AIPolicyTracker
RegisterFree · no accountNIST AI RMFISO/IEC 42001EU AI Act

AI Risk Register (MIT AI Risk Repository taxonomy)

A risk register whose domain and subdomain dropdowns are the MIT AI Risk Repository taxonomy, with inherent and residual scoring, control lookup and colour-coded thresholds.

Formats: XLSX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Register sheet: domain and subdomain dropdowns from the MIT taxonomy, likelihood × impact scoring with formulas, residual scoring after controls
  • Conditional formatting: red at 15 and above, amber at 8, green below
  • Controls sheet: every recorded control, what it does and which duties it satisfies
  • Taxonomy sheet: all 7 domains and 24 subdomains with their definitions

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Register · 16 columns · blank, 300 rows ready to fill
First rows of the Register sheet
Risk IDSystemRisk domain (MIT) ▾Subdomain (MIT) ▾Risk descriptionCause or triggerLikelihood (1–5) ▾Impact (1–5) ▾Inherent score ƒControl applied ▾Residual likelihood ▾Residual impact ▾Residual score ƒOwnerStatus ▾Review date
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

Red at 15 and above, amber from 8, green below. An all-green register is a warning sign for a reviewer.

Sheet: MIT taxonomy · 4 columns · 24 rows from the records
First rows of the MIT taxonomy sheet
DomainSubdomainDefinitionUse cases (site taxonomy)
1. Discrimination & Toxicity1.1 Unfair discrimination and misrepresentationUnequal treatment of individuals or groups by AI, often based on race, gender, or other sensitive characteristics, resulting in unfair outcomes and representatihiring_and_hr, finance_and_credit, education
1. Discrimination & Toxicity1.2 Exposure to toxic contentAI exposing users to harmful, abusive, unsafe or inappropriate content. May involve AI creating, describing, providing advice, or encouraging action. Examples ohiring_and_hr, finance_and_credit, education
1. Discrimination & Toxicity1.3 Unequal performance across groupsAccuracy and effectiveness of AI decisions and actions is dependent on group membership, where decisions in AI system design and biased training data lead to unhiring_and_hr, finance_and_credit, education
2. Privacy & Security2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive informationAI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharibiometrics, health
2. Privacy & Security2.2 AI system security vulnerabilities and attacksVulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches,biometrics, health
3. Misinformation3.1 False or misleading informationAI systems that inadvertently generate or spread incorrect or deceptive information, which can lead to inaccurate beliefs in users and undermine their autonomy.generative_ai
Sheet: Controls · 11 columns · 26 rows from the records
First rows of the Controls sheet
ControlKindPurposeTypical ownerFrequencyDuties it satisfiesDuties it supportsEvidence it producesISO/IEC 42001NIST AI RMFRecord
AI governance policy and accountability structurePolicyGives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other AExecutive sponsor for AIannual97AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility mapClause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3GOVERN 1.1, 1.2, 1.3, 2.1, 3.1https://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI impact and fundamental-rights impact assessmentProcessExamines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records theAI system ownerper_system47AI impact assessment; Impact assessment approval; Impact assessment procedure and templateClause 6.1.4, 8.4; Annex A.5MAP 5.1, 5.2; MEASURE 2.11https://aipolicytracker.org/controls/ai-impact-assessment
AI incident management and regulatory reportingProcessEnsures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and afIncident coordinatorcontinuous95AI incident response playbook; AI incident record; Incident report to an authorityClause 10.2; Annex A.8.3, A.8.4MANAGE 4.1, 4.3; GOVERN 4.3, 6.2https://aipolicytracker.org/controls/ai-incident-management-and-reporting
AI interaction and use disclosure noticesProcessTells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that theProduct owneron_material_change143AI interaction or use notice; Notice catalogue; Notice wording approvalAnnex A.8.2, A.8.5MEASURE 2.8; GOVERN 5.1https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure
AI literacy and role-based training programmeTrainingGives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of Learning and development leadannual13AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materialsClause 7.2, 7.3; Annex A.4.6GOVERN 2.2, 4.1https://aipolicytracker.org/controls/ai-literacy-and-role-based-training
AI risk assessment and lifecycle risk registerProcessIdentifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive fromAI system ownerper_system75AI system risk assessment; Per-system AI risk register; Residual-risk acceptanceClause 6.1.2, 6.1.3, 8.2, 8.3MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1https://aipolicytracker.org/controls/ai-risk-assessment
Sheet: Risk duties · 14 columns · 13 rows from the records
First rows of the Risk duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Large frontier developers must publish a frontier AI frameworkSafety testing and evaluationCalifornia SB 53California (United States)General-purpose AI model providerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, Published frontier AI frameworkGOVERN 1.x; NIST AI 600-1Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the stateSafety testing and evaluationCalifornia SB 53California (United States)General-purpose AI model providerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment Internal-use catastrophic risk assessment summary sent to the Office of Emergency ServicesClause 9.1; Annex A.8.3MEASURE 2.6, MANAGE 1.2, GOVERN 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries
Deployers must implement a risk management policy and programmeAI risk managementColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(2)2026-06-30Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to ideAI risk management policy and programmeWhole management system (named in the statute)Whole framework (named in the statute)Source-linkedhttps://aipolicytracker.org/obligations/us-colorado-deployer-risk-management-program
Developers must use reasonable care to avoid algorithmic discriminationAI risk managementColorado AI ActColorado (United States)Provider / developerLegal requirementC.R.S. 6-1-1702(1)2026-06-30A developer of a high-risk AI system must use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination aAlgorithmic discrimination risk assessment; Bias evaluation results and mitigation recordClause 6.1.2, 6.1.3MAP 1.1, MEASURE 2.11, MANAGE 1.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-reasonable-care
Deployers must use reasonable care to avoid algorithmic discriminationAI risk managementColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(1)2026-06-30A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A deDeployer compliance checklist per high-risk systemClause 6.1.2; Annex A.9.2GOVERN 1.1, MANAGE 1.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care
Establish a risk management system for high-risk AIAI risk managementEU AI ActEuropean UnionProvider / developerLegal requirementArticle 92026-08-02Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle:Risk register and treatment plan; Pre-market test reportsClauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI riskMAP, MEASURE and MANAGE functionsSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-risk-management-system

Duties this template covers (10)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

Version history

Versions of AI Risk Register (MIT AI Risk Repository taxonomy)
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Risk Register (MIT AI Risk Repository taxonomy) free?
Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 39 recorded duties are cited in it, drawn from 6 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Risk Register (MIT AI Risk Repository taxonomy) free?
Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 39 recorded duties are cited in it, drawn from 6 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.