AI Risk Register Template: 25 Pre-Built Risks for Your Company
Last updated: June 2026 · Guardrail Studio
A blank risk-register spreadsheet is where good intentions go to die. Here's what an AI risk register should track, the 25 risks most SMBs face, and a free starter you can copy today.
What is an AI risk register?
An AI risk register is a structured list of the ways your use of AI could cause harm — a data leak, a compliance breach, a hallucinated deliverable — each with an owner, a mitigation, and a current status. It turns vague worry into a managed program, and it's the single artifact boards, insurers, and enterprise clients ask for when they want proof you take AI risk seriously.
What your AI risk register should track
Six columns do the job:
- Risk ID — a simple reference (R-01, R-02…).
- Description — the risk in one plain sentence.
- Likelihood — 1–5.
- Impact — 1–5 (likelihood × impact = a score that ranks the list).
- Mitigation — what you're doing about it.
- Owner & status — who's accountable, and whether it's Open, In progress, or Mitigated.
The 25 most common AI risks for SMBs
These are the risks we see again and again — a strong starting set for any small or mid-size company:
- Confidential or client data entered into free-tier AI tools
- Personal data processed by AI without a lawful basis
- Shadow AI — staff using unapproved tools
- Staff untrained on safe AI use
- Over-reliance on unverified AI output
- Source code or IP leaked into external models
- AI vendor trains on your submitted inputs
- Vendor data residency / sub-processors unknown
- No incident-response path for AI leaks
- Copyright infringement in AI-generated output
- Biased or discriminatory AI decisions
- Client contract prohibits the AI use
- Hallucinated facts in client deliverables
- Prompt injection / data exfiltration
- Credentials or secrets pasted into AI tools
- Customers misled by undisclosed AI use
- Non-compliance with AI regulation (EU AI Act, PDPA)
- No audit trail of AI use
- Insecure AI browser extensions / plugins
- Cyber-insurance AI exclusion leaves a loss uncovered
- Deepfake / AI social engineering of staff
- High-stakes decision made on AI output with no review
- Contractor or third-party misuse of AI on your data
- Data retained in an AI tool beyond your policy
- Process dependency / skill loss from one AI tool
Free starter risk register
| ID | Risk | Likelihood | Impact | Owner | Status |
|---|---|---|---|---|---|
| R-01 | Client data in free-tier chatbots | 4 | 5 | Ops | Open |
| R-02 | No approved-tool list | 4 | 4 | IT | In progress |
| R-03 | Untrained new hires | 4 | 4 | HR | Open |
| R-04 | Vendor data-retention unknown | 3 | 3 | Legal | Open |
| R-05 | No incident-response path | 3 | 4 | Ops | Open |
Get the full pre-built register
Guardrail's pre-built AI risk register ships with all 25 risks scored, owned, and mitigated, plus an auto-calculating dashboard — part of the full AI Policy OS. Skip the blank spreadsheet.
Skip the blank spreadsheet — get the 25-risk register
Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.
Get the AI Policy OS from S$129 →Frequently asked questions
What is an AI risk register?
A living document that lists the ways AI use could go wrong in your company, with a likelihood and impact score, an owner, a mitigation, and a status for each. It's how you show a board, client, or insurer that you're managing AI risk deliberately.
Who should own the AI risk register?
One named person — usually an Ops, IT, or COO lead — owns the register overall, with individual risks assigned to functional owners (HR, Legal, Eng). The point is specific accountability, not a department.
How many risks should it have?
Start with the 20–30 risks common to most SMBs (we ship 25 pre-built), then add any unique to your business and delete what doesn't apply. A pre-built register beats a blank spreadsheet you never fill in.