A Simple AI Risk Register for Small Businesses (With Template)

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for A Simple AI Risk Register for Small Businesses (With Template).
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for A Simple AI Risk Register for Small Businesses (With Template).

Build it as one table: each AI use, what could go wrong, who would be affected, a likelihood and impact score from 1 to 3, the control in place, the extra action needed, an owner and a review date. Start with 8 to 12 rows in a 45-minute session, then review it every quarter and whenever you add a tool.

A register won't make anything safer on its own. What it does is make sure someone checks each risk on a date, instead of everyone assuming somebody else has. What follows is everything needed to start one this week: the columns and why each exists, a scoring scale, a template to copy into a spreadsheet, twelve starter rows from a florist, and a checklist for keeping it alive after the first meeting.

Follow me on Instagram@sagnikteaches

The columns, and why each one earns its place

ColumnWhat to writeWhy it's there
IDA number: R1, R2…So people can refer to a row in a meeting or email
AI useThe tool and the job: "Website chatbot answering delivery questions"Risks belong to uses, not to "AI" in general
What could go wrongOne realistic sentenceForces a specific scenario rather than a vague worry
Who's affectedCustomers, staff, the business, suppliersHarm to customers usually deserves a higher impact score
Likelihood (1 to 3)See the scale belowSeparates frequent annoyances from rare disasters
Impact (1 to 3)See the scale belowSame
ScoreLikelihood multiplied by impactSorts the list so the top rows get attention first
Control in placeWhat already reduces the riskStops you inventing actions for risks you've already handled
Action neededThe next step, if anyTurns the register into a to-do list
OwnerOne named personA risk owned by "everyone" is owned by no one
Review dateWhen it's next looked atThe column that keeps the register alive
StatusOpen, action in progress, accepted, closedShows progress between reviews

A 1-to-3 scoring scale anyone can apply

Three levels are enough for a small business. Five-point scales invite long debates about whether something is a 3 or a 4, which is time better spent on the action column.

Connect on LinkedInSagnik Bhattacharya

Likelihood

Subscribe on YouTube@codingliquids
  • 1, unlikely: you'd be surprised if it happened in the next year.
  • 2, possible: it could plausibly happen this year.
  • 3, likely: it has happened already, or will happen without action.

Impact

  • 1, minor: an annoyance, fixed within a day, no customer affected.
  • 2, moderate: a customer is let down, a refund or a day's work is lost, or a complaint is likely.
  • 3, serious: personal data is exposed, someone could be harmed, significant money is lost, or it could reach a regulator or the local press.

What the score means: 6 or 9, act this month. 3 or 4, plan an action this quarter. 1 or 2, accept it, write down that you have, and look again at the next review.

The awkward case is a risk you can't score because you've never looked. At an illustrative dental practice, the row "reception staff paste patients' details into free AI tools to draft recall letters" gets a shrug: nobody knows whether it happens. Don't average the shrug to a 2. Score likelihood 3 until someone checks, and make the check itself the action: "Practice manager asks each receptionist which tools they use, and on which account, by Friday." If the answer is "only the practice's own Copilot", the row drops to 1 at the next review with the evidence noted beside it. If not, it's already at the top of the list, where it belongs.

An accepted risk needs as much writing down as an open one, or it looks like a row nobody got round to. A clear entry reads: "R12 accepted by the owner, 3 March. Price rises at renewal are likely but small; we can switch tools within a week if needed. Re-check at each renewal." Name who accepted it, why, and what would change the decision.

The template

Copy this into a spreadsheet, one column per heading. A shared spreadsheet beats a document because you can sort by score and filter by owner.

ID | AI use | What could go wrong | Who's affected | Likelihood (1-3) | Impact (1-3) | Score | Control in place | Action needed | Owner | Review date | Status
R1 |        |                     |                |                  |              | =E*F  |                  |               |       |             | Open
R2 |        |                     |                |                  |              |       |                  |               |       |             |

Put the date of the last full review at the top of the sheet. If it's more than four months old, the register has stopped working.

The column that most often goes wrong is "What could go wrong". Rows written in the language of AI headlines can't be scored or acted on. Three illustrative rewrites:

As first writtenRewritten so someone can act on it
"Data leak"The meeting-notes tool emails its summary of a client call, including fee figures, to everyone on the invite, including the client's outside adviser
"AI hallucination"The AI-drafted quote adds a 10% loyalty discount that we don't offer, and the customer holds us to it
"Bias"The CV-sorting prompt ranks applicants with career gaps lower, and we never interview them

Each rewrite names the tool, the moment and the consequence, which is what you need to pick a control. "Data leak" can only be answered with worry.

The same problem appears if you ask an AI assistant to draft the register for you, which is a reasonable shortcut if you give it your own uses. A prompt such as "Here are the five ways we use AI in our florist's shop: [list]. For each, suggest two realistic things that could go wrong, one sentence each, naming the tool, the moment and who is affected" gets a usable first draft. Leave out the list and ask for "AI risks for a small business", and the reply (illustrative) is rows like "Model drift may degrade output quality over time" and "Algorithmic bias could lead to unfair outcomes". Neither names a tool or a moment, so neither can be scored. Rewrite them the way the table above does, or delete them; the assistant's second attempt with your real list will be better than any editing of the first.

Twelve starter rows from a florist

Here's how the register might look for an illustrative florist with a shop, a website, a small events team and a wedding business. Use it for ideas, not as a copy: your uses and scores will differ.

IDAI use and what could go wrongLIScoreActionOwner
R1AI-written care cards and product descriptions state that a plant or flower is safe for pets when it isn't (lilies are highly toxic to cats)236Rule: no pet-safety claims unless checked against a reliable source; add to the AI's instructionsShop manager
R2Order-intake automation misreads a delivery date or address on a peak day236Person checks every automated order on peak days; customers get a confirmation to correctOwner
R3Staff draft customer replies in personal AI accounts, so client details sit outside the business326Move to company accounts; one-line rule in the staff handbookOwner
R4Email from a "wholesaler" with new bank details, written convincingly by AI236Call-back rule on a known number for any bank changeBookkeeper
R5AI-drafted wedding proposal promises flowers that are out of season or quotes an old price224Current price list and seasonal list attached to the prompt; every proposal read before sendingEvents coordinator
R6Website chatbot promises same-day delivery after the cut-off224Cut-off times in its instructions; weekly read of ten conversationsShop manager
R7AI-drafted review reply strikes the wrong tone with a customer complaining about funeral flowers224Complaints and sympathy-related reviews always answered by a personOwner
R8Shared password on the automation account that links the website, inbox and order sheet224Individual logins, two-factor authentication, password managerOwner
R9AI assistant connected to the shared drive can surface staff records133Move staff records to a restricted folder before connectingOwner
R10Deepfake call "from the owner" asking the shop to pay a new supplier urgently133Call-back rule; second approval for payments over a set amountOwner
R11Chatbot doesn't tell customers they're talking to AI, and the shop delivers to customers in the EU122Add an opening line saying it's an AI assistant; accept and reviewShop manager
R12An AI tool raises its price or changes its data terms at renewal212Accept; check terms and price a month before each renewalBookkeeper

Two things stand out. The highest-scoring rows aren't exotic AI failures: they're a wrong fact on a care card, a misread order and a fraudulent email. And several rows share a single fix (the call-back rule covers R4 and R10), which is normal. Peak days make R2 worse, so the florist reviews that row before Valentine's Day and Mother's Day each year; preparing for peak days with AI covers that run-up in detail. If you're unsure where the disclosure line in R11 applies, what to tell customers at the start of a chat has wording.

The same exercise lands differently in a business whose main risks fall on people rather than orders. For an illustrative ten-person temporary staffing agency, three of the top rows might be:

IDAI use and what could go wrongLIScoreActionOwner
R1AI-written candidate profile sent to a client includes the candidate's current pay, which they asked to keep private236Pay and personal circumstances removed from the notes the AI reads; consultant reads every profile before it's sentOperations manager
R2Shortlisting prompt quietly favours applicants who resemble past placements236AI summarises against written criteria only; a person shortlists; monthly spot-check of rejected applicantsDirector
R3Interview recordings from an AI note-taker kept on a consultant's personal free account326Note-taker on a business plan only; recordings deleted after 30 daysOperations manager

Hiring is also named among the high-risk uses in the EU AI Act, with those obligations deferred to December 2027 for stand-alone systems. An agency with EU candidates or clients would add a row for that and put the question to a solicitor now, rather than in 2027.

Where to find the AI uses you don't know about

The first draft of any register misses things. Before the session, spend 20 minutes on this checklist.

  • Card statements and expense claims. Search for AI tool names and small monthly charges you don't recognise.
  • AI features in software you already use. Email marketing, accounting, website builders, booking systems and social schedulers have added AI features, sometimes switched on by default. Check each one's settings.
  • Connected apps. Look at the third-party apps connected to each work Google or Microsoft account.
  • Browser extensions on shared and work computers.
  • Your automation platform. List every active workflow and note which ones contain an AI step.
  • Your website. Any chat widget, form assistant or AI-written pages.
  • Your team. Ask what they use and make clear that honest answers won't get anyone into trouble. Whether your team is using AI without telling you explains why people often don't mention it.

Running the first session in 45 minutes

Invite the owner, the one or two people who use AI most, and someone who deals with customers every day. Share the empty template beforehand.

  1. 10 minutes: list the uses. One row per tool-and-job pair, from the checklist above.
  2. 15 minutes: what could go wrong. For each use, ask "what's the worst realistic thing that could happen here?" Realistic, not apocalyptic. Security risks from the eleven most common AI security gaps are a useful prompt.
  3. 10 minutes: score. Go fast. If two people disagree by one point, take the higher score and move on.
  4. 10 minutes: actions, owners, dates. Start from the top score. Every row scoring 6 or 9 leaves the meeting with an owner and a date.

Keeping it alive: triggers and a quarterly check

Update the register whenever one of these happens, not just at the quarterly review:

  • A new AI tool is bought or a new AI feature is switched on.
  • Something goes wrong or nearly goes wrong. Near misses are free lessons; log them.
  • A vendor changes its terms, data handling or price.
  • Someone who owns a row leaves or changes role.
  • AI starts doing something customer-facing or taking actions on its own.
  • You start selling into a market with different rules.

Here's a near miss turned into an update. On 12 February the florist's chatbot tells a customer that orders placed by 6pm will arrive on Valentine's Day. The peak-day cut-off is noon. The customer phones to double-check, so nobody is let down, but the shop manager logs it that afternoon and changes R6:

R6 BEFORE   Website chatbot promises same-day delivery after
            the cut-off.  L2 x I2 = 4.  Control: cut-off times
            in its instructions; weekly read of ten chats.

R6 AFTER    Same risk, now seen on a peak day.  L3 x I2 = 6.
            Control: as before, PLUS peak-day cut-offs added
            to the instructions 10 days before each peak;
            daily read of chats from 10 February.
            Owner: shop manager.  Review: 1 May (after
            Mother's Day).  Status: action in progress.

Nothing went wrong, and the register still changed. That's the point of logging near misses: the fix costs ten minutes in February rather than refunds on the fourteenth.

Every quarter, spend 20 minutes: re-score each row, close the finished actions, check every owner still works for you and still knows they own it, and set the next review date. The note from the florist's spring review might be no longer than this:

REVIEW, 2 April                          Attended: owner, shop manager
R3  CLOSED. All five staff on company accounts; checked each one's
    login on 28 March.
R8  Still open. Two-factor on 3 of 4 accounts; automation account
    waiting for the new password manager. Owner. New date: 30 April.
R5  Owner changed: events coordinator left in March; now the owner.
R13 NEW. Booking system switched on AI "suggested replies" by default
    in its March update. L2 x I2 = 4. Action: turn off until tested.
Next full review: 2 July

Four lines of change in twenty minutes is typical. The new R13 is the kind of row that only appears because someone asked, during the review, whether any software had changed since the last one. When something does go wrong, the register tells you who owns the response, and an AI incident response plan tells them what to do in the first hour.

What a register doesn't do

It doesn't replace your AI usage policy, your insurance or legal advice. It records the risks you know about and who's watching each one. For rules on what staff may and may not do with AI, writing an AI usage policy is the companion document.

If a larger client or partner asks how you manage AI risk, a maintained register with review dates is a credible answer for a small firm. Formal frameworks exist for bigger organisations: ISO/IEC 42001, the international standard for AI management systems, was published in December 2023. You don't need certification to keep a register, but if you're ever asked for more, the register is where that work starts. If you sell to customers in the EU, the EU AI Act's transparency duties for chatbots are worth a row of their own, as in R11; a solicitor or compliance adviser can tell you what else applies.

Questions about keeping an AI risk register

Can AI risks go in my existing risk register instead?

Yes, if you already keep one and actually review it. Add a column or tag marking the AI rows so you can filter them, and keep the same scoring scale across everything. A separate AI register makes sense only if you have no register at all, or if your existing one is a document nobody has opened since it was written.

How many rows is too many?

For a business under 20 people, more than about 25 rows usually means risks are being split too finely or copied from generic lists. Merge rows that share a cause and a control. A register you can read in five minutes gets reviewed; one that takes an hour gets skipped, and then it protects nobody.

Should staff be able to see the register?

Yes, at least the people named as owners and anyone who uses the tools listed. Seeing the risks explains why the rules exist, which makes them easier to follow. If a row describes a security weakness you haven't fixed yet, such as a shared password, keep the detail brief until it's closed.

Further reads

Sources: EU AI Act transparency provisions and the Digital Omnibus on AI; ISO/IEC 42001:2023 (checked September 2026).

Want help filling in your first AI risk register?

On a 1:1 call we'll list the AI your business actually uses, score the risks together, and agree the three actions worth doing first.

Book a 1:1 call with me