HomeBlog › AI Risk Register Template: 25 Pre-Built Risks for Your Company
Guide

AI Risk Register Template: 25 Pre-Built Risks for Your Company

Last updated: June 2026 · Guardrail Studio

A blank risk-register spreadsheet is where good intentions go to die. Here's what an AI risk register should track, the 25 risks most SMBs face, and a free starter you can copy today.

What is an AI risk register?

An AI risk register is a structured list of the ways your use of AI could cause harm — a data leak, a compliance breach, a hallucinated deliverable — each with an owner, a mitigation, and a current status. It turns vague worry into a managed program, and it's the single artifact boards, insurers, and enterprise clients ask for when they want proof you take AI risk seriously.

What your AI risk register should track

Six columns do the job:

The 25 most common AI risks for SMBs

These are the risks we see again and again — a strong starting set for any small or mid-size company:

  1. Confidential or client data entered into free-tier AI tools
  2. Personal data processed by AI without a lawful basis
  3. Shadow AI — staff using unapproved tools
  4. Staff untrained on safe AI use
  5. Over-reliance on unverified AI output
  6. Source code or IP leaked into external models
  7. AI vendor trains on your submitted inputs
  8. Vendor data residency / sub-processors unknown
  9. No incident-response path for AI leaks
  10. Copyright infringement in AI-generated output
  11. Biased or discriminatory AI decisions
  12. Client contract prohibits the AI use
  13. Hallucinated facts in client deliverables
  14. Prompt injection / data exfiltration
  15. Credentials or secrets pasted into AI tools
  16. Customers misled by undisclosed AI use
  17. Non-compliance with AI regulation (EU AI Act, PDPA)
  18. No audit trail of AI use
  19. Insecure AI browser extensions / plugins
  20. Cyber-insurance AI exclusion leaves a loss uncovered
  21. Deepfake / AI social engineering of staff
  22. High-stakes decision made on AI output with no review
  23. Contractor or third-party misuse of AI on your data
  24. Data retained in an AI tool beyond your policy
  25. Process dependency / skill loss from one AI tool

Free starter risk register

IDRiskLikelihoodImpactOwnerStatus
R-01Client data in free-tier chatbots45OpsOpen
R-02No approved-tool list44ITIn progress
R-03Untrained new hires44HROpen
R-04Vendor data-retention unknown33LegalOpen
R-05No incident-response path34OpsOpen

Get the full pre-built register

Guardrail's pre-built AI risk register ships with all 25 risks scored, owned, and mitigated, plus an auto-calculating dashboard — part of the full AI Policy OS. Skip the blank spreadsheet.

Skip the blank spreadsheet — get the 25-risk register

Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.

Get the AI Policy OS from S$129 →

Frequently asked questions

What is an AI risk register?

A living document that lists the ways AI use could go wrong in your company, with a likelihood and impact score, an owner, a mitigation, and a status for each. It's how you show a board, client, or insurer that you're managing AI risk deliberately.

Who should own the AI risk register?

One named person — usually an Ops, IT, or COO lead — owns the register overall, with individual risks assigned to functional owners (HR, Legal, Eng). The point is specific accountability, not a department.

How many risks should it have?

Start with the 20–30 risks common to most SMBs (we ship 25 pre-built), then add any unique to your business and delete what doesn't apply. A pre-built register beats a blank spreadsheet you never fill in.