AI risk assessment and lifecycle risk register
Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from design through retirement.
- Duties satisfied
- 7
- done properly, does the work
- Duties supported
- 5
- contributes; the duty needs more
- Jurisdictions
- 8
- Evidence items
- 3
How is it implemented?
For each in-scope system a cross-functional team runs a structured assessment: it lists foreseeable harms under intended use and reasonably foreseeable misuse, rates likelihood and severity, records existing and planned mitigations and decides whether residual risk is acceptable. Findings feed a per-system risk register with an owner and review date for each item. The assessment is redone on material change, after significant incidents and on a fixed cadence, and its outputs feed the testing plan, the human-oversight design and the release decision. Residual-risk acceptance is signed by an accountable person rather than the delivery team.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
Australia 1 duty
-
satisfies Voluntary confidence highEstablish accountability processes and a risk-management process (guardrails 1 and 2)
Australian Voluntary AI Safety Standard · Guardrails 1 and 2
Guardrail 2: per-use-case lifecycle risk process.
Colorado (United States) 3 duties
-
satisfies Legal requirement confidence highDeployers must implement a risk management policy and programme
Colorado AI Act · C.R.S. 6-1-1703(2) · applies from 30 Jun 2026
Per-system identification, documentation and mitigation of algorithmic discrimination risk.
-
satisfies Legal requirement confidence highDevelopers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · C.R.S. 6-1-1702(1) · applies from 30 Jun 2026
Identifies and treats discrimination risk per system.
-
supports Legal requirement confidence highDeployers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · C.R.S. 6-1-1703(1) · applies from 30 Jun 2026
Discrimination risk identified for each consequential-decision use.
European Union 1 duty
-
satisfies Legal requirement confidence highEstablish a risk management system for high-risk AI
EU AI Act · Article 9 · applies from 2 Aug 2026
Continuous lifecycle risk process with register, testing evidence and residual-risk acceptance.
South Korea 1 duty
-
satisfies Legal requirement confidence highOperators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1) · applies from 22 Jan 2026
Per-system risk plan with identified risks and treatments.
United Kingdom 1 duty
-
satisfies VoluntaryEnsure AI systems are safe, secure and robust throughout their lifecycle
UK AI regulation framework · Principle 1, Part 3
Lifecycle identification and management of risks.
United States 2 duties
-
satisfies VoluntaryPrioritise, respond to and monitor AI risks (Manage)
NIST AI RMF · MANAGE function
Risk treatment planning and resource allocation for mapped and measured risks.
-
supports VoluntaryMap context, intended use and potential impacts (Map)
NIST AI RMF · MAP function
Risk categorisation and benefit-cost analysis.
India 1 duty
-
supports VoluntaryAdopt the guiding principles and risk-based governance (voluntary)
India AI Governance Guidelines · Guiding principles and recommendations sections
Proportionate risk classification and mitigation per system.
Singapore 2 duties
-
supports VoluntaryEstablish internal governance structures and measures for AI
Singapore Model AI Governance Framework · Second edition, Part on internal governance structures and measures
Adding AI risks to enterprise risk management.
-
supports VoluntaryDetermine the appropriate level of human involvement in AI decisions
Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making
Probability and severity of harm drive the involvement level.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| AI system risk assessment | Risk assessment | Method, identified risks, ratings, treatments and residual-risk decision for one system. |
| Per-system AI risk register | Risk register | Live list of risks with owner, rating, treatment status and next review. |
| Residual-risk acceptance | Approval or sign-off record |
Owner: AI system owner. Frequency: once per ai system.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 1.1 Unfair discrimination and misrepresentation Discrimination & Toxicity118 incidents · 83 risk entries
- 1.3 Unequal performance across groups Discrimination & Toxicity34 incidents · 17 risk entries
- 5.1 Overreliance and unsafe use Human-Computer Interaction38 incidents · 60 risk entries
- 7.3 Lack of capability or robustness AI system safety, failures, & limitations305 incidents · 126 risk entries
- 6.5 Governance failure Socioeconomic & Environmental3 incidents · 61 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Clause 6.1.2, 6.1.3, 8.2, 8.3 | high | |
| ISO/IEC 23894 | Clause 6.4, 6.5, 6.6 | Risk identification, analysis, evaluation, treatment and monitoring. | high |
| NIST AI RMF | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | high |
Cite this record
AIPolicyTracker (2026). “AI risk assessment and lifecycle risk register”. https://aipolicytracker.org/controls/ai-risk-assessment (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "AI risk assessment and lifecycle risk register" satisfy?
- It is recorded as satisfying 7 and supporting 5 duties across Australia, Colorado (United States), European Union, South Korea, United Kingdom, United States, India and Singapore. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- AI system risk assessment, Per-system AI risk register and Residual-risk acceptance. Owner: AI system owner. Frequency: once per ai system.