Most organisations already have a risk register. Almost none have a real AI risk register.
They copy/paste cybersecurity risks, add “AI” in the title, and hope it works. It doesn’t. AI creates new behaviours, new dependencies, new failure modes, and new regulatory obligations your existing register was not designed for.
Good news: You don’t need a new risk framework ; you need a better one, adapted to AI’s realities.
Here is the practical, field-tested method to build an AI risk register that actually works.
AI risk is not “cyber risk with a twist.” AI systems:
- change over time,
- depend on datasets you don’t always control,
- rely on vendors you don’t always see,
- produce outputs you cannot fully predict,
- affect decisions you cannot always trace.
Your risk register must reflect that.
The secret is simple:Blend ISO 27005 + ISO 31000 + ISO/IEC 42001 thinking ; without reinventing everything.
Let’s break down the method step by step.
1. Start by Identifying Your AI Assets
Your AI risk register begins with a clear inventory. You cannot assess what you cannot identify.
List four asset categories:
AI Systems LLMs, classifiers, predictive models, chatbots, scoring engines.
AI Pipelines & Data Sources Training datasets, inference data, preprocessing.
AI-Embedded Services HR screening tools, fraud models, recommendation engines, AI copilots.
External & GPAI Models Azure OpenAI, Claude, Gemini, HuggingFace APIs, SaaS features with embedded AI.
If you skip this step, the risk register collapses.
2. Categorise the AI Assets by Risk Exposure
Not all AI is equal.
Use AI-specific criticality metrics:
- autonomy (how independent is the system?)
- decision criticality
- business impact
- data sensitivity
- explainability required
- drift likelihood
- user exposure
- regulatory category (EU AI Act: minimal, limited, high-risk)
This gives you the lens you’ll use to prioritise risks.
3. Expand Your Threat Catalogue to Include AI Failure Modes
Traditional threat libraries miss 80% of AI risk. You need AI-specific threats and vulnerabilities.
Dataset-related threats
- bias in training data
- data poisoning
- inaccurate labels
- leakage through prompts
- PII exposure in outputs
Model-related threats
- hallucinations
- adversarial prompts
- model drift
- loss of reproducibility
- lack of explainability
Operational threats
- AI service outages
- uncontrolled model updates
- misuse by employees
- over-reliance on AI outputs
Governance & Compliance threats
- failure to meet AI Act requirements
- missing model documentation
- unclear human oversight boundaries
- unapproved AI tools in use
- no audit trail for AI decisions
These threats feed directly into your risk scenarios.
4. Write Risk Scenarios Using a Standard ISO 27005 Structure
You don’t need a new method. You need new scenarios.
Example Scenario 1
Threat: AI chatbot hallucinates incorrect medical advice.Vulnerability: No human review or output validation.Impact: Legal liability, reputational damage, patient harm.Likelihood: MediumControls: Human-in-the-loop review, prompt filtering, usage restrictions.Residual Risk: Low
Example Scenario 2
Threat: Model drift reduces fraud detection accuracy.Vulnerability: No monitoring of model performance over time.Impact: Financial loss, regulatory incident.Controls: Drift monitoring, retraining schedule, thresholds.Residual Risk: Medium
Example Scenario 3
Threat: Employees share sensitive data with an external LLM.Vulnerability: No AI usage policy or prompt controls.Impact: Data leakage, GDPR breach.Controls: Access restrictions, policy, training, monitoring.Residual Risk: Low/Medium
This is the level of clarity auditors will expect during AI Act enforcement.
5. Score the Risks Properly (AI Requires Extra Dimensions)
Likelihood and impact still apply, but with additional factors specific to AI.
Add the following dimensions to your scoring logic:
- drift risk
- data quality risk
- explainability requirement
- dependence on third-party AI
- autonomy level
- model predictability
- potential for discrimination
- cross-border data exposure
These factors influence your likelihood/impact scoring.
You don’t need new columns ; just deeper evaluation.
6. Map Each Risk to AI-Specific Controls
AI risks require both security and governance controls.
Typical AI controls include:
- dataset validation
- content filtering
- bias testing
- human oversight
- role-based access
- drift monitoring
- usage policies
- logging & traceability
- model versioning
- incident response for AI failures
- explainability mechanisms
- vendor evaluation for AI providers
Match controls to risks the same way you do with ISO 27001.
7. Integrate AI Risk Into Your Existing Risk Register
You don't need a separate register. You need to enrich your existing one.
Add AI risks into your main register, but include:
- “AI asset” as an asset category
- “AI model” or “AI data pipeline” as an asset type
- AI-specific threats and vulnerabilities
- specific controls
- updated scoring
- owner accountable for the AI system
- regulatory implications (AI Act, GDPR, sectoral rules)
This ensures AI governance becomes part of your ISMS ; not an isolated initiative.
8. Add AI Risk Into Existing GRC Processes
The risk register is only useful if it's embedded in governance.
AI risks must feed into:
- change management
- vendor management
- incident response
- internal audit
- training awareness
- ISMS reviews
- Board reporting
AI risks evolve faster than traditional IT systems ; governance must follow.
9. Review AI Risks More Frequently Than Traditional Risks
AI systems change:
- through retraining,
- through drift,
- through new use cases,
- through vendor model updates,
- through regulatory milestones.
Quarterly review is minimum. Monthly for high-impact AI systems.
AI risks are not “set and forget.”
10. Provide a Simple, Readable Template for All Teams
Here is a ready-to-use AI Risk Register Template you can adopt today. Use it inside Excel, Notion, Confluence, or your existing GRC platform.
📄 AI Risk Register Template (Download)
Final Thought
An AI risk register is not a compliance exercise. It’s a visibility tool, a control mechanism, and the foundation of your AI governance.
If you build it properly, you don’t just protect the organisation, you enable safe, scalable, confident AI adoption.
AI governance isn’t about slowing innovation. It’s about making sure innovation doesn’t blow up in your face.
If you want to build a complete AI risk management program ; including templates, controls, and ISO/IEC 42001 alignment ; that’s exactly what we teach in the Cyber Academy AI Risk Manager course. Join the next session and build an AI risk register that stands up to scrutiny.
