Templates / Shadow AI risk register template
Shadow AI risk register template
Shadow AI is the unapproved AI tools staff use on work data — the biggest new source of uncontrolled risk in most organisations. This register captures the shadow-AI risks and their treatments, free to download or open live. Urna also keeps an AI systems inventory so you can catalogue the tools themselves.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: shadow ai risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Shadow or unsanctioned AI useStaff paste confidential documents, customer data or code into public AI tools to get work done faster, sending that data to a third party outside any agreement or oversight. | legal | high | high | Publish a short AI-use policy: which tools are approved, and the data categories that must never be pasted into a public service. | |
| Sensitive data sent to an external AI modelPrompts, documents or records sent to a hosted model for inference leave your security boundary — retained in logs, exposed to the provider, or transferred across borders — even when the AI use is sanctioned. | legal | high | medium | Classify what may and may not be sent to an external model, and minimise or redact personal and confidential data in prompts. | |
| Over-reliance on unverified AI outputStaff or an automated process act on confident-sounding AI output that is wrong, fabricated or biased, because no one with the authority or information reviews it before it is used. | operational | high | high | Keep a person in the loop for any consequential decision, with the authority, time and information to override the AI. | |
| Prompt injection of a deployed AI featureMalicious instructions hidden in user input or in content the model retrieves override its intended behaviour — leaking data, calling tools, or producing harmful output. | security | medium | high | Red-team the feature for prompt injection and jailbreaking before launch and periodically after. | |
| Insecure AI-assisted developmentStaff use AI coding assistants to build or change software and ship the output without review, introducing vulnerabilities, insecure dependencies, hardcoded secrets or unmanaged systems. | security | high | medium | Require human security review and testing of AI-generated code before it reaches production, the same as any other code. | |
| Intellectual-property and copyright exposure in AI outputAI-generated text, images or code reproduces third-party material or carries unclear ownership, and the organisation uses it without the rights to do so — or cannot protect its own output. | legal | medium | medium | Set rules for using generative-AI output in products and published material, including where it may not be used. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is shadow AI?
Shadow AI is the use of AI tools that haven't been approved or reviewed — staff pasting work data into public chatbots, building unofficial automations, or shipping AI-assisted code without review. Most organisations have it; few have a policy for it.
How do you manage shadow AI risk?
Inventory the AI actually in use (including the unofficial tools), flag anything touching sensitive data, publish an approved-tools list and a request route, and record the risks in a register with owners and controls — exactly what the example below and Urna set up.
Is there a free tool for this?
Yes — download the register CSV free, or open it live in Urna, which combines the register with an AI systems inventory. No card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.