FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Strategy · 4 minute read

AI Risk Register: Structure, Starter Risks, and Review Cadence

An AI risk register is a maintained list of the risks each AI system and the AI program carry, quality, safety, security, privacy, compliance, cost, vendor, and adoption, each with likelihood, impact, the control that addresses it, an owner, and a review date. It turns vague concern into assigned, tracked work, and it is what auditors ask for first.

By FISTA Solutions· AI-Native Engineering Team·
AI Risk Register: Structure, Starter Risks, and Review Cadence article cover

Every AI project has a list of things that could go wrong, usually in someone's head. A risk register moves that list into a document where each risk has a score, a control, an owner, and a review date, so it becomes work rather than worry. It is also the first document auditors, boards, and insurers ask for, and its absence is itself a finding. This guide covers the structure, a starter list of AI-specific risks, scoring, and cadence, drawing on FISTA Solutions' AI enablement practice. The wider risk framework is in ai model risk management and the standard in nist ai risk management framework explained.

What does a register entry contain?

FieldContent
Identifier and systemWhich system or the program
Risk statementWhat could happen and what would cause it
CategoryQuality, safety, security, privacy, compliance, cost, vendor, adoption, delivery
LikelihoodScored on a defined scale with reasoning
ImpactScored on a defined scale with reasoning
RatingDerived from likelihood and impact
ControlThe specific measure that reduces likelihood or impact
Control evidenceHow the control's operation is verified
OwnerNamed person accountable
Status and review dateOpen, mitigated, accepted, closed; next review

What AI-specific risks belong in a starter list?

  • Quality: accuracy below threshold on a category; groundedness failures; regression after prompt or model change. Controls: golden datasets, CI gates, production sampling. See the ai evaluation checklist.
  • Safety and fairness: harmful, biased, or non-compliant outputs. Controls: safety suites, fairness testing, output policy checks.
  • Security: prompt injection, tool misuse, jailbreaks. Controls: structural separation, least-privilege tools, validation, red teaming. See ai agent security risks.
  • Privacy: personal data in prompts, logs, or memory; unauthorized retrieval. Controls: redaction, permission-aware retrieval, retention. See ai data privacy compliance.
  • Cost: usage growth beyond budget; provider price changes. Controls: attribution, budgets, routing, caching. See ai cost optimization checklist.
  • Vendor: silent model changes, deprecation, outages, dependence. Controls: pinning, evaluation on updates, fallbacks, exit terms. See ai third party risk management.
  • Adoption: users ignore or over-rely on the system. Controls: change management, trust patterns, usage measurement.
  • Compliance: regulatory obligations unmet; disclosure failures. Controls: tiering, documentation, legal review.
  • Delivery: scope drift, data unavailable, integration blocked. Controls: specification, checkpoints, dependencies managed.

How should risks be scored?

Define likelihood and impact scales, typically three to five levels each, with descriptions so scores are comparable across systems. Derive a rating that sets review cadence and escalation thresholds. Record the reasoning behind each score, because scores without reasoning cannot be challenged or updated sensibly. Rescore at project checkpoints, after incidents, and after model or vendor changes. Assessment method is in the ai privacy impact assessment checklist for the privacy dimension.

How do system and program registers relate?

Each AI system has its own register maintained by its owner. A program-level register aggregates cross-cutting risks such as platform dependence, governance capacity, skills gaps, and regulatory change, and rolls up the highest-rated system risks. The program register is what the governance board and executive risk committee review. Governance structure is in ai governance board.

How do controls and evidence close the loop?

A control is specific and verifiable: not "we test for bias" but "fairness tests by protected attribute run in CI with thresholds; results attached to each release." Control evidence, such as test reports, gate logs, and monitoring dashboards, is referenced from the register so reviewers and auditors can verify operation without interviews. Controls without evidence are assertions. Monitoring practice is in the ai observability checklist.

What review cadence works?

High-risk systems monthly; medium quarterly; low annually; program register quarterly; and immediate review after incidents, model or vendor changes, regulatory developments, or material scope changes. Reviews update scores, verify control evidence, close mitigated risks, add new ones, and escalate ratings above threshold. Audit expectations are in what is an ai audit.

What are common mistakes?

Risks stated so vaguely they cannot be controlled; controls that are intentions rather than mechanisms; no owners; scores without reasoning; registers created for an audit and abandoned; and no link between the register and the delivery process, so new risks from changes never enter it. Each is visible to an auditor in minutes. Documentation integration is in the ai documentation checklist.

How FISTA Solutions helps build AI risk registers

FISTA Solutions builds system-level registers as part of every specification, implements controls with verifiable evidence in delivery pipelines, and helps clients establish program registers with scoring scales and review cadences tied to governance. The AI enablement practice leads governance design, forward deployed engineers embed with client risk and engineering teams, and AI agents ship with controls and evidence. The record behind the approach is 150+ projects for 50+ companies.

To turn AI risk from concern into managed work, message FISTA on WhatsApp, or read ai model risk management for the framework the register operates within.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What is an AI risk register?

A living document listing the risks associated with each AI system and the AI program overall, with each risk scored on likelihood and impact, paired with a control and an owner, and given a review date, so that risk is managed as assigned work rather than discussed as concern.

02What risks are specific to AI?

Quality below threshold on some category, harmful or biased outputs, prompt injection and tool misuse, data leakage through prompts or logs, cost growth with adoption, provider model changes, vendor dependence, adoption failure, regulatory non-compliance, and over-reliance by users, alongside conventional project and security risks.

03How should risks be scored?

With defined scales for likelihood and impact, typically three to five levels each, producing a rating that determines review cadence and escalation. Score consistently across systems, record the reasoning, and rescore at project checkpoints and after incidents.

04How does the register connect to governance?

System registers feed the inventory and risk tiering; high-rated risks escalate to the governance board; controls map to policy requirements; and audits sample the register for completeness, control evidence, and review discipline.

05How often should it be reviewed?

By risk tier: high-risk systems monthly, medium quarterly, low annually, with immediate review after incidents, model or vendor changes, regulatory developments, or material scope changes. Reviews update scores, verify controls, and close or add risks.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project