AI Governance · Risk Management

AI Risk Register

Likelihood x impact, named owners, and NIST AI RMF mapping — not a spreadsheet nobody opens again.

Last reviewed:

"We're aware of the risks" is not a risk register. Awareness isn't management. A real register names each risk, scores it, assigns someone to own it, and sets the point where it escalates.

The 5x5 grid

Every risk is scored on two axes — likelihood (1-5) and impact (1-5) — multiplied for a severity score, visualised as a colour-coded heat map. That's what lets you rank risks against each other instead of treating everything as equally urgent.

Mapped to NIST AI RMF

  1. GovernPolicies and oversight structure.
  2. MapWhere AI risk actually lives in the organisation.
  3. MeasureThe likelihood x impact scoring.
  4. ManageMitigation and ongoing monitoring.

Get a free sample AI risk register — no cost, just your email.

Email me the free sample

Or go straight to the full register — $29, one-time.

Frequently asked

What is an AI risk register?
A structured document that names specific AI risks, scores each on likelihood and impact, assigns a named owner and escalation threshold, and lists concrete mitigation actions — as opposed to a general statement of risk awareness.
How is AI risk scored on a risk register?
Commonly on a 5x5 matrix: likelihood rated 1-5 and impact rated 1-5, multiplied for a severity score, visualised as a colour-coded heat map to rank risks against each other.
How does an AI risk register map to NIST AI RMF?
Against the framework's four functions: Govern (policies and oversight), Map (identifying where AI risk exists), Measure (scoring, e.g. the 5x5 matrix), and Manage (mitigation and ongoing monitoring).

This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.

Sources: NIST AI Risk Management Framework · ISO/IEC 42001:2023 · Responsible AI Studio .

← All AI governance resources