Implementation Kit
AI Risk Register Template and Framework Mapping
One risk register that serves EU AI Act, NIST AI RMF, ISO 42001, and GDPR at once, without duplicating work. A register template with cross-reference notation, a framework cross-reference map, and a committee reporting format.
Who this is for: The governance analyst who has to satisfy several frameworks and refuses to keep four spreadsheets.
1. Multi-framework risk register template
SpreadsheetOne row per risk per system. Frameworks are a column, not separate registers.
Template
| ID | System | Risk description | Frameworks addressed | Owner | Current control | Status | Target date |
|---|---|---|---|---|---|---|---|
| R-001 | <system> | <what could go wrong and its effect> | EU AI Act Art. X / NIST <func> / ISO 42001 §X / GDPR Art. X | <name> | <control in place today> | Open / In progress / Mitigated / Accepted | YYYY-MM-DD |
Worked example
| ID | System | Risk description | Frameworks addressed | Owner | Current control | Status | Target date |
|---|---|---|---|---|---|---|---|
| R-014 | Resume Screener | Historical hiring data skew produces disparate scores by sex | EU AI Act Art. 10 / NIST MEASURE 2.11 / ISO 42001 6.1.2 / GDPR Art. 22 | R. Nkemelu | Monthly adverse-impact eval; tenure-weight cap | In progress | 2026-10-15 |
| R-015 | Resume Screener | No FRIA completed for an Annex III use | EU AI Act Art. 27 | Legal | Scheduled | Open | 2026-10-31 |
| R-022 | Support Copilot | Retrieval can surface another customer's data | NIST MANAGE 2.2 / ISO 42001 8.3 | MLOps | Customer-ID scoping added; CI test pending | Mitigated | 2026-09-20 |
Acceptance criteria
- ✓Each risk has one owner, responsible regardless of which framework raised it.
- ✓The frameworks column uses specific article or function references, not just a framework name.
- ✓Every row has a status and, unless Mitigated or Accepted, a target date.
2. Framework cross-reference map
SpreadsheetA lookup from a risk theme to the clause in each framework that covers it, so mapping a new risk is fast.
Template
| Risk theme | EU AI Act | NIST AI RMF | ISO 42001 | GDPR / other |
|---|---|---|---|---|
| Data quality and bias | Art. 10 | MEASURE 2.11 | 6.1.2, 8.3 | Art. 5(1)(d) |
| Risk management process | Art. 9 | MAP / MANAGE | 6.1, 8.2 | Art. 35 (DPIA) |
| Human oversight | Art. 14 | MEASURE 2.8 | 8.3 | Art. 22 |
| Transparency to affected people | Art. 13, 52 | GOVERN 4.2 | 7.4 | Art. 13-14 |
| Logging and traceability | Art. 12 | MEASURE 2.4 | 8.4 | Art. 30 |
| Accuracy, robustness, security | Art. 15 | MEASURE 2.5-2.7 | 8.3 | Art. 32 |
| Post-market monitoring | Art. 72 | MANAGE 4.1 | 9.1, 10.2 | - |
Worked example
Using the map to place a new risk: "agent can call a payment API without a second approval."
| Risk theme matched | EU AI Act | NIST AI RMF | ISO 42001 | GDPR / other |
|---|---|---|---|---|
| Human oversight | Art. 14 | MEASURE 2.8 | 8.3 | Art. 22 |
| Accuracy, robustness, security | Art. 15 | MEASURE 2.5-2.7 | 8.3 | Art. 32 |
Added to the register as R-031 with those references in under two minutes.
Acceptance criteria
- ✓The map covers every framework the organization is subject to.
- ✓References are kept current as framework versions change, with a review owner.
- ✓New register entries draw their framework column from the map.
3. Register review cadence and committee report
DocumentHow the register is kept alive and what the governance committee sees each cycle.
Template
Quarterly review; standing committee agenda item.
Review steps:
- Update status on every open item; flag anything past its target date.
- Add risks from new regulatory developments and from incidents since last review.
- Re-confirm each open item still has the right owner.
- Close items that are mitigated, with evidence.
Committee report (one page):
- Open items by status, and change since last quarter
- Overdue items, with owner and reason
- New risks added this quarter and why
- Items accepted as residual risk, with who accepted them
- Ask: any decisions or resourcing needed
Worked example
Q3 2026 report:
- Open: 12 (was 15). In progress 7, Open 5. Mitigated this quarter: 4.
- Overdue: 2. R-015 FRIA (Legal, notified-body scheduling delay). R-019 monitoring alerting (MLOps, deprioritized behind incident fix).
- New: 3, all from the agent pilot in engineering.
- Accepted as residual: R-014 adverse-impact ratio in the 0.80-0.90 band, accepted by Head of Talent to next cycle.
- Ask: 0.3 FTE from MLOps to clear R-019 by year end.
Acceptance criteria
- ✓The review happens on a fixed cadence with a named owner.
- ✓The committee sees overdue items and accepted residual risks every cycle, not just totals.
- ✓New regulatory developments are a standing input to the review.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The register template is the unified multi-framework risk register itself.
The cross-reference map operationalises multi-jurisdiction and multi-framework obligation mapping.
The frameworks column and map evidence voluntary-framework obligations are tracked alongside binding ones.
Quarterly register review with committee reporting is a governance-program milestone and cadence.
The one-page committee report feeds board risk reporting with overdue and accepted-risk detail.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →