Skip to main content
AI-Si.com
RiskGovernance

Building an AI Risk Register From Scratch

Building an AI Risk Register From Scratch
Published 3 September 2026Last reviewed 3 September 20266 min readBy Simon Steggles· Fractional AI Director
Who this is for:UK SME owners, council service leads and board members who need a first AI risk register in place, not a 40-page framework.

TL;DR

Most organisations using AI have no written record of what could go wrong, who owns it, or what they would do about it. When something does go wrong, the board asks for the risk register and there isn't one. This is how to build a first version in a week that people will keep using.

Key takeaways

  • Start with an inventory of every AI use in the business, including the unofficial ones. You cannot register a risk against a tool you do not know exists.
  • Ten columns are enough. Every extra column is a reason for someone not to fill it in.
  • Every risk has one named owner. A committee is not an owner.
  • Score likelihood and impact on a 1 to 5 scale and write down what "3" means before you start, or the scores will drift.
  • Review it monthly for the first six months. A register nobody opens is not a control. It is a liability with a filename.

Most organisations using AI have no written record of what could go wrong, who owns it, or what they would do about it. When something does go wrong, the board asks for the risk register and there isn't one. This is how to build a first version in a week that people will keep using.

Why you need one now, not after the first incident

Proofpoint surveyed more than 1,400 security professionals in January 2026. In the UK, 94% of organisations had AI assistants deployed beyond pilot stage. 31% had already experienced a suspected or confirmed AI-related incident. Only 36% said they were fully prepared to investigate one. Read those three numbers together. Almost everyone is using AI. A third have already had a problem. Two thirds could not properly investigate it if it happened tomorrow.

A risk register does not stop incidents. It does two other things. It forces you to write down what you are actually running, and it gives you a place to put the answer to "what would we do if". When a director, an auditor, an insurer or the ICO asks how you manage AI risk, the register is the first document they will want to see. If you have one, the conversation is about its contents. If you do not, the conversation is about why not.

The UK government's own AI Management Essentials tool, finalised in February 2026, asks organisations whether they maintain a record of AI risks and how they are managed. It is voluntary today. Public sector buyers are already starting to ask suppliers the same questions in tenders. A register you built six months ago answers that question in one attachment.

Start with the inventory, not the risks

The most common mistake I see is starting with a blank risk register and trying to think of AI risks. You end up with generic entries like "bias" and "data leakage" that attach to nothing and mean nothing. Start the other way round. List every place AI is in use. Then ask what could go wrong with each one.

Your inventory needs four things per entry: what the tool is, who uses it, what data goes into it, and what decisions or outputs come out of it. Include the copilot bundled into your Microsoft licence. Include the AI feature your accounting software switched on in an update. Include the ChatGPT account your marketing lead pays for personally. If a third of your staff are using tools you have not approved, your register is a fiction until they are on the list.

Do this by asking, not by auditing. Send a two-line message to every team lead: "List every tool you or your team use that has AI in it, including free ones and personal accounts. No consequences, I need the full picture." You will get more honest answers this way than any discovery tool will give you, and you will get them in 48 hours. For a 40-person business expect 8 to 15 entries. For a council directorate, expect more than you think.

The ten columns that are enough

I have seen 30-column AI risk registers built from consultancy templates. None of them were still being updated three months later. Ten columns are enough for a first version. Here they are.

  • Reference number. R01, R02 and so on. You will need to refer to risks in meetings and minutes.
  • AI use it relates to. Taken from your inventory. One risk can attach to several uses.
  • Risk description. One sentence, written as "X happens, causing Y". Not "data risk". Instead: "Staff paste client contract text into a public AI tool, causing a confidentiality breach."
  • Category. Pick from a short fixed list: data protection, confidentiality, accuracy and hallucination, bias and fairness, security including prompt injection, legal and contractual, operational dependency, reputational.
  • Likelihood, 1 to 5.
  • Impact, 1 to 5.
  • Score. Likelihood multiplied by impact. Sort by this column.
  • Existing controls. What already reduces this risk today. Be honest. "None" is an acceptable answer and a useful one.
  • Planned actions, owner and date. What you will do, who will do it, by when. One named person. Not "IT" or "the leadership team".
  • Last reviewed. The date someone last looked at this row and confirmed or changed it.

Before you score anything, write a one-line definition for each point on both scales. Likelihood 3 might mean "plausible within 12 months". Impact 3 might mean "regulatory reportable or over £10,000 direct cost". Put those definitions at the top of the register. Without them, three different people will score the same risk 4, 9 and 20 and the sort order becomes meaningless.

Writing risks that mean something

A risk register earns its keep when a non-technical director can read a row and understand what would actually happen. Test every entry against that. "Model drift" fails the test. "The AI tool we use to triage inbound enquiries starts misclassifying complaints as general questions, so complaints go unanswered past the statutory deadline" passes it.

Cover the risks people skip because they feel awkward. Vendor dependency: what happens if the supplier doubles its price, changes its terms, or shuts down. Over-reliance: what happens when a member of staff stops checking the output because it has been right for six months. Prompt injection: what happens when a document or email your AI tool reads contains instructions aimed at the tool rather than the reader. The NIST AI Risk Management Framework is a useful checklist here. You do not need to adopt it. Read the "Map" section, which lists the categories of harm, and use it to check you have not missed a whole category.

Resist the urge to be complete. A first register with 12 well-written risks, each with a named owner and a date, is worth more than 60 entries that are half filled. You can add to it. You cannot easily get people to trust a document that started as noise.

Keeping it alive

The register needs a single owner. In an SME that is usually the managing director or operations director. In a council it is usually the head of the relevant service or the information governance lead. That person does not own every risk. They own the document and the review cycle.

Set a monthly 30-minute review for the first six months. The agenda is fixed: any new AI tools since last month, any incidents or near misses, any rows where the planned action date has passed, and the top five by score. After six months, if the register is stable, move to quarterly. Put the top five and any changes into the board or committee pack as a half-page summary. That is the whole reporting mechanism. It does not need a dashboard.

Store the register somewhere people can find it and in a format they can edit. A spreadsheet in a shared drive with version history is fine. A PDF is not, because nobody updates PDFs. If you later adopt ISO 42001 or a governance platform, the register migrates across. The columns above map directly onto what those frameworks ask for.

What to do this week

Send the inventory message to your team leads today. Give them until Friday. On Monday, open a spreadsheet with the ten columns, paste in the definitions for your 1 to 5 scales, and write your first ten risks from the inventory. Give each one a named owner and a date. Book the first monthly review in the calendar before you close the file.

That is a working AI risk register. It took a week, cost nothing, and puts you ahead of most organisations in the Proofpoint survey. If you want a structure to start from rather than a blank sheet, the linked resource below gives you the exact columns and scale definitions I use with clients.

About the author

Simon Steggles - Fractional AI Director

Simon helps UK SMEs and councils put AI to work safely. Royal Navy 1984–90 (Cat 3 PV at the time, now superseded by DV); current NPPV3 Police vetting for public-sector work; ISACA AI Governance certified. Based in Birmingham. £300K+ recovered for councils, 43% cost reduction in manufacturing, zero data-protection incidents across every engagement.

More about Simon

Want help applying this?

Grab the free AI Readiness Checklist or book a 30-minute strategy call with Simon - no pitch, no slide deck, just practical advice for your situation.

Free AI Readiness Checklist

Find Out Where AI Can Save or Generate Money in Your Organisation

Book a free 30-minute call with Simon. Bring a real problem - staff time, governance worry, vendor proposal, failing pilot - and leave with a concrete first step you can take next week.

Call