# AI Risk Register Template and Framework Mapping

One risk register that serves EU AI Act, NIST AI RMF, ISO 42001, and GDPR at once, without duplicating work. A register template with cross-reference notation, a framework cross-reference map, and a committee reporting format.

**Who this is for:** The governance analyst who has to satisfy several frameworks and refuses to keep four spreadsheets.

Source playbook: https://aigovernance.com/playbook/multi-framework-ai-risk-register

---

## Multi-framework risk register template

_One row per risk per system. Frameworks are a column, not separate registers._

### Template

| ID | System | Risk description | Frameworks addressed | Owner | Current control | Status | Target date |
|---|---|---|---|---|---|---|---|
| R-001 | <system> | <what could go wrong and its effect> | EU AI Act Art. X / NIST <func> / ISO 42001 §X / GDPR Art. X | <name> | <control in place today> | Open / In progress / Mitigated / Accepted | YYYY-MM-DD |

### Worked example

| ID | System | Risk description | Frameworks addressed | Owner | Current control | Status | Target date |
|---|---|---|---|---|---|---|---|
| R-014 | Resume Screener | Historical hiring data skew produces disparate scores by sex | EU AI Act Art. 10 / NIST MEASURE 2.11 / ISO 42001 6.1.2 / GDPR Art. 22 | R. Nkemelu | Monthly adverse-impact eval; tenure-weight cap | In progress | 2026-10-15 |
| R-015 | Resume Screener | No FRIA completed for an Annex III use | EU AI Act Art. 27 | Legal | Scheduled | Open | 2026-10-31 |
| R-022 | Support Copilot | Retrieval can surface another customer's data | NIST MANAGE 2.2 / ISO 42001 8.3 | MLOps | Customer-ID scoping added; CI test pending | Mitigated | 2026-09-20 |

### Acceptance criteria

- Each risk has one owner, responsible regardless of which framework raised it.
- The frameworks column uses specific article or function references, not just a framework name.
- Every row has a status and, unless Mitigated or Accepted, a target date.

---

## Framework cross-reference map

_A lookup from a risk theme to the clause in each framework that covers it, so mapping a new risk is fast._

### Template

| Risk theme | EU AI Act | NIST AI RMF | ISO 42001 | GDPR / other |
|---|---|---|---|---|
| Data quality and bias | Art. 10 | MEASURE 2.11 | 6.1.2, 8.3 | Art. 5(1)(d) |
| Risk management process | Art. 9 | MAP / MANAGE | 6.1, 8.2 | Art. 35 (DPIA) |
| Human oversight | Art. 14 | MEASURE 2.8 | 8.3 | Art. 22 |
| Transparency to affected people | Art. 13, 52 | GOVERN 4.2 | 7.4 | Art. 13-14 |
| Logging and traceability | Art. 12 | MEASURE 2.4 | 8.4 | Art. 30 |
| Accuracy, robustness, security | Art. 15 | MEASURE 2.5-2.7 | 8.3 | Art. 32 |
| Post-market monitoring | Art. 72 | MANAGE 4.1 | 9.1, 10.2 | - |

### Worked example

> Using the map to place a new risk: "agent can call a payment API without a second approval."

| Risk theme matched | EU AI Act | NIST AI RMF | ISO 42001 | GDPR / other |
|---|---|---|---|---|
| Human oversight | Art. 14 | MEASURE 2.8 | 8.3 | Art. 22 |
| Accuracy, robustness, security | Art. 15 | MEASURE 2.5-2.7 | 8.3 | Art. 32 |

Added to the register as R-031 with those references in under two minutes.

### Acceptance criteria

- The map covers every framework the organization is subject to.
- References are kept current as framework versions change, with a review owner.
- New register entries draw their framework column from the map.

---

## Register review cadence and committee report

_How the register is kept alive and what the governance committee sees each cycle._

### Template

> Quarterly review; standing committee agenda item.

**Review steps:**
1. Update status on every open item; flag anything past its target date.
2. Add risks from new regulatory developments and from incidents since last review.
3. Re-confirm each open item still has the right owner.
4. Close items that are mitigated, with evidence.

**Committee report (one page):**
- Open items by status, and change since last quarter
- Overdue items, with owner and reason
- New risks added this quarter and why
- Items accepted as residual risk, with who accepted them
- Ask: any decisions or resourcing needed

### Worked example

**Q3 2026 report:**
- Open: 12 (was 15). In progress 7, Open 5. Mitigated this quarter: 4.
- Overdue: 2. R-015 FRIA (Legal, notified-body scheduling delay). R-019 monitoring alerting (MLOps, deprioritized behind incident fix).
- New: 3, all from the agent pilot in engineering.
- Accepted as residual: R-014 adverse-impact ratio in the 0.80-0.90 band, accepted by Head of Talent to next cycle.
- Ask: 0.3 FTE from MLOps to clear R-019 by year end.

### Acceptance criteria

- The review happens on a fixed cadence with a named owner.
- The committee sees overdue items and accepted residual risks every cycle, not just totals.
- New regulatory developments are a standing input to the review.

---

## Governance controls this kit produces evidence for

- **BRD-009**: The register template is the unified multi-framework risk register itself.
- **CMP-001**: The cross-reference map operationalises multi-jurisdiction and multi-framework obligation mapping.
- **CMP-003**: The frameworks column and map evidence voluntary-framework obligations are tracked alongside binding ones.
- **MGV-003**: Quarterly register review with committee reporting is a governance-program milestone and cadence.
- **HOC-007**: The one-page committee report feeds board risk reporting with overdue and accepted-risk detail.
