AIPolicyTracker
Process Owner: AI system owner Once per AI system

AI risk assessment and lifecycle risk register

Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from design through retirement.

Duties satisfied
7
done properly, does the work
Duties supported
5
contributes; the duty needs more
Jurisdictions
8
Evidence items
3

How is it implemented?

For each in-scope system a cross-functional team runs a structured assessment: it lists foreseeable harms under intended use and reasonably foreseeable misuse, rates likelihood and severity, records existing and planned mitigations and decides whether residual risk is acceptable. Findings feed a per-system risk register with an owner and review date for each item. The assessment is redone on material change, after significant incidents and on a fixed cadence, and its outputs feed the testing plan, the human-oversight design and the release decision. Residual-risk acceptance is signed by an accountable person rather than the delivery team.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

Australia 1 duty

Colorado (United States) 3 duties

European Union 1 duty

South Korea 1 duty

United Kingdom 1 duty

United States 2 duties

India 1 duty

Singapore 2 duties

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
AI system risk assessmentRisk assessmentMethod, identified risks, ratings, treatments and residual-risk decision for one system.
Per-system AI risk registerRisk registerLive list of risks with owner, rating, treatment status and next review.
Residual-risk acceptanceApproval or sign-off record

Owner: AI system owner. Frequency: once per ai system.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Clause 6.1.2, 6.1.3, 8.2, 8.3high
ISO/IEC 23894Clause 6.4, 6.5, 6.6Risk identification, analysis, evaluation, treatment and monitoring.high
NIST AI RMFMAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1high

Cite this record

AIPolicyTracker (2026). “AI risk assessment and lifecycle risk register”. https://aipolicytracker.org/controls/ai-risk-assessment (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "AI risk assessment and lifecycle risk register" satisfy?
It is recorded as satisfying 7 and supporting 5 duties across Australia, Colorado (United States), European Union, South Korea, United Kingdom, United States, India and Singapore. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
AI system risk assessment, Per-system AI risk register and Residual-risk acceptance. Owner: AI system owner. Frequency: once per ai system.