# AI risk assessment and lifecycle risk register

- **Record type**: Control
- **Kind**: Process
- **Owner**: AI system owner
- **Frequency**: Once per AI system
- **Duties served**: 12

## What the control achieves

Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from design through retirement.

## How it is typically implemented

For each in-scope system a cross-functional team runs a structured assessment: it lists foreseeable harms under intended use and reasonably foreseeable misuse, rates likelihood and severity, records existing and planned mitigations and decides whether residual risk is acceptable. Findings feed a per-system risk register with an owner and review date for each item. The assessment is redone on material change, after significant incidents and on a fixed cadence, and its outputs feed the testing plan, the human-oversight design and the release decision. Residual-risk acceptance is signed by an accountable person rather than the delivery team.

## Evidence it produces

- AI system risk assessment (risk_assessment): Method, identified risks, ratings, treatments and residual-risk decision for one system.
- Per-system AI risk register (risk_register): Live list of risks with owner, rating, treatment status and next review.
- Residual-risk acceptance (approval_record)

## Legal duties this control serves

- Establish accountability processes and a risk-management process (guardrails 1 and 2) — Australian Voluntary AI Safety Standard, Australia (satisfies): https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
- Establish a risk management system for high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system
- Establish internal governance structures and measures for AI — Singapore Model AI Governance Framework, Singapore (supports): https://aipolicytracker.org/obligations/singapore-mgf-internal-governance
- Adopt the guiding principles and risk-based governance (voluntary) — India AI Governance Guidelines, India (supports): https://aipolicytracker.org/obligations/india-ai-guidelines-principles-and-risk-based-governance
- Determine the appropriate level of human involvement in AI decisions — Singapore Model AI Governance Framework, Singapore (supports): https://aipolicytracker.org/obligations/singapore-mgf-human-involvement
- Operators of high-impact AI must establish and operate a risk management plan — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (satisfies): https://aipolicytracker.org/obligations/uk-principles-safety-security-robustness
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-deployer-risk-management-program
- Developers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-reasonable-care
- Deployers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States) (supports): https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (supports): https://aipolicytracker.org/obligations/us-nist-ai-rmf-map
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (satisfies): https://aipolicytracker.org/obligations/us-nist-ai-rmf-manage

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 6.1.2, 6.1.3, 8.2, 8.3
- ISO/IEC 23894:2023: Clause 6.4, 6.5, 6.6 — Risk identification, analysis, evaluation, treatment and monitoring.
- NIST AI RMF 1.0: MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1

## MIT AI Risk Repository subdomains addressed

1.1, 1.3, 5.1, 7.3, 6.5

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-risk-assessment
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
