DoAIRight
ISO/IEC 42001

How to Build an AI Risk Register (With Examples)

PUBLISHED 06 AUG 2026

An AI risk register is a centralized tool used within an AI Management System (AIMS) to systematically record, analyze, prioritize, and monitor the risks associated with developing, deploying, or using artificial intelligence. Aligned with ISO/IEC 42001 (specifically Clause 6.1 and Annex A.5), a complete AI risk register goes beyond traditional IT risk tracking by evaluating technical failures alongside broad impacts on individuals, groups, and society. Paired with explicit risk treatment strategies and controls, this register ensures your organization maintains control over algorithmic risks across the entire AI lifecycle.

Why Traditional IT Risk Registers Fail for AI

Standard IT risk management typically focuses on confidentiality, integrity, and availability (CIA). While these remain relevant, AI applications introduce unique failure modes like model drift, training data bias, hallucination, autonomous decision-making errors, and lack of explainability.

Under ISO/IEC 42001 Clause 6.1, organizations must establish an AI risk assessment process that specifically accounts for these AI-native hazards. Furthermore, ISO/IEC 42001 Annex A.5 requires organizations to assess the impact of AI systems not just on internal operations, but on external stakeholders—including individual consumers, vulnerable groups, and broader society.

Key Columns Every AI Risk Register Must Include

To build a compliant and actionable AI risk register, structure your spreadsheet or management software with the following fields:

  • Risk ID & System Identifier: A unique code mapped to the specific AI system or application (e.g., SYS-01: Hiring Recommendation Engine).
  • Risk Scenario: A clear description of the threat, vulnerability, and potential failure mode.
  • Impacted Stakeholders: Specifies whether the impact affects individuals, specific groups, society, or the organization.
  • Inherent Risk Rating: The likelihood and severity of the risk before controls are applied.
  • Selected ISO 42001 Annex A Controls: Applicable controls from domains like A.5 (Impact Assessment), A.6 (AI Lifecycle), A.7 (Data for AI), or A.10 (Third-Party Relationships).
  • Risk Treatment Strategy: The decided action plan (Mitigate, Avoid, Transfer, or Accept).
  • Residual Risk Rating: The remaining risk level after applying treatment controls.
  • Risk Owner: The individual or role accountable for managing the risk.

Concrete AI Risk Examples and Treatment Strategies

Here are three practical AI risk examples showing how threats map to risk treatment plans under ISO/IEC 42001.

Example 1: Algorithmic Bias in Credit Scoring

  • Scenario: An automated credit assessment model systematically lowers credit limits for applicants from specific demographic backgrounds due to historical bias in the training data.
  • Impacted Parties: Individuals and protected demographic groups.
  • Annex A Controls: A.5 (Impacts Assessment), A.7 (Data for AI Systems).
  • Risk Treatment: Mitigate. Rebalance and re-sample training datasets, perform pre-deployment fairness audits, and implement a human-in-the-loop review for automated credit denials.

Example 2: LLM Hallucinations in Medical Customer Service

  • Scenario: A generative AI chatbot provides inaccurate medical advice or incorrect drug dosage instructions to users.
  • Impacted Parties: Individual consumers and public safety (Society).
  • Annex A Controls: A.6 (AI System Life Cycle), A.8 (Information for Interested Parties).
  • Risk Treatment: Avoid / Mitigate. Restrict model output using retrieval-augmented generation (RAG) tied strictly to approved medical databases, display mandatory disclaimers, and route clinical queries directly to human staff.

Example 3: Third-Party Data Leakage via Vendor APIs

  • Scenario: Proprietary customer data sent to a third-party LLM API is logged and used by the vendor to train public baseline models.
  • Impacted Parties: The organization and individual data subjects.
  • Annex A Controls: A.7 (Data for AI Systems), A.10 (Third-Party and Customer Relationships).
  • Risk Treatment: Mitigate. Negotiate enterprise zero-data-retention agreements, apply local anonymization before transmission, and audit third-party compliance.

Step-by-Step: How to Build Your Register

  1. Define Context and AI Asset Inventory: Map all internal, customer-facing, and third-party AI tools in scope (Clause 4).
  2. Identify Threats and Conduct Impact Assessments: Evaluate technical flaws alongside ethical impacts on people and society (Annex A.5).
  3. Score Inherent Risk: Rate probability and impact to prioritize high-risk AI deployments.
  4. Formulate Risk Treatment Plans: Select controls across ISO/IEC 42001 Annex A domains (A.2 through A.10) to reduce risk to acceptable levels.
  5. Assign Ownership and Monitor: Assign risk owners (Clause 5) and schedule regular reviews (Clause 8 & 9) to detect data drift and new regulatory requirements.

Preparing Your AI Risk Register for Certification

When you undergo formal ISO/IEC 42001 certification, independent human auditors from an accredited certification body (operating under ISO/IEC 42006) will thoroughly examine your risk register. They will check whether your risk treatment decisions are grounded in actual evidence and whether residual risks are systematically reviewed.

To verify if your AI risk register and broader management system are audit-ready, use DoAIRight's free AI Readiness Assessment. DoAIRight helps prepare your team for accredited certification body audits by validating your AIMS structure against every ISO/IEC 42001 requirement.

Frequently asked

What is the difference between an AI risk assessment and an AI risk register?

An AI risk assessment is the process of identifying, analyzing, and evaluating risks and impacts. An AI risk register is the continuous log where those findings, along with risk treatment plans, controls, and risk owners, are documented and tracked over time.

What are the standard risk treatment options under ISO 42001?

The four standard risk treatment strategies are Risk Mitigation (applying controls to reduce impact/likelihood), Risk Avoidance (discontinuing the high-risk AI activity), Risk Transfer (sharing risk via insurance or third-party contracts), and Risk Acceptance (formally accepting low-level residual risk).

How does ISO/IEC 42001 account for societal AI risks?

Unlike traditional security standards that focus strictly on business impact, ISO/IEC 42001 Annex A.5 explicitly requires organizations to assess and mitigate risks to individuals, marginalized groups, and society at large, such as bias, misinformation, and job displacement.

Does DoAIRight issue ISO/IEC 42001 certificates?

No. Formal certification is granted exclusively by accredited third-party certification bodies using independent human auditors under ISO/IEC 42006. DoAIRight provides tools and readiness assessments to help your organization become fully certification-ready.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score