Templates / AI risk register template

AI risk register template

An AI risk register catalogues the risks that come with building or deploying AI — bias, drift, prompt injection, PII leakage, weak human oversight, regulatory classification. The worked example below reflects the risk areas behind the EU AI Act, ISO/IEC 42001, and the NIST AI RMF, and is free to download or open live.

Open live in Urna — free Download the CSV

No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.

Worked example: ai risk register template

RiskCategoryLikelihoodImpactRatingSuggested remediation
EU AI Act risk-classification / non-conformityThe system is not correctly classified under the EU AI Act (e.g. an unrecognised high-risk use), so required conformity, documentation and oversight obligations are missed.accountabilitymediumhighhighDetermine the EU AI Act risk category and map obligations to controls.
Bias / unfair outcomes across groupsThe model produces systematically different or worse outcomes for some demographic groups.bias_fairnesshighhighhighRun bias / fairness evaluation across relevant groups and document results.
Model drift / performance degradationModel accuracy degrades over time as real-world data diverges from the training distribution.robustnesshighmediumhighSet performance baselines and monitor for drift with defined thresholds and alerts.
Prompt injection / jailbreakingMalicious instructions in user input or retrieved content override the system's intended behaviour or bypass safety constraints.securityhighhighhighRed-team for prompt injection and jailbreaking before and during deployment.
Training-data privacy / PII leakagePersonal data in training or context is memorised and surfaced in outputs, or processed without a lawful basis.privacymediumhighhighMinimise and document training data; apply a lawful basis and data-protection controls.
Insufficient transparency / missing AI disclosureUsers are not told they are interacting with AI or how outputs are produced, breaching transparency duties (EU AI Act Art. 50).transparencymediummediummediumDisclose AI use to users and label AI-generated content.
Insufficient human oversightConsequential decisions are automated without a human able to review, override or intervene in real time.accountabilitymediumhighhighDefine human-in-the-loop controls at each consequential step, with the authority and information to intervene.
Compromised / poisoned model or dependencyAn externally sourced model or dependency carries a backdoor, or training data is poisoned so the model fails on attacker-chosen inputs.securitymediumhighhighObtain models only from trusted origins; verify integrity and provenance (signing) where available.
Hallucinated / incorrect output relied uponThe model produces plausible but false output that a user or downstream process acts on.robustnesshighmediumhighGround responses in verified sources and surface uncertainty / citations.
Unsafe autonomous-agent actionsAn agent with tool or write access takes unintended or irreversible actions beyond its intended scope.safetymediumhighhighScope agent permissions tightly; require approval for consequential or irreversible actions.

Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.

Questions

What is an AI risk register?

A structured record of the risks specific to an AI system or an organisation's AI use — technical (drift, hallucination), governance (oversight, transparency), and regulatory (EU AI Act classification) — each rated and treated. It's the documented risk assessment behind ISO 42001 and the EU AI Act's risk-management requirement.

Does the EU AI Act require a risk register?

Article 9 requires a risk-management system for high-risk AI that is established, documented, and maintained — a risk register in all but name. High-risk obligations apply from December 2027, and building the inventory and register now is the recommended way to prepare.

Is there a free AI risk register tool?

Yes. Download the CSV free, or open it live in Urna, which also keeps an AI systems inventory (including shadow AI) alongside the register. No card required.

Build your own in Urna — free

Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.

Start free See how it works