You already have a list of the choices your team makes. For each one, ask what happens if it goes wrong. That list of answers is your risk list.
If you've filled in a decision inventory, you've done most of the work of a risk register. Take each decision that AI touches, ask five questions about what goes wrong and who notices, and you have a register people can act on.
Derive the register from the decision inventory: filter to AI-influenced decisions, then add impact if wrong, reversibility, reliance, time to detect, owner, control and nudge. Inherit volume and stakes from the inventory so ranking needs no new data collection.
Why start from the inventory
In Most AI risk registers list the model, not the decision I argued that a useful register has one row per decision. That raises the obvious question: where do the rows come from? My answer is the decision inventory. It already lists the decisions a team makes, with volume, stakes and reversibility. Those are half the columns a register needs.
Starting there also stops the register drifting back to generic model risks. Every row has to name a real decision someone makes.
The steps
- Filter the inventory to decisions that an AI tool influences, now or in a plan you're considering. Include decisions where a person reads an AI summary before choosing. Those count.
- Copy across the decision, the owner, the volume and the stakes.
- For each row, answer five questions.
| Question | What I write |
|---|---|
| What does a wrong answer look like here? | One sentence, specific to this decision |
| Who bears the cost if it's wrong? | A customer, a colleague, the budget, the organisation |
| Can it be undone, and how fast? | Yes within a day, yes within a month, or no |
| How long before anyone would notice? | Hours, weeks, or only at audit |
| What catches or prevents it today? | The control that actually exists, even if it's weak |
- Tag each row with one or more of the five risk types.
- Leave the rating for later. Ranking comes next, in Likelihood, impact and reversibility on one sheet.
A worked example
This team and its numbers are illustrative. A customer service team's inventory has 14 decisions. Five are influenced by AI.
| Decision | Volume a month | Wrong answer looks like | Undo? | Noticed in |
|---|---|---|---|---|
| Which queue a complaint goes to | 1,200 | Urgent complaint sits in routine queue | Yes, within a day | Days, if the customer chases |
| Goodwill credit up to £20 | 300 | Credit given where policy says no | No, once paid | Month-end report |
| Reply wording on a sensitive case | 150 | Tone or fact is wrong | Partly, with an apology | When the customer replies |
| Whether to escalate to a manager | 90 | A case that needed a manager doesn't get one | Yes, slowly | Weeks, or at complaint review |
| Summary of call history for a new agent | 600 | A key fact is missing from the summary | Yes | Often never |
The last row is the interesting one. It looks low risk because nothing is decided from the summary directly. But if nobody ever notices a missing fact, the errors pass silently into every later decision on that case. That row deserves a better control than its stakes suggest.
What to expect
I'd expect two things to come up. The first is that the "what catches it today" column has more blanks or "nothing" than people expect. The second is that teams may find decisions that AI already influences without anyone having decided it should, such as someone pasting a case into Copilot Chat for a suggested reply. Both are useful to know before anything is ranked.
Where I got stuck
The hardest column is "how long before anyone would notice". People tend to answer with how long it should take. So I ask for the last time an error of that kind was actually found, and how. If nobody can remember one, I write "unknown", which is itself a finding.
Sources
This article describes my own method and uses no external facts or figures. It builds on two earlier articles on this site: The decision inventory template and Most AI risk registers list the model, not the decision.