AI Governance Institute
All governance templates →How do we build and maintain a multi-framework AI risk register?

Implementation Kit

AI Risk Register Template and Framework Mapping

One risk register that serves EU AI Act, NIST AI RMF, ISO 42001, and GDPR at once, without duplicating work. A register template with cross-reference notation, a framework cross-reference map, and a committee reporting format.

Who this is for: The governance analyst who has to satisfy several frameworks and refuses to keep four spreadsheets.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Multi-framework risk register template

Spreadsheet

One row per risk per system. Frameworks are a column, not separate registers.

Template

IDSystemRisk descriptionFrameworks addressedOwnerCurrent controlStatusTarget date
R-001<system><what could go wrong and its effect>EU AI Act Art. X / NIST <func> / ISO 42001 §X / GDPR Art. X<name><control in place today>Open / In progress / Mitigated / AcceptedYYYY-MM-DD

Worked example

IDSystemRisk descriptionFrameworks addressedOwnerCurrent controlStatusTarget date
R-014Resume ScreenerHistorical hiring data skew produces disparate scores by sexEU AI Act Art. 10 / NIST MEASURE 2.11 / ISO 42001 6.1.2 / GDPR Art. 22R. NkemeluMonthly adverse-impact eval; tenure-weight capIn progress2026-10-15
R-015Resume ScreenerNo FRIA completed for an Annex III useEU AI Act Art. 27LegalScheduledOpen2026-10-31
R-022Support CopilotRetrieval can surface another customer's dataNIST MANAGE 2.2 / ISO 42001 8.3MLOpsCustomer-ID scoping added; CI test pendingMitigated2026-09-20

Acceptance criteria

  • Each risk has one owner, responsible regardless of which framework raised it.
  • The frameworks column uses specific article or function references, not just a framework name.
  • Every row has a status and, unless Mitigated or Accepted, a target date.

2. Framework cross-reference map

Spreadsheet

A lookup from a risk theme to the clause in each framework that covers it, so mapping a new risk is fast.

Template

Risk themeEU AI ActNIST AI RMFISO 42001GDPR / other
Data quality and biasArt. 10MEASURE 2.116.1.2, 8.3Art. 5(1)(d)
Risk management processArt. 9MAP / MANAGE6.1, 8.2Art. 35 (DPIA)
Human oversightArt. 14MEASURE 2.88.3Art. 22
Transparency to affected peopleArt. 13, 52GOVERN 4.27.4Art. 13-14
Logging and traceabilityArt. 12MEASURE 2.48.4Art. 30
Accuracy, robustness, securityArt. 15MEASURE 2.5-2.78.3Art. 32
Post-market monitoringArt. 72MANAGE 4.19.1, 10.2-

Worked example

Using the map to place a new risk: "agent can call a payment API without a second approval."

Risk theme matchedEU AI ActNIST AI RMFISO 42001GDPR / other
Human oversightArt. 14MEASURE 2.88.3Art. 22
Accuracy, robustness, securityArt. 15MEASURE 2.5-2.78.3Art. 32

Added to the register as R-031 with those references in under two minutes.

Acceptance criteria

  • The map covers every framework the organization is subject to.
  • References are kept current as framework versions change, with a review owner.
  • New register entries draw their framework column from the map.

3. Register review cadence and committee report

Document

How the register is kept alive and what the governance committee sees each cycle.

Template

Quarterly review; standing committee agenda item.

Review steps:

  1. Update status on every open item; flag anything past its target date.
  2. Add risks from new regulatory developments and from incidents since last review.
  3. Re-confirm each open item still has the right owner.
  4. Close items that are mitigated, with evidence.

Committee report (one page):

  • Open items by status, and change since last quarter
  • Overdue items, with owner and reason
  • New risks added this quarter and why
  • Items accepted as residual risk, with who accepted them
  • Ask: any decisions or resourcing needed

Worked example

Q3 2026 report:

  • Open: 12 (was 15). In progress 7, Open 5. Mitigated this quarter: 4.
  • Overdue: 2. R-015 FRIA (Legal, notified-body scheduling delay). R-019 monitoring alerting (MLOps, deprioritized behind incident fix).
  • New: 3, all from the agent pilot in engineering.
  • Accepted as residual: R-014 adverse-impact ratio in the 0.80-0.90 band, accepted by Head of Talent to next cycle.
  • Ask: 0.3 FTE from MLOps to clear R-019 by year end.

Acceptance criteria

  • The review happens on a fixed cadence with a named owner.
  • The committee sees overdue items and accepted residual risks every cycle, not just totals.
  • New regulatory developments are a standing input to the review.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

BRD-009
BRD-009

The register template is the unified multi-framework risk register itself.

CMP-001
CMP-001

The cross-reference map operationalises multi-jurisdiction and multi-framework obligation mapping.

CMP-003
CMP-003

The frameworks column and map evidence voluntary-framework obligations are tracked alongside binding ones.

MGV-003
MGV-003

Quarterly register review with committee reporting is a governance-program milestone and cadence.

HOC-007
HOC-007

The one-page committee report feeds board risk reporting with overdue and accepted-risk detail.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →