Templates / Electoral technology risk register template

Electoral technology risk register template

A risk register for the technology and AI risks facing an election management body — from phishing and results-transmission interception to shadow AI and electronic-count verifiability. The worked example below is drawn from electoral-cybersecurity guidance and is free to download or open live in Urna's election edition.

Open live in Urna — free Download the CSV

No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.

Worked example: electoral technology risk register template

RiskCategoryLikelihoodImpactRatingSuggested remediation
Phishing / credential theft against staffAn attacker tricks a staff member into revealing login credentials or installing malware, gaining access to electoral systems.securityhighhighhighEnforce phishing-resistant multi-factor authentication (hardware keys or passkeys) for privileged accounts.
AI-enhanced phishing and deepfakesGenerative AI produces convincing, personalised phishing content or deepfake audio/video impersonating a senior official to manipulate staff.securityhighhighhighTrain staff to recognise AI-generated manipulation and to verify unusual instructions out-of-band.
Ransomware locking electoral systemsMalware encrypts drives or locks staff out of systems during a critical period, with a demand for payment.operationalmediumhighhighMaintain tested, offline backups and a documented recovery procedure.
Interception in transitAn attacker intercepts results data during transmission to alter it before it reaches the central server.technicallowhighmediumEncrypt all transmitted data end to end.
Vendor / supply-chain compromiseA flaw or malicious code is introduced through a vendor, hosting provider or software update, exposing electoral data or systems.securitymediumhighhighSet contractual security standards, audit rights and incident-notification periods for vendors.
Voter register data breachPersonal data from the voter register is exfiltrated and leaked or offered for sale.legalmediumhighhighEncrypt the register at rest and in transit; apply least-privilege access.
Shadow-AI leakage of sensitive electoral dataStaff paste voter-register extracts or results data into a public AI tool to summarise or analyse it, transmitting personal data to a third party.legalhighhighhighPublish an AI use policy: approved tools, and data categories that may never be sent to external services.
Tampering with electronic vote recordsVote records held or moved by the e-voting system are altered — in the machine, in transit or in the count store — changing results without visible trace.securitylowhighmediumUse end-to-end cryptographic integrity (signing at capture, verification at count) so any alteration is detectable.
No independent way to verify the electronic countWithout a voter-verified paper trail or equivalent, the electronic count cannot be independently audited — so even a false claim of manipulation cannot be disproven, collapsing confidence.politicalmediumhighhighMaintain a voter-verified paper audit trail (or legally equivalent independent record) for every electronically-cast vote.
False claims of manipulationA candidate or actor alleges the system was hacked and results altered, despite no evidence of a breach, to undermine confidence.reputationalhighmediumhighMaintain an end-to-end audit trail with digital signatures at each step.

Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.

Questions

What is an electoral technology risk register?

A structured record of the cybersecurity and AI risks to electoral systems — voter registration, results transmission, electronic voting, public-facing information — each rated and matched to controls. It's a common deliverable in donor-funded and audit contexts.

Who is this for?

Election management bodies, electoral-assistance programmes, and observer groups assessing the technology and AI risk around an election. Urna's election edition is built for exactly this.

Is it free?

Yes — download the CSV free, or open it live in Urna. No card.

Build your own in Urna — free

Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.

Start free See how it works