Craig Stanley
Home / Risk / Start here / Start a risk register from the decision inventory

Start a risk register from the decision inventory

How I turn a team's decision inventory into a first risk register in about an hour, with one row per decision and five questions per row.

· 3 min read · Craig Stanley
In short, explained

You already have a list of the choices your team makes. For each one, ask what happens if it goes wrong. That list of answers is your risk list.

If you've filled in a decision inventory, you've done most of the work of a risk register. Take each decision that AI touches, ask five questions about what goes wrong and who notices, and you have a register people can act on.

Derive the register from the decision inventory: filter to AI-influenced decisions, then add impact if wrong, reversibility, reliance, time to detect, owner, control and nudge. Inherit volume and stakes from the inventory so ranking needs no new data collection.

Why start from the inventory

In Most AI risk registers list the model, not the decision I argued that a useful register has one row per decision. That raises the obvious question: where do the rows come from? My answer is the decision inventory. It already lists the decisions a team makes, with volume, stakes and reversibility. Those are half the columns a register needs.

Starting there also stops the register drifting back to generic model risks. Every row has to name a real decision someone makes.

The steps

  1. Filter the inventory to decisions that an AI tool influences, now or in a plan you're considering. Include decisions where a person reads an AI summary before choosing. Those count.
  2. Copy across the decision, the owner, the volume and the stakes.
  3. For each row, answer five questions.
QuestionWhat I write
What does a wrong answer look like here?One sentence, specific to this decision
Who bears the cost if it's wrong?A customer, a colleague, the budget, the organisation
Can it be undone, and how fast?Yes within a day, yes within a month, or no
How long before anyone would notice?Hours, weeks, or only at audit
What catches or prevents it today?The control that actually exists, even if it's weak
  1. Tag each row with one or more of the five risk types.
  2. Leave the rating for later. Ranking comes next, in Likelihood, impact and reversibility on one sheet.

A worked example

This team and its numbers are illustrative. A customer service team's inventory has 14 decisions. Five are influenced by AI.

DecisionVolume a monthWrong answer looks likeUndo?Noticed in
Which queue a complaint goes to1,200Urgent complaint sits in routine queueYes, within a dayDays, if the customer chases
Goodwill credit up to £20300Credit given where policy says noNo, once paidMonth-end report
Reply wording on a sensitive case150Tone or fact is wrongPartly, with an apologyWhen the customer replies
Whether to escalate to a manager90A case that needed a manager doesn't get oneYes, slowlyWeeks, or at complaint review
Summary of call history for a new agent600A key fact is missing from the summaryYesOften never

The last row is the interesting one. It looks low risk because nothing is decided from the summary directly. But if nobody ever notices a missing fact, the errors pass silently into every later decision on that case. That row deserves a better control than its stakes suggest.

What to expect

I'd expect two things to come up. The first is that the "what catches it today" column has more blanks or "nothing" than people expect. The second is that teams may find decisions that AI already influences without anyone having decided it should, such as someone pasting a case into Copilot Chat for a suggested reply. Both are useful to know before anything is ranked.

Where I got stuck

The hardest column is "how long before anyone would notice". People tend to answer with how long it should take. So I ask for the last time an error of that kind was actually found, and how. If nobody can remember one, I write "unknown", which is itself a finding.

Sources

This article describes my own method and uses no external facts or figures. It builds on two earlier articles on this site: The decision inventory template and Most AI risk registers list the model, not the decision.

Read next

A question to take awayWho gets told, and how fast, when a decision model starts drifting?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry (formerly Azure AI Foundry) work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

I write this site to learn in public: explaining each idea simply is how I check I understand it. Why I write this site.

Find me