Draw a grid. Down the side, write the jobs a person does. Across the top, write the kinds of trouble. Tick where trouble could happen. Now you can see where to look first.
A risk map is a grid with work activities down the side and risk types across the top. Each cell asks whether AI changes the risk for that activity. It shows clusters, gaps and the right owner much faster than a long list does.
Cross work activities (from O*NET, ESCO or your own task list) with the five risk types and the AI capability in use. Mark each cell as new risk, changed risk or unchanged. Owners follow the activity's process owner; clusters indicate where a control can cover several cells at once.
Why a map as well as a register
A register is a list, which is good for tracking. A map is a grid, which is good for seeing patterns. I use both. The register comes from decisions, as in Start a risk register from the decision inventory. The map comes from work activities: the things a role does all day, whether or not they involve a clear decision.
Activities matter because AI tools are often introduced activity by activity. Someone starts using Copilot to draft letters, or summarise meetings, or search policy. Each of those changes risk somewhere, even if no formal decision changes.
How the grid works
Down the side, list the role's main work activities. O*NET and ESCO are good sources, or use the team's own task list. Across the top, use the five risk types: data, decision, people, supplier and cost.
In each cell, write one of three marks.
| Mark | Meaning |
|---|---|
| N | AI adds a new risk to this activity |
| C | AI changes an existing risk, making it larger or smaller |
| blank | No meaningful change |
Then add a column for which AI capability is involved, such as Copilot Chat, a SharePoint agent or a Copilot Studio agent. The same activity can carry different risks depending on the tool.
A worked example
This role and its markings are illustrative. An HR adviser's main activities:
| Activity | Tool | Data | Decision | People | Supplier | Cost |
|---|---|---|---|---|---|---|
| Answer policy questions from managers | SharePoint agent | C | C | N | ||
| Draft letters for formal processes | Microsoft 365 Copilot | N | C | C | ||
| Summarise case notes before a hearing | Microsoft 365 Copilot | N | N | C | ||
| Analyse absence data | Copilot in Excel | C | C | |||
| Book training for staff | None |
Three things stand out. Data risk is new or changed in four of five activities, because Copilot can reach whatever the adviser can open. Decision risk clusters around formal processes, where summaries and letters shape outcomes for an individual. And cost appears only for the SharePoint agent, because managers without a Copilot licence would use it on pay-as-you-go.
Reading the map
Look for columns. A column full of marks suggests one control could cover many cells. Here, a review of the adviser's access before rollout addresses most of the data column at once.
Look for rows. A row with marks in three or more columns is usually the activity to pilot carefully, with a named reviewer. Here, that's case note summaries.
Look for empty columns. If supplier is blank for every activity, either the risk is genuinely low or nobody has thought about what happens when the tool or model changes. I'd ask which.
Who owns each cell
I give ownership by row, to the person responsible for the activity, with specialist help by column. The HR lead owns the case summary row. The data protection officer helps across the data column. That keeps one accountable person per activity without making a specialist responsible for work they don't do.
Where I got stuck
The trap I keep running into on paper is too many activities, until every cell gets a mark and nothing stands out. My working limit is about ten activities per role. If a role has more, I group them, then split only the rows that light up.
Sources
This article describes my own method and uses no external facts or figures. Activity lists can come from O*NET OnLine or the European Commission's ESCO classification, covered in the Work section.