Practical asset
AI Risk Register: What to Record and How to Use It
Create a usable AI risk register covering risks, affected people, owners, controls, evidence, and reassessment.
Last updated
2026-09-14
What is an AI risk register?
An AI risk register is a working record of risks connected to a defined AI use case. It is not just a list of abstract concerns. Each entry should connect a risk to an affected outcome, an owner, a control, and evidence that the control is operating.
A useful register stays proportionate. It should help a team make decisions and revisit them when the system, data, users, or operating context changes.
Suggested fields
For each risk, record the description, cause, affected people or process, likelihood, impact, owner, mitigation, evidence, status, and reassessment trigger. Avoid inventing precise scores when the organisation has not defined a scoring method.
Iteretta's Compliance & AI Governance lab uses risk registers alongside policies, control frameworks, audit evidence, and governance decisions.
Common questions
Is an AI risk register a legal document?
Not necessarily. It can support governance, but it does not replace qualified legal advice, a formal compliance process, or organisation-specific requirements.
How can I show a risk register in a portfolio?
Use a fictional or permitted scenario, show the risk-to-control links, explain the ownership decisions, and state the assumptions and limits of the exercise.
This resource is maintained by Iteretta. It is educational information, not legal, financial, medical, employment, or other professional advice.