What Is an AI Risk Register?
It's a living document that catalogues AI risks, scores their likelihood and impact, identifies mitigations, assigns ownership, and tracks review dates. Every well-governed organisation has a general risk register. Most don't have one for AI specifically.
That matters because AI risks don't fit neatly into existing risk categories. Algorithmic bias isn't a traditional IT risk. Automated decision-making transparency isn't a traditional compliance risk. Agentic browser credential exposure isn't a traditional cybersecurity risk. These risks need their own register because they fall between existing governance structures.
ASIC Report 798 found nearly 50% of financial services licensees lacked fairness policies. A properly maintained AI risk register would have flagged that gap before ASIC found it. The register isn't overhead. It's early warning.
Template Structure
The template includes six columns for each risk entry:
Risk Category: The type of AI risk (bias, privacy, governance, explainability, compliance, vendor, workforce)
AI System: The specific system or tool the risk applies to. Be precise. "Credit scoring model v3.2" not "AI systems."
Likelihood: Low, Medium, or High. Based on current controls and exposure.
Impact: Low, Medium, High, or Critical. Based on regulatory, financial, and reputational consequences.
Mitigation: Specific actions in place or planned to reduce the risk. Not "we'll look into it." Documented steps with timelines.
Owner: Named individual accountable for monitoring and acting on this risk. Not a committee. A person.
Review Date: Next scheduled review. Quarterly at minimum for critical risks.
Pre-Loaded Risk Categories
The template comes with seven risk categories pre-populated based on common Australian AI exposures:
1. Algorithmic Bias AI systems producing discriminatory outcomes across protected characteristics. Relevant to credit scoring, insurance pricing, HR screening, and customer service routing. ASIC's focus area under REP 798.
2. Unexplainable Decisions AI systems making decisions that can't be explained in plain English to customers or regulators. ASIC found "black box" credit scoring at one licensee where nobody could explain the variables influencing outcomes.
3. Privacy and Data Sovereignty AI tools processing personal information without adequate security controls or offshore data processing without appropriate safeguards. OAIC Privacy Sweep targeting 60 entities. APP 11 applies to all AI processing of personal data.
4. Governance Gap Operating AI systems without board-approved policies for fairness, transparency, and accountability. Many Australian firms have no AI governance procedures. This risk is the foundation. Without governance, every other risk is unmanaged.
5. ADM Compliance Failure Missing the 10 December 2026 ADM transparency deadline. Legislative breach triggering OAIC enforcement. Risk increases as the deadline approaches and advisory capacity fills up.
6. Vendor Risk AI vendor claims that aren't independently verifiable. Vendors asserting "fair and unbiased" models without providing documentation. Vendor data processing practices that don't meet Australian regulatory requirements.
7. Workforce AI Usage Employees using consumer AI tools (personal ChatGPT accounts, unapproved browser extensions, agentic browsers) to process business or customer data. 28% of enterprises downloaded OpenAI's Atlas browser within one week with no IT approval.
How to Use This Template
Step 1: List every AI system in your organisation. Include automated decision-making tools, AI-powered analytics, chatbots, scoring models, and any tool where AI processes data or makes recommendations. Most organisations discover more systems than expected. I've audited firms that thought they had two and found eleven.
Step 2: For each system, assess risks across all seven categories. Not every system will have risks in every category, but every system should be evaluated against each one.
Step 3: Assign owners. A risk without an owner is unmanaged. The owner must be a named individual with authority to act, not a department or committee.
Step 4: Set review dates. Critical risks (bias, compliance deadlines) should be reviewed quarterly. Medium risks reviewed bi-annually. Low risks reviewed annually.
Step 5: Present to the board. The risk register should appear in board minutes at least quarterly. This creates the evidence trail that demonstrates reasonable care under Section 180.
Related Resources
- AI Governance Framework: Full governance framework
- AI Compliance Checklist: Step-by-step compliance verification
- ASIC AI Director Duties: Director obligations
- AI Risk for Boards: Complete board risk guide
Download the template, populate it with your AI systems, and bring it to your next board meeting. If you can't fill in every row, that gap is your risk. Book a governance diagnostic to close it.
Related Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.