Risk register
The Risk Register is the organisation-wide list of AI and governance risks — title, owner, severity, mitigation status, risk level, target date, and optional links to use cases and framework programs.
Open Risk & Assurance → Risk Register in the sidebar.
This is not the same as:
| Area | What it is |
|---|---|
| This page | Organisation-wide risks |
| Use case → Use case risks | Risks for one AI use case |
| Frameworks → Framework risks | Risks under the org program |
| Model registry → Model risks | Risks logged against a model |
What you see
Severity overview chips: Total, Very high, High, Medium, Low (counts for the whole workspace, not only this page).
The table is list-only (no card grid). Search with Search risks… Admin and Editor see Add new risk. If your plan does not allow more records, you are asked to upgrade.
Columns: Risk name, owner, severity, mitigation status, risk level, target date, and a ⋯ menu (Edit / Delete risk).
Severity is calculated from likelihood and impact when you save. You do not pick severity as a separate field.
Add or edit a risk
The form has three tabs:
Risks
- Optional links to applicable projects (use cases) and applicable frameworks (your org program: ISO, NIST AI RMF, GDPR, and so on)
- Risk name, owner, AI lifecycle phase
- Description, category tags, potential impact
- Likelihood and impact — the risk level updates automatically
- Review notes
Mitigation
- Mitigation status (not started, in review, in progress, mitigated, accepted)
- Current risk level and deadline
- Mitigation plan and implementation strategy
- Residual likelihood / impact
- Approver, approval status, assessment date, recommendations
Activity (edit only) — who created or updated the risk, and when.
Risk name and description are required. Delete asks you to confirm. This cannot be undone.
Who can do what
| Action | Admin | Editor | Reviewer | Auditor |
|---|---|---|---|---|
| View, search, open Activity | Yes | Yes | Yes | Yes |
| Add, edit, delete | Yes | Yes | No | No |