AI Risk Register Template for UK SMEs

Free template for documenting AI tools, risk classifications, and governance decisions.

·4 min read
An AI risk register documents every AI tool your organisation uses, its risk classification, what data it accesses, your governance decision, and the review schedule. It's the evidence trail that regulators, insurers, and auditors want to see — and the foundation of practical AI governance.

Template

ToolBusiness UseData AccessedRiskStatusMitigationOwner
ChatGPT TeamContent draftingInternal docsMediumApprovedNo client data; Team account (no training)IT Manager
Microsoft CopilotEmail + document assistanceEmail, SharePointMediumApproved with conditionsDPA in place; sensitivity labels enforcedIT Manager
GrammarlyWriting assistanceText inputLowApprovedBusiness plan; enterprise settingsOps Lead
Otter.aiMeeting transcriptionAudio, meeting contentHighFlaggedUnder review — client meetings may contain PIICompliance
Personal ChatGPTVarious (unapproved)UnknownHighProhibitedUse Team account instead; policy briefing issuedAll staff

How to use this template

  1. Run an AI tools audit to discover all tools in use
  2. Add each tool to the register with its business use and data access
  3. Classify risk (low/medium/high) based on data sensitivity and scope
  4. Record your governance decision (approved/flagged/prohibited)
  5. Assign an owner and set a review date
  6. Review quarterly — or when a new tool is discovered

What is an AI risk register?

A document listing every AI tool, its risk level, data access, and governance decision.

Is it legally required?

Not explicitly in UK law, but expected by the EU AI Act and increasingly by cyber insurers.

How often should I update it?

Quarterly minimum. Update whenever a new tool is discovered or a governance decision changes.