AI systems & governance

Free AI risk assessment template

AI risk register

Prioritize AI risks and assign the next action.

Start the toolEstimated: 10 minutes
02

Live risk register

Score, assign, control, review.

The 25 sample risks are complete enough to use. Replace the owners, controls, actions, and scores with your own; everything recalculates in this browser.

Your first decision

8 high risks need a named decision. Start with R-01: customer or employee data is pasted into an unapproved ai tool.

Free resourceKeep the working register

Download the editable workbook and implementation pack.

Get the formula-driven Excel workbook, Google Sheets import path, 25 sample risks, heat map, review cadence, NIST map, and safe generator prompt. Your browser edits are not uploaded.

  • Workbook with your current risk register
  • Live heatmap and review dates
  • Review cadence and source map
Preview the result or example included in this kit
8 high risks need a named decision. Start with R-01: customer or employee data is pasted into an unapproved ai tool.

You'll also receive practical Nerd Out notes. Unsubscribe anytime. We never sell your email.

Live 3 × 3 heat map

Exposure by likelihood and impact

1 risk owner still unassigned.

Counts of register rows by impact and likelihood. Every cell names its risk level; color is supplemental.
Impact ↓ / Likelihood →1 · Unlikely2 · Plausible3 · Expected
3 · Major5Medium4High3High
2 · Material5Low7Medium1High
1 · Limited0Low0Low0Medium
25 of 25 risks shown. Edit the blue fields; scores and the heat map update in this browser.
RiskScoreLevelNIST functionLikelihoodImpactOwnerCurrent controlNext actionNext reviewStatus
R-01 · Data & privacyCustomer or employee data is pasted into an unapproved AI tool9HighGOVERN
R-06 · Accuracy & customer trustAI invents a customer quote, price, policy, or factual claim9HighMEASURE
R-11 · Security & accessExternal text or files manipulate the agent through prompt injection9HighMEASURE
R-16 · Operations & continuityA scheduled agent loops, retries, or calls tools until spend runs away6HighMANAGE
R-21 · Governance & peopleAI use has no named business owner or decision authority6HighGOVERN
R-03 · Data & privacyAn AI connector can reach more files or records than the workflow needs6HighMANAGE
R-22 · Governance & peopleTeams deploy AI without acceptance tests or a known failure set6HighMEASURE
R-02 · Data & privacySensitive prompts or outputs remain in unmanaged chat history6HighMAP
R-18 · Operations & continuityFollow-up automation continues after a reply, opt-out, or resolved case4MediumMANAGE
R-17 · Operations & continuityAn AI workflow fails silently and work disappears from the queue4MediumMEASURE
R-08 · Accuracy & customer trustThe assistant answers from stale policies, prices, or operating documents4MediumMEASURE
R-20 · Operations & continuityA model or API version change breaks quality, cost, or output structure4MediumMEASURE
R-25 · Governance & peopleMaterial AI decisions and approvals are not logged4MediumGOVERN
R-15 · Security & accessShared AI accounts prevent reliable access removal and audit history4MediumGOVERN
R-19 · Operations & continuityA vendor outage or account suspension stops a critical workflow4MediumMAP
R-07 · Accuracy & customer trustCustomer-facing output is sent without the required human approval3MediumMANAGE
R-13 · Security & accessAn agent can approve payments, delete data, or contact people beyond scope3MediumMANAGE
R-23 · Governance & peopleThe company cannot pause, roll back, or investigate an AI incident3MediumMANAGE
R-09 · Accuracy & customer trustAI-assisted decisions treat customers or employees inconsistently3MediumMEASURE
R-12 · Security & accessCredentials, tokens, or secrets appear in prompts, logs, or exports3MediumMANAGE
R-14 · Security & accessA malicious attachment or link triggers an unsafe downstream action2LowMEASURE
R-04 · Data & privacyAI vendor training or data-use terms are not reviewed2LowGOVERN
R-10 · Accuracy & customer trustGenerated content creates an accessibility or language barrier2LowMEASURE
R-05 · Data & privacyAI-generated records omit required retention or deletion handling2LowMAP
R-24 · Governance & peopleGenerated content reuses protected material or creates unclear ownership2LowMAP

NIST AI RMF map

Four functions, used as organizing labels.

Reviewed 2026-08-30

GOVERN5 rows

Set policy, accountability, roles, and oversight across every AI use.

MAP4 rows

Document the use, people, data, context, benefits, and possible harms.

MEASURE9 rows

Test, track, and document whether the system and its controls work.

MANAGE7 rows

Prioritize, treat, monitor, and retire risks with named decisions.

NIST describes the AI RMF as voluntary and is revising AI RMF 1.0. The mapping here is a Nerd Out crosswalk for review conversations; it does not show compliance or that a control is effective.

Source ledger and freshness owner

Owner: Nerd Out AI risk reviewer. Recheck before publication, when NIST releases a revision, and at least semiannually.

Review cadence

Fifteen minutes monthly. Re-score quarterly.

  1. Review high risks, overdue actions, incidents, and new AI uses.
  2. Confirm the owner, control evidence, next action, and next review.
  3. Quarterly, re-score every row and retire controls that no longer work.
How this tool works

Twenty-five practical AI risks in. A live 3 × 3 heat map, named owners, next actions, review dates, and a one-hour first register out.

  1. Review the 25 preloaded SMB AI risks.
  2. Edit scores, owners, controls, actions, and dates.
  3. Get the workbook, prompt, cadence, and NIST map.

The useful distinction

A risk list names fears. A risk register names the next decision.

Start with plausible operating failures: sensitive data in prompts, invented facts, excessive access, silent workflow errors, runaway spend, and missing approvals. Score likelihood and impact on a simple three-level scale, then assign one owner, one current control, and one next action.

The NIST AI RMF labels help organize the conversation across Govern, Map, Measure, and Manage. NIST describes the framework as voluntary, and this template is a Nerd Out operating crosswalk, not a certification, legal opinion, insurer requirement, or proof that a control works.

Questions owners ask

AI risk assessment and register FAQ

What is an AI risk register?

An AI risk register is a working list of AI-related failure scenarios with likelihood, impact, owner, current control, next action, status, and review date. It is useful only when the team updates it after incidents, workflow changes, new tools, and control tests.

How do you score AI risk in this template?

Multiply likelihood from 1 to 3 by impact from 1 to 3. Scores of 6 to 9 are high, 3 to 4 medium, and 1 to 2 low. That scale is a transparent Nerd Out prioritization heuristic; it is not a NIST score or compliance determination.

How often should a small business review its AI risk register?

Use a short monthly review for high risks, incidents, new AI uses, overdue actions, and ownership changes. Re-score every row quarterly, and review immediately after a material vendor, model, workflow, legal, security, or customer-impact change.

Does this template make a company NIST AI RMF compliant?

No. NIST describes the AI RMF as voluntary and flexible. This template maps each row to a primary Govern, Map, Measure, or Manage function to support discussion; it does not test every framework outcome, prove control effectiveness, or replace qualified legal, privacy, security, insurance, or industry advice.

Can I use the workbook in Google Sheets?

Yes. Download the Excel workbook, upload it to Google Drive, open it with Google Sheets, and save it as a native Google Sheets file. The formulas, validations, heat map, source ledger, prompt, and review cadence travel with the workbook.