Opis
What is an AI Risk Register?
An AI Risk Register is a structured record where an organisation documents what can go wrong with its AI systems, how likely it is and how severe, which controls reduce the risk, and the residual risk that remains after controls. Article 9 of the EU AI Act requires establishing, implementing and maintaining a risk-management system across the entire lifecycle of high-risk AI systems — this template turns that requirement into a practical, measurable, audit-ready document.
What you get (3-file bundle)
- Excel template — 8 worksheets: Cover, Dashboard, Risk Register (24 columns), Treatment Plan, Risk Catalogue, Matrix & Methodology, Audit Trail, Instructions & Legend.
- PDF user guide (15 pages) — 5×5 methodology, column-by-column reference, dashboard guide, glossary and regulatory references.
- PDF risk-identification checklist (1 page) — a quick 7-domain sweep for each AI system.
Key features
- Catalogue of 40 AI risks across 7 domains, based on the MIT AI Risk Repository (CC BY 4.0).
- 5×5 assessment methodology (likelihood × impact) with automatic inherent and residual risk scoring.
- Colour-coded risk levels: Low (1–4), Moderate (5–9), High (10–15), Critical (16–25).
- Risk appetite: residual risk ≤ 9 is automatically flagged as acceptable.
- Automated dashboard — 4 KPI cards, a 5×5 heatmap and 4 self-refreshing charts.
- 12 pre-filled example risks and 12 treatment actions as a starting point.
- Dropdown lists, conditional formatting and an audit trail supporting Article 12 (record-keeping).
Compliance and standards
| Framework | Relevance |
| EU AI Act | Regulation (EU) 2024/1689 — Art. 9 (risk management), Art. 10, 12, 14, 15, 72, 73. |
| ISO/IEC 23894:2023 | Artificial intelligence risk management. |
| ISO/IEC 42001:2023 | AI management system (AIMS). |
| ISO 31000:2018 | Risk management — treatment options. |
| GDPR | Regulation (EU) 2016/679 — DPIA and data protection. |
| MIT AI Risk Repository | Slattery et al. (2024), arXiv:2408.12622 — risk taxonomy. |
Who it is for
- Compliance officers and DPOs leading risk assessment and communication.
- Risk managers scoring likelihood and impact and defining controls.
- AI system owners and IT teams providing risk and control input.
- Management and internal audit tracking the dashboard and treatment status.
How it works (5 steps)
- Identify — pick relevant risks from the catalogue or add your own.
- Assess — enter likelihood and impact (1–5); scores and levels compute automatically.
- Controls — describe existing controls and enter the residual assessment.
- Treat — choose an option (avoid, mitigate, transfer, accept) and open an action.
- Monitor — the dashboard refreshes; track the heatmap and status.
Technical requirements
Microsoft Excel 2016 or newer, LibreOffice Calc or Google Sheets. No macros, no installation, no subscription. One-time purchase, perpetual licence for internal use, unlimited editing.
Frequently asked questions (FAQ)
An AI Risk Register is a record where an organisation documents the risks of its AI systems — likelihood, impact, existing controls, and residual risk — to comply with Article 9 of the EU AI Act. This template ships as an Excel file with a catalogue of 40 risks, a 5×5 methodology, and an automated dashboard.
Who must keep a risk register under the EU AI Act?
Providers and deployers of high-risk AI systems (Art. 6 and Annex III) must establish a risk-management system under Article 9. A risk register is the practical tool that documents and maintains this requirement across the system lifecycle.
How is a risk register different from an AI register (inventory)?
An AI register answers “what AI systems do we have?” (inventory, owner, classification). A risk register answers “what can go wrong and how do we control it?” (likelihood, impact, controls, residual risk). They link via a shared system ID (e.g. AI-001).
What does the template include?
The bundle contains three files: an Excel template (8 sheets, 24 columns, 40 risks, dashboard), a 15-page PDF user guide and a 1-page PDF risk-identification checklist.
Do I need special tools or coding skills?
No. The template works in Excel, LibreOffice, and Google Sheets, with no macros and no installation. All risk-scoring formulas are built in — you only enter likelihood, impact, and controls.
Is it aligned with ISO 42001 and ISO 23894?
Yes. The methodology follows ISO/IEC 23894 (AI risk management) and ISO 31000, and the structure supports an AI management system under ISO/IEC 42001. EU AI Act article references are cited directly in the template.
Can I customise it for my organisation?
Yes. The template is fully editable — add risks, change controls, adjust risk-appetite thresholds, and extend the catalogue with your own risks.










