so risks can be compared and prioritised.

Existing controls

Record what already reduces the risk today.

Risk owner

Name the person accountable for the risk.

Treatment and residual risk

State the planned treatment and the risk that remains after it.

Review trigger and evidence

Note what prompts a review and where the supporting evidence lives.

Risk starts with the use case, not just the model

The same model is low-risk for public drafting and higher-risk for decisions about people. Anchor each entry to the use case and the information involved.

Screen first, assess proportionately

Use quick screening to triage use cases, then assess the higher-risk ones in more depth. Screening decides how much assessment is needed; it is not the assessment itself.

Connect the risk register to operational controls

AI policy

The AI policy sets the rules the register helps enforce.

AI systems register

The use register tells you which systems the risk register must cover.

Human review

Higher-risk entries should require human review before AI output drives action.

Testing and monitoring

Test controls and monitor outcomes for the highest-consequence uses.

Incident records

Capture incidents and near-misses so the register stays honest.

How Traigun approaches AI risk

We help scope a proportionate register, connect it to policy and review, and keep evidence that controls are working, as part of the AI Governance Starter Pack.