Skip to main content

    Executive tool

    AI Risk Register Template: Board-Ready Download

    An AI risk register is a structured document that tracks every AI-related risk in your organisation, from algorithmic bias and privacy breaches to governance gaps and compliance deadline failures. This template is pre-loaded with the most common AI risk categories Australian boards face, mapped to ASIC, OAIC, and APRA requirements. Download it, populate it with your AI systems, and review it quarterly. It's the single most important evidence document your board can produce if regulators investigate.

    What Is an AI Risk Register?

    It's a living document that catalogues AI risks, scores their likelihood and impact, identifies mitigations, assigns ownership, and tracks review dates. Every well-governed organisation has a general risk register. Most don't have one for AI specifically.

    That matters because AI risks don't fit neatly into existing risk categories. Algorithmic bias isn't a traditional IT risk. Automated decision-making transparency isn't a traditional compliance risk. Agentic browser credential exposure isn't a traditional cybersecurity risk. These risks need their own register because they fall between existing governance structures.

    ASIC Report 798 found nearly 50% of financial services licensees lacked fairness policies. A properly maintained AI risk register would have flagged that gap before ASIC found it. The register isn't overhead. It's early warning.

    Template Structure

    The template includes six columns for each risk entry:

    Risk Category: The type of AI risk (bias, privacy, governance, explainability, compliance, vendor, workforce)

    AI System: The specific system or tool the risk applies to. Be precise. "Credit scoring model v3.2" not "AI systems."

    Likelihood: Low, Medium, or High. Based on current controls and exposure.

    Impact: Low, Medium, High, or Critical. Based on regulatory, financial, and reputational consequences.

    Mitigation: Specific actions in place or planned to reduce the risk. Not "we'll look into it." Documented steps with timelines.

    Owner: Named individual accountable for monitoring and acting on this risk. Not a committee. A person.

    Review Date: Next scheduled review. Quarterly at minimum for critical risks.

    Pre-Loaded Risk Categories

    The template comes with seven risk categories pre-populated based on common Australian AI exposures:

    1. Algorithmic Bias AI systems producing discriminatory outcomes across protected characteristics. Relevant to credit scoring, insurance pricing, HR screening, and customer service routing. ASIC's focus area under REP 798.

    2. Unexplainable Decisions AI systems making decisions that can't be explained in plain English to customers or regulators. ASIC found "black box" credit scoring at one licensee where nobody could explain the variables influencing outcomes.

    3. Privacy and Data Sovereignty AI tools processing personal information without adequate security controls or offshore data processing without appropriate safeguards. OAIC Privacy Sweep targeting 60 entities. APP 11 applies to all AI processing of personal data.

    4. Governance Gap Operating AI systems without board-approved policies for fairness, transparency, and accountability. Many Australian firms have no AI governance procedures. This risk is the foundation. Without governance, every other risk is unmanaged.

    5. ADM Compliance Failure Missing the 10 December 2026 ADM transparency deadline. Legislative breach triggering OAIC enforcement. Risk increases as the deadline approaches and advisory capacity fills up.

    6. Vendor Risk AI vendor claims that aren't independently verifiable. Vendors asserting "fair and unbiased" models without providing documentation. Vendor data processing practices that don't meet Australian regulatory requirements.

    7. Workforce AI Usage Employees using consumer AI tools (personal ChatGPT accounts, unapproved browser extensions, agentic browsers) to process business or customer data. 28% of enterprises downloaded OpenAI's Atlas browser within one week with no IT approval.

    How to Use This Template

    Step 1: List every AI system in your organisation. Include automated decision-making tools, AI-powered analytics, chatbots, scoring models, and any tool where AI processes data or makes recommendations. Most organisations discover more systems than expected. I've audited firms that thought they had two and found eleven.

    Step 2: For each system, assess risks across all seven categories. Not every system will have risks in every category, but every system should be evaluated against each one.

    Step 3: Assign owners. A risk without an owner is unmanaged. The owner must be a named individual with authority to act, not a department or committee.

    Step 4: Set review dates. Critical risks (bias, compliance deadlines) should be reviewed quarterly. Medium risks reviewed bi-annually. Low risks reviewed annually.

    Step 5: Present to the board. The risk register should appear in board minutes at least quarterly. This creates the evidence trail that demonstrates reasonable care under Section 180.

    Related Resources

    Download the template, populate it with your AI systems, and bring it to your next board meeting. If you can't fill in every row, that gap is your risk. Book a governance diagnostic to close it.

    Related Topics

    Explore This Pillar

    Go deeper with the matching master pillar and the most relevant supporting topics for this page.