Build it as one table: each AI use, what could go wrong, who would be affected, a likelihood and impact score from 1 to 3, the control in place, the extra action needed, an owner and a review date. Start with 8 to 12 rows in a 45-minute session, then review it every quarter and whenever you add a tool.
A register won't make anything safer on its own. What it does is make sure someone checks each risk on a date, instead of everyone assuming somebody else has. What follows is everything needed to start one this week: the columns and why each exists, a scoring scale, a template to copy into a spreadsheet, twelve starter rows from a florist, and a checklist for keeping it alive after the first meeting.
The columns, and why each one earns its place
| Column | What to write | Why it's there |
|---|---|---|
| ID | A number: R1, R2… | So people can refer to a row in a meeting or email |
| AI use | The tool and the job: "Website chatbot answering delivery questions" | Risks belong to uses, not to "AI" in general |
| What could go wrong | One realistic sentence | Forces a specific scenario rather than a vague worry |
| Who's affected | Customers, staff, the business, suppliers | Harm to customers usually deserves a higher impact score |
| Likelihood (1 to 3) | See the scale below | Separates frequent annoyances from rare disasters |
| Impact (1 to 3) | See the scale below | Same |
| Score | Likelihood multiplied by impact | Sorts the list so the top rows get attention first |
| Control in place | What already reduces the risk | Stops you inventing actions for risks you've already handled |
| Action needed | The next step, if any | Turns the register into a to-do list |
| Owner | One named person | A risk owned by "everyone" is owned by no one |
| Review date | When it's next looked at | The column that keeps the register alive |
| Status | Open, action in progress, accepted, closed | Shows progress between reviews |
A 1-to-3 scoring scale anyone can apply
Three levels are enough for a small business. Five-point scales invite long debates about whether something is a 3 or a 4, which is time better spent on the action column.
Likelihood
- 1, unlikely: you'd be surprised if it happened in the next year.
- 2, possible: it could plausibly happen this year.
- 3, likely: it has happened already, or will happen without action.
Impact
- 1, minor: an annoyance, fixed within a day, no customer affected.
- 2, moderate: a customer is let down, a refund or a day's work is lost, or a complaint is likely.
- 3, serious: personal data is exposed, someone could be harmed, significant money is lost, or it could reach a regulator or the local press.
What the score means: 6 or 9, act this month. 3 or 4, plan an action this quarter. 1 or 2, accept it, write down that you have, and look again at the next review.
The awkward case is a risk you can't score because you've never looked. At an illustrative dental practice, the row "reception staff paste patients' details into free AI tools to draft recall letters" gets a shrug: nobody knows whether it happens. Don't average the shrug to a 2. Score likelihood 3 until someone checks, and make the check itself the action: "Practice manager asks each receptionist which tools they use, and on which account, by Friday." If the answer is "only the practice's own Copilot", the row drops to 1 at the next review with the evidence noted beside it. If not, it's already at the top of the list, where it belongs.
An accepted risk needs as much writing down as an open one, or it looks like a row nobody got round to. A clear entry reads: "R12 accepted by the owner, 3 March. Price rises at renewal are likely but small; we can switch tools within a week if needed. Re-check at each renewal." Name who accepted it, why, and what would change the decision.
The template
Copy this into a spreadsheet, one column per heading. A shared spreadsheet beats a document because you can sort by score and filter by owner.
ID | AI use | What could go wrong | Who's affected | Likelihood (1-3) | Impact (1-3) | Score | Control in place | Action needed | Owner | Review date | Status
R1 | | | | | | =E*F | | | | | Open
R2 | | | | | | | | | | |
Put the date of the last full review at the top of the sheet. If it's more than four months old, the register has stopped working.
The column that most often goes wrong is "What could go wrong". Rows written in the language of AI headlines can't be scored or acted on. Three illustrative rewrites:
| As first written | Rewritten so someone can act on it |
|---|---|
| "Data leak" | The meeting-notes tool emails its summary of a client call, including fee figures, to everyone on the invite, including the client's outside adviser |
| "AI hallucination" | The AI-drafted quote adds a 10% loyalty discount that we don't offer, and the customer holds us to it |
| "Bias" | The CV-sorting prompt ranks applicants with career gaps lower, and we never interview them |
Each rewrite names the tool, the moment and the consequence, which is what you need to pick a control. "Data leak" can only be answered with worry.
The same problem appears if you ask an AI assistant to draft the register for you, which is a reasonable shortcut if you give it your own uses. A prompt such as "Here are the five ways we use AI in our florist's shop: [list]. For each, suggest two realistic things that could go wrong, one sentence each, naming the tool, the moment and who is affected" gets a usable first draft. Leave out the list and ask for "AI risks for a small business", and the reply (illustrative) is rows like "Model drift may degrade output quality over time" and "Algorithmic bias could lead to unfair outcomes". Neither names a tool or a moment, so neither can be scored. Rewrite them the way the table above does, or delete them; the assistant's second attempt with your real list will be better than any editing of the first.
Twelve starter rows from a florist
Here's how the register might look for an illustrative florist with a shop, a website, a small events team and a wedding business. Use it for ideas, not as a copy: your uses and scores will differ.
| ID | AI use and what could go wrong | L | I | Score | Action | Owner |
|---|---|---|---|---|---|---|
| R1 | AI-written care cards and product descriptions state that a plant or flower is safe for pets when it isn't (lilies are highly toxic to cats) | 2 | 3 | 6 | Rule: no pet-safety claims unless checked against a reliable source; add to the AI's instructions | Shop manager |
| R2 | Order-intake automation misreads a delivery date or address on a peak day | 2 | 3 | 6 | Person checks every automated order on peak days; customers get a confirmation to correct | Owner |
| R3 | Staff draft customer replies in personal AI accounts, so client details sit outside the business | 3 | 2 | 6 | Move to company accounts; one-line rule in the staff handbook | Owner |
| R4 | Email from a "wholesaler" with new bank details, written convincingly by AI | 2 | 3 | 6 | Call-back rule on a known number for any bank change | Bookkeeper |
| R5 | AI-drafted wedding proposal promises flowers that are out of season or quotes an old price | 2 | 2 | 4 | Current price list and seasonal list attached to the prompt; every proposal read before sending | Events coordinator |
| R6 | Website chatbot promises same-day delivery after the cut-off | 2 | 2 | 4 | Cut-off times in its instructions; weekly read of ten conversations | Shop manager |
| R7 | AI-drafted review reply strikes the wrong tone with a customer complaining about funeral flowers | 2 | 2 | 4 | Complaints and sympathy-related reviews always answered by a person | Owner |
| R8 | Shared password on the automation account that links the website, inbox and order sheet | 2 | 2 | 4 | Individual logins, two-factor authentication, password manager | Owner |
| R9 | AI assistant connected to the shared drive can surface staff records | 1 | 3 | 3 | Move staff records to a restricted folder before connecting | Owner |
| R10 | Deepfake call "from the owner" asking the shop to pay a new supplier urgently | 1 | 3 | 3 | Call-back rule; second approval for payments over a set amount | Owner |
| R11 | Chatbot doesn't tell customers they're talking to AI, and the shop delivers to customers in the EU | 1 | 2 | 2 | Add an opening line saying it's an AI assistant; accept and review | Shop manager |
| R12 | An AI tool raises its price or changes its data terms at renewal | 2 | 1 | 2 | Accept; check terms and price a month before each renewal | Bookkeeper |
Two things stand out. The highest-scoring rows aren't exotic AI failures: they're a wrong fact on a care card, a misread order and a fraudulent email. And several rows share a single fix (the call-back rule covers R4 and R10), which is normal. Peak days make R2 worse, so the florist reviews that row before Valentine's Day and Mother's Day each year; preparing for peak days with AI covers that run-up in detail. If you're unsure where the disclosure line in R11 applies, what to tell customers at the start of a chat has wording.
The same exercise lands differently in a business whose main risks fall on people rather than orders. For an illustrative ten-person temporary staffing agency, three of the top rows might be:
| ID | AI use and what could go wrong | L | I | Score | Action | Owner |
|---|---|---|---|---|---|---|
| R1 | AI-written candidate profile sent to a client includes the candidate's current pay, which they asked to keep private | 2 | 3 | 6 | Pay and personal circumstances removed from the notes the AI reads; consultant reads every profile before it's sent | Operations manager |
| R2 | Shortlisting prompt quietly favours applicants who resemble past placements | 2 | 3 | 6 | AI summarises against written criteria only; a person shortlists; monthly spot-check of rejected applicants | Director |
| R3 | Interview recordings from an AI note-taker kept on a consultant's personal free account | 3 | 2 | 6 | Note-taker on a business plan only; recordings deleted after 30 days | Operations manager |
Hiring is also named among the high-risk uses in the EU AI Act, with those obligations deferred to December 2027 for stand-alone systems. An agency with EU candidates or clients would add a row for that and put the question to a solicitor now, rather than in 2027.
Where to find the AI uses you don't know about
The first draft of any register misses things. Before the session, spend 20 minutes on this checklist.
- Card statements and expense claims. Search for AI tool names and small monthly charges you don't recognise.
- AI features in software you already use. Email marketing, accounting, website builders, booking systems and social schedulers have added AI features, sometimes switched on by default. Check each one's settings.
- Connected apps. Look at the third-party apps connected to each work Google or Microsoft account.
- Browser extensions on shared and work computers.
- Your automation platform. List every active workflow and note which ones contain an AI step.
- Your website. Any chat widget, form assistant or AI-written pages.
- Your team. Ask what they use and make clear that honest answers won't get anyone into trouble. Whether your team is using AI without telling you explains why people often don't mention it.
Running the first session in 45 minutes
Invite the owner, the one or two people who use AI most, and someone who deals with customers every day. Share the empty template beforehand.
- 10 minutes: list the uses. One row per tool-and-job pair, from the checklist above.
- 15 minutes: what could go wrong. For each use, ask "what's the worst realistic thing that could happen here?" Realistic, not apocalyptic. Security risks from the eleven most common AI security gaps are a useful prompt.
- 10 minutes: score. Go fast. If two people disagree by one point, take the higher score and move on.
- 10 minutes: actions, owners, dates. Start from the top score. Every row scoring 6 or 9 leaves the meeting with an owner and a date.
Keeping it alive: triggers and a quarterly check
Update the register whenever one of these happens, not just at the quarterly review:
- A new AI tool is bought or a new AI feature is switched on.
- Something goes wrong or nearly goes wrong. Near misses are free lessons; log them.
- A vendor changes its terms, data handling or price.
- Someone who owns a row leaves or changes role.
- AI starts doing something customer-facing or taking actions on its own.
- You start selling into a market with different rules.
Here's a near miss turned into an update. On 12 February the florist's chatbot tells a customer that orders placed by 6pm will arrive on Valentine's Day. The peak-day cut-off is noon. The customer phones to double-check, so nobody is let down, but the shop manager logs it that afternoon and changes R6:
R6 BEFORE Website chatbot promises same-day delivery after
the cut-off. L2 x I2 = 4. Control: cut-off times
in its instructions; weekly read of ten chats.
R6 AFTER Same risk, now seen on a peak day. L3 x I2 = 6.
Control: as before, PLUS peak-day cut-offs added
to the instructions 10 days before each peak;
daily read of chats from 10 February.
Owner: shop manager. Review: 1 May (after
Mother's Day). Status: action in progress.
Nothing went wrong, and the register still changed. That's the point of logging near misses: the fix costs ten minutes in February rather than refunds on the fourteenth.
Every quarter, spend 20 minutes: re-score each row, close the finished actions, check every owner still works for you and still knows they own it, and set the next review date. The note from the florist's spring review might be no longer than this:
REVIEW, 2 April Attended: owner, shop manager
R3 CLOSED. All five staff on company accounts; checked each one's
login on 28 March.
R8 Still open. Two-factor on 3 of 4 accounts; automation account
waiting for the new password manager. Owner. New date: 30 April.
R5 Owner changed: events coordinator left in March; now the owner.
R13 NEW. Booking system switched on AI "suggested replies" by default
in its March update. L2 x I2 = 4. Action: turn off until tested.
Next full review: 2 July
Four lines of change in twenty minutes is typical. The new R13 is the kind of row that only appears because someone asked, during the review, whether any software had changed since the last one. When something does go wrong, the register tells you who owns the response, and an AI incident response plan tells them what to do in the first hour.
What a register doesn't do
It doesn't replace your AI usage policy, your insurance or legal advice. It records the risks you know about and who's watching each one. For rules on what staff may and may not do with AI, writing an AI usage policy is the companion document.
If a larger client or partner asks how you manage AI risk, a maintained register with review dates is a credible answer for a small firm. Formal frameworks exist for bigger organisations: ISO/IEC 42001, the international standard for AI management systems, was published in December 2023. You don't need certification to keep a register, but if you're ever asked for more, the register is where that work starts. If you sell to customers in the EU, the EU AI Act's transparency duties for chatbots are worth a row of their own, as in R11; a solicitor or compliance adviser can tell you what else applies.
Questions about keeping an AI risk register
Can AI risks go in my existing risk register instead?
Yes, if you already keep one and actually review it. Add a column or tag marking the AI rows so you can filter them, and keep the same scoring scale across everything. A separate AI register makes sense only if you have no register at all, or if your existing one is a document nobody has opened since it was written.
How many rows is too many?
For a business under 20 people, more than about 25 rows usually means risks are being split too finely or copied from generic lists. Merge rows that share a cause and a control. A register you can read in five minutes gets reviewed; one that takes an hour gets skipped, and then it protects nobody.
Should staff be able to see the register?
Yes, at least the people named as owners and anyone who uses the tools listed. Seeing the risks explains why the rules exist, which makes them easier to follow. If a row describes a security weakness you haven't fixed yet, such as a shared password, keep the detail brief until it's closed.
Further reads
- AI Governance for a Small Business: Who Decides, Approves, Checks — Who decides, approves and checks AI use in a small firm.
- AI Compliance Checklist for Small Businesses: What Applies to You — Which rules actually apply to your AI use.
- How to Run a Pre-Mortem Before You Launch an AI Project — Find risks in a new project before launch, not after.
- AI Error Log: Track Mistakes and Stop Them Happening Again — Log the mistakes that feed new rows into the register.
- AI Tool Approval Process: How Staff Request a New AI Tool — A request process that adds each new tool to the register.
- Does Cyber Insurance Cover AI Incidents? What Insurers Ask — What insurers ask about AI, and how the register helps.
- How to Pilot AI in Shadow Mode Before Customers See It — How to run AI in parallel with your team, log and grade what it would have done, and decide from real numbers when it's safe to let customers see it.
- AI Ethics for Small Businesses: A Practical Checklist — Twenty-five questions in six groups, each with why it matters and how to check, plus red lines and a nursery example run end to end.
- AI Use Case Template: Score Every Idea on One Page — A one-page template with scoring anchors, knock-out questions and a worked veterinary example for ranking AI ideas before you spend anything.
- What Are the Risks of Using AI in My Small Business? — Eight risks of using AI in a small business, a four-factor score for your own exposure, three example risk profiles, and the cheapest control for each risk.
- Does a Five-Person Business Really Need an AI Policy? — Why a five-person business needs a one-page AI policy rather than a handbook: six triggers, a complete template, and when one page stops being enough.
- Does Your Business Insurance Cover AI Mistakes? — Match each kind of AI mistake to the policy that would respond, spot the new AI exclusions at renewal, and send your broker five precise questions.
- How Advisers Use AI to Prepare for Annual Client Reviews — A four-week countdown for review prep with AI: what it drafts, what the adviser checks, and the prompts that keep figures and advice in human hands.
- AI Governance Checklist for Small Financial Advice Firms — Eight groups of checks, each with the evidence to keep, so a small advice firm can show how AI is approved, supervised and recorded.
- AI CV Screening for Recruitment Agencies: Setup and Safeguards — Five set-up steps and the safeguards to have in place before an agency lets AI score CVs, with a rubric, prompt, sample output and back-test.
- How Property Managers Use AI to Screen Tenant Applications Fairly — Written criteria, one summary format for every applicant, human decisions with recorded reasons, and a monthly check that your rules aren't quietly unfair.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act transparency provisions and the Digital Omnibus on AI; ISO/IEC 42001:2023 (checked September 2026).