Templates / Electoral technology risk register template
Electoral technology risk register template
A risk register for the technology and AI risks facing an election management body — from phishing and results-transmission interception to shadow AI and electronic-count verifiability. The worked example below is drawn from electoral-cybersecurity guidance and is free to download or open live in Urna's election edition.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: electoral technology risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Phishing / credential theft against staffAn attacker tricks a staff member into revealing login credentials or installing malware, gaining access to electoral systems. | security | high | high | Enforce phishing-resistant multi-factor authentication (hardware keys or passkeys) for privileged accounts. | |
| AI-enhanced phishing and deepfakesGenerative AI produces convincing, personalised phishing content or deepfake audio/video impersonating a senior official to manipulate staff. | security | high | high | Train staff to recognise AI-generated manipulation and to verify unusual instructions out-of-band. | |
| Ransomware locking electoral systemsMalware encrypts drives or locks staff out of systems during a critical period, with a demand for payment. | operational | medium | high | Maintain tested, offline backups and a documented recovery procedure. | |
| Interception in transitAn attacker intercepts results data during transmission to alter it before it reaches the central server. | technical | low | high | Encrypt all transmitted data end to end. | |
| Vendor / supply-chain compromiseA flaw or malicious code is introduced through a vendor, hosting provider or software update, exposing electoral data or systems. | security | medium | high | Set contractual security standards, audit rights and incident-notification periods for vendors. | |
| Voter register data breachPersonal data from the voter register is exfiltrated and leaked or offered for sale. | legal | medium | high | Encrypt the register at rest and in transit; apply least-privilege access. | |
| Shadow-AI leakage of sensitive electoral dataStaff paste voter-register extracts or results data into a public AI tool to summarise or analyse it, transmitting personal data to a third party. | legal | high | high | Publish an AI use policy: approved tools, and data categories that may never be sent to external services. | |
| Tampering with electronic vote recordsVote records held or moved by the e-voting system are altered — in the machine, in transit or in the count store — changing results without visible trace. | security | low | high | Use end-to-end cryptographic integrity (signing at capture, verification at count) so any alteration is detectable. | |
| No independent way to verify the electronic countWithout a voter-verified paper trail or equivalent, the electronic count cannot be independently audited — so even a false claim of manipulation cannot be disproven, collapsing confidence. | political | medium | high | Maintain a voter-verified paper audit trail (or legally equivalent independent record) for every electronically-cast vote. | |
| False claims of manipulationA candidate or actor alleges the system was hacked and results altered, despite no evidence of a breach, to undermine confidence. | reputational | high | medium | Maintain an end-to-end audit trail with digital signatures at each step. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is an electoral technology risk register?
A structured record of the cybersecurity and AI risks to electoral systems — voter registration, results transmission, electronic voting, public-facing information — each rated and matched to controls. It's a common deliverable in donor-funded and audit contexts.
Who is this for?
Election management bodies, electoral-assistance programmes, and observer groups assessing the technology and AI risk around an election. Urna's election edition is built for exactly this.
Is it free?
Yes — download the CSV free, or open it live in Urna. No card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.