Skip to main content

Risk register

The Risk Register is the organisation-wide list of AI and governance risks — title, owner, severity, mitigation status, risk level, target date, and optional links to use cases and framework programs.

Open Risk & Assurance → Risk Register in the sidebar.

This is not the same as:

AreaWhat it is
This pageOrganisation-wide risks
Use case → Use case risksRisks for one AI use case
Frameworks → Framework risksRisks under the org program
Model registry → Model risksRisks logged against a model

What you see​

Severity overview chips: Total, Very high, High, Medium, Low (counts for the whole workspace, not only this page).

The table is list-only (no card grid). Search with Search risks… Admin and Editor see Add new risk. If your plan does not allow more records, you are asked to upgrade.

Columns: Risk name, owner, severity, mitigation status, risk level, target date, and a ⋯ menu (Edit / Delete risk).

Severity is calculated from likelihood and impact when you save. You do not pick severity as a separate field.


Add or edit a risk​

The form has three tabs:

Risks

  • Optional links to applicable projects (use cases) and applicable frameworks (your org program: ISO, NIST AI RMF, GDPR, and so on)
  • Risk name, owner, AI lifecycle phase
  • Description, category tags, potential impact
  • Likelihood and impact — the risk level updates automatically
  • Review notes

Mitigation

  • Mitigation status (not started, in review, in progress, mitigated, accepted)
  • Current risk level and deadline
  • Mitigation plan and implementation strategy
  • Residual likelihood / impact
  • Approver, approval status, assessment date, recommendations

Activity (edit only) — who created or updated the risk, and when.

Risk name and description are required. Delete asks you to confirm. This cannot be undone.


Who can do what​

ActionAdminEditorReviewerAuditor
View, search, open ActivityYesYesYesYes
Add, edit, deleteYesYesNoNo