Building an AI Risk Register
An AI risk register is a living log of every AI risk your business carries, the model, the harm, the likelihood, the owner, and the mitigation. It is the first artifact regulators, insurers, and enterprise clients request, and it maps directly to the NIST AI RMF Map and Manage functions.
What belongs in the register
Each entry captures the AI system, the specific risk, its likelihood and impact, the accountable owner, and the mitigation. This mirrors NIST AI RMF, which spans four functions and 72 subcategories built around exactly this kind of mapping.
- System & use case, what the AI does and where.
- Risk description, e.g. hallucination in client-facing answers, data leakage, biased screening.
- Likelihood & impact, a simple high/medium/low scoring is enough to prioritize.
- Owner, a named person, not a department. Only 28% of organizations have defined AI oversight roles (Knostic, 2025).
- Mitigation & status, the control in place and whether it is live.
The GenAI-specific risks to log first
Start with the 12 risks NIST named in its July 2024 Generative AI Profile. The highest-frequency ones for operating businesses are confabulation (hallucination), prompt injection, data leakage, and IP/copyright exposure.
These are not theoretical. 63% of organizations that suffered an AI-related breach lacked a formal governance policy and 97% lacked proper access controls (Knostic, 2025), both are register line-items that would have flagged the exposure before it became an incident.
Frequently asked questions.
What is an AI risk register?
A living document that logs each AI system, the risks it carries, their likelihood and impact, a named owner, and the mitigation in place. It is the core artifact of the NIST AI RMF Map and Manage functions and the first thing auditors ask for.
Which AI risks should we track first?
Begin with NIST’s 12 GenAI risks (July 2024 profile). For most businesses the priority four are hallucination in customer-facing output, prompt injection, data leakage into third-party models, and IP/copyright exposure.