Set policy, accountability, roles, and oversight across every AI use.
Free AI risk assessment template
AI risk register
Prioritize AI risks and assign the next action.
Live risk register
Score, assign, control, review.
The 25 sample risks are complete enough to use. Replace the owners, controls, actions, and scores with your own; everything recalculates in this browser.
Your first decision
8 high risks need a named decision. Start with R-01: customer or employee data is pasted into an unapproved ai tool.
Download the editable workbook and implementation pack.
Get the formula-driven Excel workbook, Google Sheets import path, 25 sample risks, heat map, review cadence, NIST map, and safe generator prompt. Your browser edits are not uploaded.
- Workbook with your current risk register
- Live heatmap and review dates
- Review cadence and source map
Preview the result or example included in this kit
8 high risks need a named decision. Start with R-01: customer or employee data is pasted into an unapproved ai tool.
Live 3 × 3 heat map
Exposure by likelihood and impact
1 risk owner still unassigned.
| Impact ↓ / Likelihood → | 1 · Unlikely | 2 · Plausible | 3 · Expected |
|---|---|---|---|
| 3 · Major | 5Medium | 4High | 3High |
| 2 · Material | 5Low | 7Medium | 1High |
| 1 · Limited | 0Low | 0Low | 0Medium |
| Risk | Score | Level | NIST function | Likelihood | Impact | Owner | Current control | Next action | Next review | Status |
|---|---|---|---|---|---|---|---|---|---|---|
| R-01 · Data & privacyCustomer or employee data is pasted into an unapproved AI tool | 9 | High | GOVERN | |||||||
| R-06 · Accuracy & customer trustAI invents a customer quote, price, policy, or factual claim | 9 | High | MEASURE | |||||||
| R-11 · Security & accessExternal text or files manipulate the agent through prompt injection | 9 | High | MEASURE | |||||||
| R-16 · Operations & continuityA scheduled agent loops, retries, or calls tools until spend runs away | 6 | High | MANAGE | |||||||
| R-21 · Governance & peopleAI use has no named business owner or decision authority | 6 | High | GOVERN | |||||||
| R-03 · Data & privacyAn AI connector can reach more files or records than the workflow needs | 6 | High | MANAGE | |||||||
| R-22 · Governance & peopleTeams deploy AI without acceptance tests or a known failure set | 6 | High | MEASURE | |||||||
| R-02 · Data & privacySensitive prompts or outputs remain in unmanaged chat history | 6 | High | MAP | |||||||
| R-18 · Operations & continuityFollow-up automation continues after a reply, opt-out, or resolved case | 4 | Medium | MANAGE | |||||||
| R-17 · Operations & continuityAn AI workflow fails silently and work disappears from the queue | 4 | Medium | MEASURE | |||||||
| R-08 · Accuracy & customer trustThe assistant answers from stale policies, prices, or operating documents | 4 | Medium | MEASURE | |||||||
| R-20 · Operations & continuityA model or API version change breaks quality, cost, or output structure | 4 | Medium | MEASURE | |||||||
| R-25 · Governance & peopleMaterial AI decisions and approvals are not logged | 4 | Medium | GOVERN | |||||||
| R-15 · Security & accessShared AI accounts prevent reliable access removal and audit history | 4 | Medium | GOVERN | |||||||
| R-19 · Operations & continuityA vendor outage or account suspension stops a critical workflow | 4 | Medium | MAP | |||||||
| R-07 · Accuracy & customer trustCustomer-facing output is sent without the required human approval | 3 | Medium | MANAGE | |||||||
| R-13 · Security & accessAn agent can approve payments, delete data, or contact people beyond scope | 3 | Medium | MANAGE | |||||||
| R-23 · Governance & peopleThe company cannot pause, roll back, or investigate an AI incident | 3 | Medium | MANAGE | |||||||
| R-09 · Accuracy & customer trustAI-assisted decisions treat customers or employees inconsistently | 3 | Medium | MEASURE | |||||||
| R-12 · Security & accessCredentials, tokens, or secrets appear in prompts, logs, or exports | 3 | Medium | MANAGE | |||||||
| R-14 · Security & accessA malicious attachment or link triggers an unsafe downstream action | 2 | Low | MEASURE | |||||||
| R-04 · Data & privacyAI vendor training or data-use terms are not reviewed | 2 | Low | GOVERN | |||||||
| R-10 · Accuracy & customer trustGenerated content creates an accessibility or language barrier | 2 | Low | MEASURE | |||||||
| R-05 · Data & privacyAI-generated records omit required retention or deletion handling | 2 | Low | MAP | |||||||
| R-24 · Governance & peopleGenerated content reuses protected material or creates unclear ownership | 2 | Low | MAP |
NIST AI RMF map
Four functions, used as organizing labels.
Reviewed 2026-08-30
Document the use, people, data, context, benefits, and possible harms.
Test, track, and document whether the system and its controls work.
Prioritize, treat, monitor, and retire risks with named decisions.
NIST describes the AI RMF as voluntary and is revising AI RMF 1.0. The mapping here is a Nerd Out crosswalk for review conversations; it does not show compliance or that a control is effective.
Source ledger and freshness owner
Owner: Nerd Out AI risk reviewer. Recheck before publication, when NIST releases a revision, and at least semiannually.
- NIST AI Risk Management Framework 1.0Voluntary, non-sector-specific framework; source for the Govern, Map, Measure, and Manage functions.
- NIST AI RMF PlaybookVoluntary companion suggestions. NIST says the playbook is not a checklist and will change after the AI RMF revision.
- NIST AI 600-1 Generative AI ProfileCross-sector companion profile used to review the generative-AI examples in this SMB register.
Review cadence
Fifteen minutes monthly. Re-score quarterly.
- Review high risks, overdue actions, incidents, and new AI uses.
- Confirm the owner, control evidence, next action, and next review.
- Quarterly, re-score every row and retire controls that no longer work.
How this tool works
Twenty-five practical AI risks in. A live 3 × 3 heat map, named owners, next actions, review dates, and a one-hour first register out.
- Review the 25 preloaded SMB AI risks.
- Edit scores, owners, controls, actions, and dates.
- Get the workbook, prompt, cadence, and NIST map.
The useful distinction
A risk list names fears. A risk register names the next decision.
Start with plausible operating failures: sensitive data in prompts, invented facts, excessive access, silent workflow errors, runaway spend, and missing approvals. Score likelihood and impact on a simple three-level scale, then assign one owner, one current control, and one next action.
The NIST AI RMF labels help organize the conversation across Govern, Map, Measure, and Manage. NIST describes the framework as voluntary, and this template is a Nerd Out operating crosswalk, not a certification, legal opinion, insurer requirement, or proof that a control works.
Questions owners ask
AI risk assessment and register FAQ
What is an AI risk register?
An AI risk register is a working list of AI-related failure scenarios with likelihood, impact, owner, current control, next action, status, and review date. It is useful only when the team updates it after incidents, workflow changes, new tools, and control tests.
How do you score AI risk in this template?
Multiply likelihood from 1 to 3 by impact from 1 to 3. Scores of 6 to 9 are high, 3 to 4 medium, and 1 to 2 low. That scale is a transparent Nerd Out prioritization heuristic; it is not a NIST score or compliance determination.
How often should a small business review its AI risk register?
Use a short monthly review for high risks, incidents, new AI uses, overdue actions, and ownership changes. Re-score every row quarterly, and review immediately after a material vendor, model, workflow, legal, security, or customer-impact change.
Does this template make a company NIST AI RMF compliant?
No. NIST describes the AI RMF as voluntary and flexible. This template maps each row to a primary Govern, Map, Measure, or Manage function to support discussion; it does not test every framework outcome, prove control effectiveness, or replace qualified legal, privacy, security, insurance, or industry advice.
Can I use the workbook in Google Sheets?
Yes. Download the Excel workbook, upload it to Google Drive, open it with Google Sheets, and save it as a native Google Sheets file. The formulas, validations, heat map, source ledger, prompt, and review cadence travel with the workbook.