What an AI risk register is
An AI risk register is a living record of AI-specific risks, their owners and controls. It turns a general intention to be careful into a concrete, reviewable list.
Why ordinary IT risk registers may not be enough
An IT register is a good base, but AI adds use-case risks such as inaccurate or fabricated output, inappropriate information handling and loss of meaningful human oversight. These deserve explicit entries.
What to record for each AI risk
AI system or use case
Identify the tool and the specific task, not just AI in general.
Potential impact
Describe what could go wrong and who is affected.
Likelihood and consequence
Rate both so risks can be compared and prioritised.
Existing controls
Record what already reduces the risk today.
Risk owner
Name the person accountable for the risk.
Treatment and residual risk
State the planned treatment and the risk that remains after it.
Review trigger and evidence
Note what prompts a review and where the supporting evidence lives.
Risk starts with the use case, not just the model
The same model is low-risk for public drafting and higher-risk for decisions about people. Anchor each entry to the use case and the information involved.
Screen first, assess proportionately
Use quick screening to triage use cases, then assess the higher-risk ones in more depth. Screening decides how much assessment is needed; it is not the assessment itself.
Connect the risk register to operational controls
AI policy
The AI policy sets the rules the register helps enforce.
AI systems register
The use register tells you which systems the risk register must cover.
Human review
Higher-risk entries should require human review before AI output drives action.
Testing and monitoring
Test controls and monitor outcomes for the highest-consequence uses.
Incident records
Capture incidents and near-misses so the register stays honest.
How Traigun approaches AI risk
We help scope a proportionate register, connect it to policy and review, and keep evidence that controls are working, as part of the AI Governance Starter Pack.