ISO 42001 AI Risk Log Template

AI Risk Assessment & Management Tool

This interactive AI Risk Log helps organizations identify, assess, and manage risks associated with their AI systems in compliance with ISO/IEC 42001 standards. Document your AI risks, evaluate their likelihood and impact, and develop appropriate mitigation strategies.

Understanding the Risk Log

Risk ID

A unique identifier assigned to each risk for easy reference and tracking.

Entry Date

The date when the risk was first identified and entered into the log (automatically set to current date).

AI System / Model

The specific AI system, model, or component being assessed for risks.

Risk Source

The origin or source from which the risk emerges (e.g., data, algorithm, deployment environment).

Risk Description

A detailed description of the potential risk, including what could go wrong and how.

Risk Category

Classification of the risk based on predefined categories (e.g., bias, privacy, security).

Likelihood (1-5)

The probability that this risk will occur, rated from 1 (very unlikely) to 5 (very likely).

Impact (1-5)

The severity of consequences if the risk occurs, rated from 1 (minimal) to 5 (catastrophic).

Mitigation Measures

The planned actions, controls, or strategies to prevent, reduce, or manage the risk.

Responsible Person

The individual or team responsible for managing, monitoring, and addressing this risk.

Status

Current state of the risk management process (In Progress, Open, or Closed).

Review Date

Scheduled date for the next review of the risk to assess changes and effectiveness of mitigation measures.

Risk Scoring Criteria (1-5 Scale)

Rate both likelihood and impact using the following scale. Risk level is calculated as Likelihood × Impact.

1: Very Low
Extremely rare occurrence / Minimal impact
2: Low
Unlikely to occur / Minor impact
3: Medium
Possible occurrence / Moderate impact
4: High
Likely to occur / Major impact
5: Very High
Almost certain to occur / Catastrophic impact

AI Risk Log Entries

Risk Entry 1