RegisterFree · no accountNIST AI RMFISO/IEC 42001EU AI Act
AI Risk Register (MIT AI Risk Repository taxonomy)
A risk register whose domain and subdomain dropdowns are the MIT AI Risk Repository taxonomy, with inherent and residual scoring, control lookup and colour-coded thresholds.
What's inside
- Register sheet: domain and subdomain dropdowns from the MIT taxonomy, likelihood × impact scoring with formulas, residual scoring after controls
- Conditional formatting: red at 15 and above, amber at 8, green below
- Controls sheet: every recorded control, what it does and which duties it satisfies
- Taxonomy sheet: all 7 domains and 24 subdomains with their definitions
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Register
| Risk ID | System | Risk domain (MIT) ▾ | Subdomain (MIT) ▾ | Risk description | Cause or trigger | Likelihood (1–5) ▾ | Impact (1–5) ▾ | Inherent score ƒ | Control applied ▾ | Residual likelihood ▾ | Residual impact ▾ | Residual score ƒ | Owner | Status ▾ | Review date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||||||||||||
Red at 15 and above, amber from 8, green below. An all-green register is a warning sign for a reviewer.
Sheet: MIT taxonomy
| Domain | Subdomain | Definition | Use cases (site taxonomy) |
|---|---|---|---|
| 1. Discrimination & Toxicity | 1.1 Unfair discrimination and misrepresentation | Unequal treatment of individuals or groups by AI, often based on race, gender, or other sensitive characteristics, resulting in unfair outcomes and representati | hiring_and_hr, finance_and_credit, education |
| 1. Discrimination & Toxicity | 1.2 Exposure to toxic content | AI exposing users to harmful, abusive, unsafe or inappropriate content. May involve AI creating, describing, providing advice, or encouraging action. Examples o | hiring_and_hr, finance_and_credit, education |
| 1. Discrimination & Toxicity | 1.3 Unequal performance across groups | Accuracy and effectiveness of AI decisions and actions is dependent on group membership, where decisions in AI system design and biased training data lead to un | hiring_and_hr, finance_and_credit, education |
| 2. Privacy & Security | 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information | AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized shari | biometrics, health |
| 2. Privacy & Security | 2.2 AI system security vulnerabilities and attacks | Vulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches, | biometrics, health |
| 3. Misinformation | 3.1 False or misleading information | AI systems that inadvertently generate or spread incorrect or deceptive information, which can lead to inaccurate beliefs in users and undermine their autonomy. | generative_ai |
Sheet: Controls
| Control | Kind | Purpose | Typical owner | Frequency | Duties it satisfies | Duties it supports | Evidence it produces | ISO/IEC 42001 | NIST AI RMF | Record |
|---|---|---|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | Policy | Gives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other A | Executive sponsor for AI | annual | 9 | 7 | AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility map | Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 | GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability |
| AI impact and fundamental-rights impact assessment | Process | Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the | AI system owner | per_system | 4 | 7 | AI impact assessment; Impact assessment approval; Impact assessment procedure and template | Clause 6.1.4, 8.4; Annex A.5 | MAP 5.1, 5.2; MEASURE 2.11 | https://aipolicytracker.org/controls/ai-impact-assessment |
| AI incident management and regulatory reporting | Process | Ensures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and af | Incident coordinator | continuous | 9 | 5 | AI incident response playbook; AI incident record; Incident report to an authority | Clause 10.2; Annex A.8.3, A.8.4 | MANAGE 4.1, 4.3; GOVERN 4.3, 6.2 | https://aipolicytracker.org/controls/ai-incident-management-and-reporting |
| AI interaction and use disclosure notices | Process | Tells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that the | Product owner | on_material_change | 14 | 3 | AI interaction or use notice; Notice catalogue; Notice wording approval | Annex A.8.2, A.8.5 | MEASURE 2.8; GOVERN 5.1 | https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure |
| AI literacy and role-based training programme | Training | Gives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of | Learning and development lead | annual | 1 | 3 | AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materials | Clause 7.2, 7.3; Annex A.4.6 | GOVERN 2.2, 4.1 | https://aipolicytracker.org/controls/ai-literacy-and-role-based-training |
| AI risk assessment and lifecycle risk register | Process | Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from | AI system owner | per_system | 7 | 5 | AI system risk assessment; Per-system AI risk register; Residual-risk acceptance | Clause 6.1.2, 6.1.3, 8.2, 8.3 | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | https://aipolicytracker.org/controls/ai-risk-assessment |
Sheet: Risk duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Large frontier developers must publish a frontier AI framework | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, | Published frontier AI framework | GOVERN 1.x; NIST AI 600-1 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | |
| Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment | Internal-use catastrophic risk assessment summary sent to the Office of Emergency Services | Clause 9.1; Annex A.8.3 | MEASURE 2.6, MANAGE 1.2, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries |
| Deployers must implement a risk management policy and programme | AI risk management | Colorado AI Act | Colorado (United States) | Deployer / user organisation | Legal requirement | C.R.S. 6-1-1703(2) | 2026-06-30 | Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to ide | AI risk management policy and programme | Whole management system (named in the statute) | Whole framework (named in the statute) | Source-linked | https://aipolicytracker.org/obligations/us-colorado-deployer-risk-management-program |
| Developers must use reasonable care to avoid algorithmic discrimination | AI risk management | Colorado AI Act | Colorado (United States) | Provider / developer | Legal requirement | C.R.S. 6-1-1702(1) | 2026-06-30 | A developer of a high-risk AI system must use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination a | Algorithmic discrimination risk assessment; Bias evaluation results and mitigation record | Clause 6.1.2, 6.1.3 | MAP 1.1, MEASURE 2.11, MANAGE 1.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-reasonable-care |
| Deployers must use reasonable care to avoid algorithmic discrimination | AI risk management | Colorado AI Act | Colorado (United States) | Deployer / user organisation | Legal requirement | C.R.S. 6-1-1703(1) | 2026-06-30 | A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A de | Deployer compliance checklist per high-risk system | Clause 6.1.2; Annex A.9.2 | GOVERN 1.1, MANAGE 1.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care |
| Establish a risk management system for high-risk AI | AI risk management | EU AI Act | European Union | Provider / developer | Legal requirement | Article 9 | 2026-08-02 | Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: | Risk register and treatment plan; Pre-market test reports | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk | MAP, MEASURE and MANAGE functions | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system |
Duties this template covers (10)
Each is cited in the file with its source reference and a link back to the record.
- Large frontier developers must publish a frontier AI framework
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Establish a risk management system for high-risk AI
- Manage systemic risk for high-impact general-purpose models
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Operators of high-impact AI must establish and operate a risk management plan
- Ensure AI systems are safe, secure and robust throughout their lifecycle
- Measure and test trustworthiness characteristics (Measure)
- Prioritise, respond to and monitor AI risks (Manage)
- Apply minimum risk-management practices to high-impact AI
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Risk Register (MIT AI Risk Repository taxonomy) free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 39 recorded duties are cited in it, drawn from 6 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Risk Register (MIT AI Risk Repository taxonomy) free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 39 recorded duties are cited in it, drawn from 6 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.