Skip to main content
AI Governance

Building an AI Risk Register

An AI risk register is a living log of every AI risk your business carries, the model, the harm, the likelihood, the owner, and the mitigation. It is the first artifact regulators, insurers, and enterprise clients request, and it maps directly to the NIST AI RMF Map and Manage functions.

8 min read/Written by Perry Luzier/Reviewed

What belongs in the register

Each entry captures the AI system, the specific risk, its likelihood and impact, the accountable owner, and the mitigation. This mirrors NIST AI RMF, which spans four functions and 72 subcategories built around exactly this kind of mapping.

  • System & use case, what the AI does and where.
  • Risk description, e.g. hallucination in client-facing answers, data leakage, biased screening.
  • Likelihood & impact, a simple high/medium/low scoring is enough to prioritize.
  • Owner, a named person, not a department. Only 28% of organizations have defined AI oversight roles (Knostic, 2025).
  • Mitigation & status, the control in place and whether it is live.

The GenAI-specific risks to log first

Start with the 12 risks NIST named in its July 2024 Generative AI Profile. The highest-frequency ones for operating businesses are confabulation (hallucination), prompt injection, data leakage, and IP/copyright exposure.

These are not theoretical. 63% of organizations that suffered an AI-related breach lacked a formal governance policy and 97% lacked proper access controls (Knostic, 2025), both are register line-items that would have flagged the exposure before it became an incident.

Questions

Frequently asked questions.

What is an AI risk register?

A living document that logs each AI system, the risks it carries, their likelihood and impact, a named owner, and the mitigation in place. It is the core artifact of the NIST AI RMF Map and Manage functions and the first thing auditors ask for.

Which AI risks should we track first?

Begin with NIST’s 12 GenAI risks (July 2024 profile). For most businesses the priority four are hallucination in customer-facing output, prompt injection, data leakage into third-party models, and IP/copyright exposure.

Want this built into your operation?

We install the systems described here as owned infrastructure. Start with a diagnostic of where your business actually loses time and margin.