AI risk register with real review (L3)
Every AI workload that touches customer data, money, or public output gets a register entry with its failure modes, its blast radius, and its rollback. Review is scheduled, not incident driven.
The steps
- 01
Set the registration threshold
Tool: Manual
Define exactly which workloads must register: customer data, external output, financial action, or employment decisions. Registering everything means registering nothing well. Owner: security plus legal. DoD: threshold published with examples.
- 02
Record failure modes and blast radius
Tool: Notion
For each workload, what can go wrong, who is affected, how it is detected, and how it is rolled back. Detection is the field teams most often leave blank and most often need. Pitfall: a register of descriptions with no detection method. DoD: every entry has a detection and rollback line.
- 03
Review on a schedule
Tool: Manual
High risk workloads quarterly, others twice a year. Attach the review to a calendar owner, not to a policy sentence. Owner: security. DoD: next review date on every entry.
- 04
Report to leadership in one page
Tool: Slack
Count by risk tier, overdue reviews, and incidents. Leadership needs the shape of the exposure, not the register itself. Owner: security lead. DoD: quarterly one page report delivered.
Tools in this playbook
Next playbooks
Unfamiliar terms are defined in the AI and Revenue Dictionary. Related frameworks live in the framework library.
