Back to Blog

    The One-Page AI Risk Register Worth Keeping

    Enterprise risk registers are theatre for a 60-person company. Here is the version that actually gets used.

    Erin Moore

    Erin Moore

    Fractional Chief AI Officer

    |September 24, 20263 min read
    The One-Page AI Risk Register Worth Keeping
    Share:
    Share:

    An AI risk register worth keeping lists every AI system in use, what data each touches, who owns it, and what happens if it fails. Four columns. Enterprise templates with likelihood-impact matrices and residual-risk scoring are theatre at the scale most growing businesses operate at, and they go stale within a quarter because nobody can face updating them.

    The four columns

    System. The tool, by name, including the ones bought by a single department. Discovering these is its own exercise — see how to find shadow AI.

    Data it touches. Specifically. "Customer data" is not specific; "customer names, email addresses and order history" is. This column is what you reach for when a customer or auditor asks.

    Owner. A person, not a department. If nobody's name fits in this cell, that is the finding.

    Failure mode. What actually happens when the output is wrong, and who notices. Most rows are boring, which is useful — it tells you where the real exposure sits.

    What to leave out

    Numeric likelihood scores, five-point impact scales, and residual-risk calculations. At small scale these produce false precision and consume the effort that should go into keeping the register current. A register that is accurate and crude beats one that is elegant and eighteen months old.

    Also leave out systems you are merely considering. The register describes what is running.

    Keeping it alive

    Review quarterly, alongside the AI policy, and update whenever a tool is adopted or dropped. The register is the natural output of the standing agenda item described in who owns AI governance — fifteen minutes on what was adopted, declined or went wrong.

    If you want a public structure to align the vocabulary with, NIST's AI Risk Management Framework treats this kind of inventory as foundational to its "map" function, which is a useful thing to be able to cite when someone asks what standard you follow.

    The test of a good register

    Someone outside your team should be able to read it and answer three questions: what AI are you running, whose data does it touch, and who is answerable. If your register cannot do that, it is documentation rather than governance.

    Frequently asked questions

    What should an AI risk register include? Four columns: the system by name, the specific data it touches, a named owner, and what happens when it fails. Anything more tends to go unmaintained.

    Do we need likelihood and impact scores? Not at small scale. Numeric scoring produces false precision and consumes the effort better spent keeping the register current and complete.

    How often should it be reviewed? Quarterly, plus whenever a tool is adopted or retired. Tools change faster than policies, so the register goes stale before the policy does.

    Who should maintain it? Whoever owns AI governance — a single named person with authority over AI spend, not a committee and not IT by default.

    Further reading

    Erin Moore

    Written by

    Erin Moore

    Fractional Chief AI Officer

    Army Veteran turned Fractional Chief AI Officer. Founder of AutomateNexus. I help growing businesses implement enterprise-grade AI solutions that deliver ROI in 90 days or less. Author of "The AI Automation Field Manual."

    Ready to Automate Your Business?

    Let's discuss how AI automation can deliver measurable ROI for your organization in 90 days or sooner.