Building an AI Risk Register for Your Business
Emeka runs an independent bookstore and events space in Minneapolis. He started using AI tools in January: ChatGPT for marketing copy, an AI scheduling tool for his event calendar, and a chatbot on his website that answered customer questions. By March he had had three problems. The chatbot told a customer his store was open on Mondays, which it is not. The AI wrote a newsletter that accidentally promised a discount he had never authorized. And an employee used ChatGPT to draft a vendor negotiation email that included Emeka's actual cost margins. None of these were catastrophic, but each one cost him something: customer trust, awkward vendor conversations, a coupon he had to honor. A risk register would not have prevented all three, but it would have prevented two of them.
What a Risk Register Actually Is
A risk register is a simple document, a spreadsheet or even a one-page table, that lists every way your AI tools could cause a problem, how likely that problem is, how bad it would be if it happened, and what you are doing to prevent or handle it. That is the whole idea. It is not a compliance artifact and it is not something you write once and file away. It is a working list, ranked by how much each item could hurt you, that tells you where to spend the small amount of prevention effort you actually have.
Think of it the way a chef thinks about the safety checklist run before service. The checklist does not exist because disasters happen every night. It exists because the cost of one disaster is higher than the cost of the checklist. A register works the same way. Writing down that your chatbot could state the wrong opening hours takes about a minute. Discovering it because a customer drove across town on a Monday costs considerably more than a minute, and the cost lands on your reputation rather than your calendar.
The word "register" makes it sound like something only large companies need, with a risk officer and a board pack behind it. Strip that association away. In a small business the register is one tab in a spreadsheet you already have open, and the person who maintains it is you. What makes it valuable is not its formality but the fact that the thinking happens before the incident rather than after it.
Why Small Businesses Are More Exposed, Not Less
The smaller your business, the more a single AI mistake can hurt. A big retailer can absorb the cost of a chatbot error: a support team fields the complaints, a policy team issues a correction, and the incident disappears into a rounding error. A twelve-person bookstore cannot absorb the cost of accidentally promising thirty-percent discounts to five hundred newsletter subscribers. There is no reserve to draw on and no department to hand the problem to. The owner honors the coupon, and the margin comes out of the same account that pays the staff.
Emeka's three incidents illustrate the pattern. Each one was small enough to survive and large enough to notice. Wrong opening hours cost him a customer's trust. An unauthorized discount cost him real money he had to hand over. Cost margins pasted into a public tool cost him leverage in a negotiation he had not finished. None of these required a sophisticated attacker or an exotic failure mode. They required an ordinary tool doing an ordinary thing slightly wrong, with nobody having decided in advance who would catch it.
The Five Columns of a Simple Register
You do not need software or a consultant to build this. A spreadsheet with five columns works, and adding more columns usually makes the register less likely to be maintained rather than more useful. Keep it to the minimum that lets you rank the rows and act on the top ones.
- Risk: what could go wrong, described in one sentence. If you cannot say it in one sentence, you probably have two risks.
- AI tool involved: which specific tool creates this risk. Naming the tool is what makes the control actionable later.
- Likelihood (1 to 3): 1 means unlikely, 2 means possible, 3 means it has already happened or came close to happening.
- Impact (1 to 3): 1 is a minor inconvenience, 2 costs money or damages a customer relationship, 3 is serious legal, financial, or reputational harm.
- Control: the specific step you are taking to prevent or reduce this risk, plus the person responsible for checking that it is happening.
The control column is where most registers fail. A control written as "be careful with customer data" is not a control, because nobody can tell on a Tuesday afternoon whether it is being followed. A control written as "no vendor pricing or customer personal data goes into a public AI tool, checked by the office manager during the monthly review" is a control, because it names the behaviour, the boundary, and the person who verifies it.
Scoring: Likelihood Times Impact
You prioritize by multiplying likelihood by impact. A score of 9, meaning high likelihood and high impact, goes at the top of your list. A score of 1, low likelihood and low impact, stays at the bottom until the higher-priority risks are addressed. This is deliberately crude arithmetic. Its purpose is not precision; it is to force a comparison between risks that would otherwise all feel equally urgent at the moment you happen to be thinking about them.
Add a control for every row that scores 4 or higher. Rows below that threshold stay on the register without a control attached, which is a legitimate outcome rather than a failure. Writing a risk down and deciding not to act on it yet is a decision, and a recorded decision is worth far more than an unrecorded worry. When something on the low end almost happens, you raise its likelihood score, it crosses the threshold, and it earns a control.
The Seven AI Risks Every Small Business Should Log
Start your register with these seven categories, then add rows specific to your business as you go. They are not exhaustive and they are not meant to be. They are the failures that recur across small businesses regardless of sector, which makes them the cheapest possible starting point for a register you are building from nothing.
1. Wrong information reaching customers
AI tools make things up. The behaviour has a name, hallucination: the model generates confident-sounding text that is simply wrong. A chatbot can state incorrect hours, prices, or policies with exactly the same fluency it uses for correct ones, which is what makes the failure hard to spot. The control is to review customer-facing AI output before it goes live. For a chatbot, which answers without you watching, test it monthly by asking ten questions you already know the answers to. That spot check catches drift; it does not certify the chatbot as accurate.
2. Unauthorized commitments
AI-generated marketing copy and emails can promise things your business has not approved: discounts, availability, delivery windows, policies. The model has no way of knowing which offers you are willing to honor, so it writes the offer that reads best. The control is to require a human to approve any AI-written content that makes a specific offer or commitment before it reaches a customer. Note the narrow scope. You are not reviewing every sentence the AI writes, only the sentences that create an obligation you would have to fund.
3. Confidential information shared with AI tools
Employees may paste sensitive information into a public AI tool without realizing the data may be stored or used by the vendor: vendor pricing, customer personal data, payroll figures, proprietary recipes. This is rarely carelessness. It is usually somebody trying to do good work quickly, pasting in the whole document because trimming it first takes time. The control is a written list of information categories that employees are never allowed to paste into public AI tools. Categories, not examples, so that a new case is covered by the rule rather than by a judgement call.
4. AI output used without review
When AI is fast, people skip review. A contract drafted by AI goes out without a legal check. An invoice template auto-filled by AI contains errors that get paid. Speed is exactly the property that makes the tool worth having, and it is exactly the property that erodes the habit of checking. The control is to define which output categories carry financial or legal impact and to require a review step for those before anything leaves your business. Defining the category in advance is what stops the decision being made under time pressure.
5. Tool dependency and downtime
If your AI scheduling tool goes offline on a Saturday, can your business still operate? If the answer is no, you have a dependency risk, and it is one that grows quietly, because a tool becomes load-bearing through daily use rather than through a decision. The control is to document the manual backup process for any AI tool that has become critical to operations, and to make sure at least two people know it. Two people, because the one person who knows the workaround is frequently the person on holiday when it is needed.
6. Bias in AI output affecting customers or hiring
AI writing tools can reflect biases in their training data. That shows up as stereotyping of certain customers, non-inclusive language, or hiring copy that inadvertently discourages protected groups from applying. The control is to spot-check AI-generated hiring ads and customer communications quarterly, using inclusive language guidelines as the review checklist. Treat this as a detection habit rather than a guarantee: a quarterly sample tells you whether a problem exists in the material you sampled, and it is a floor for this risk rather than a ceiling.
7. Staff over-reliance on AI judgment
When employees start treating AI output as authoritative rather than as a draft to improve, quality degrades and mistakes compound, because each unreviewed output becomes the input to the next task. The control is cultural rather than procedural, and it belongs in training: every AI output is a starting point, not a final answer, and someone who knows the business makes the final call. This is the risk most likely to be missing from a register, because unlike the other six it never produces a single dramatic incident you can point at.
Building Your Register in One Hour
Block sixty minutes. Open a spreadsheet. Add the five columns. Then go through every AI tool you currently use and ask one question of each: what could go wrong with this tool in my specific business? Write each answer as a row. Score likelihood and impact from your own experience rather than from a general sense of how risky AI is. Then add a control for every row scoring 4 or higher. An hour is enough because the hard part is not the writing, it is the deciding, and the seven categories above have already done most of the deciding for you.
Emeka's finished register had eleven rows. The three highest-scoring were the ones he had already lived through, which is common: the first register you write is largely a record of the last quarter. For each one he documented a specific control and assigned one person responsible for checking it monthly, because a control without a name attached to it is an intention.
| Risk | Likelihood | Impact | Score | Control |
|---|---|---|---|---|
| Chatbot gives wrong business hours | 3 | 2 | 6 | Monthly test of ten questions with known answers |
| AI-written content makes an unauthorized commitment | 2 | 3 | 6 | Human approval before any specific offer reaches a customer |
| Employee shares cost data with a public AI tool | 2 | 3 | 6 | Written do-not-paste list of information categories |
A risk register does not eliminate AI mistakes. It ensures you have thought about which ones would hurt you most, and done something about those first.
Keeping Your Register Current
Review your register when you add a new AI tool, when something goes wrong, and on a quarterly schedule regardless of whether anything has happened. Add new rows as you identify new risks. Raise a likelihood score when a risk almost happens, because a near miss is evidence and should move the number. Adjust a control when the control proves ineffective, which you will only discover by checking whether the control was actually performed rather than whether it was written down.
The register is a living document, not a one-time exercise. Most small businesses can maintain it in thirty minutes per quarter. That is two hours a year to protect a business you have spent years building, and the maintenance is what separates a register from a document somebody wrote during an enthusiastic afternoon and never opened again.
Anti-Patterns
These failure modes turn a register from a working control into paperwork. Each is easy to fall into because it looks like diligence.
- Treating the monthly ten-question chatbot test as proof of accuracy. The test samples ten answers out of everything the chatbot will say that month. A clean result tells you the bot has not drifted on the things you checked. It is a tripwire, not a certificate, and it belongs alongside the review of customer-facing output rather than in place of it.
- Writing controls nobody can verify. "Be careful," "use good judgement," and "review as needed" cannot be checked, so they cannot fail visibly, so they never get fixed. Every control needs an observable action and a named person.
- Scoring risks by how frightening they sound. The dramatic scenario usually scores low on likelihood, and the boring one, an employee pasting a price list into a public tool, scores high on both. The multiplication exists to override your instincts, so let it.
- Building the register once and never touching it. An unmaintained register is worse than none, because it creates the impression that the risks were handled. If the quarterly review does not happen, the document is describing the business you had last year.
- Listing risks without naming the tool. "AI might produce something wrong" cannot be controlled. "The website chatbot might state the wrong opening hours" can be, because a specific tool has a specific place where a check can be inserted.
Practice Prompts
Use these with your own AI assistant to draft a first version of the register, then edit it against what you actually know about your business. The AI is useful for generating candidate rows and useless for scoring them, because only you know what has almost happened.
- Inventory prompt: "I run a [type of business] with [number] employees. We currently use these AI tools: [list each tool and what it is used for]. For each tool, list the ways it could cause a problem in a business like mine. Write each one as a single sentence describing the failure, not the solution."
- Control drafting prompt: "Here is a risk from my AI risk register: [paste the one-sentence risk]. Suggest three possible controls. For each, state the specific action, how often it happens, and who in a small business would realistically perform it. Do not suggest controls that require software we would have to buy."
- Do-not-paste list prompt: "Help me write a list of information categories that employees at my [type of business] should never paste into a public AI tool. Give categories rather than examples, so that new cases are covered by the rule. Keep it short enough to fit on one page next to a workstation."
Reflection
Work through these before you open the spreadsheet. The answers are the raw material for your first rows.
- Which AI tool in your business would you least like to explain to a customer if it got something wrong in public?
- What has almost gone wrong in the last quarter that you have not written down anywhere? Near misses belong on the register at a raised likelihood score.
- For each control you are about to write, who checks it, and how would you know this month whether they did?
- If an employee pasted something sensitive into a public tool tomorrow, would they know they had done something wrong, or would they find out from you afterwards?
Glossary
- Risk register: a table listing each way your AI tools could cause a problem, with a likelihood score, an impact score, and the control you have put in place.
- Hallucination: an AI system generating confident-sounding output that is factually wrong, delivered with the same fluency as correct output.
- Likelihood: how probable a risk is, scored here from 1 for unlikely to 3 for already happened or close to happening.
- Impact: how much harm the risk would do, scored from 1 for a minor inconvenience to 3 for serious legal, financial, or reputational harm.
- Risk score: likelihood multiplied by impact, used to rank rows so that prevention effort goes to the top of the list first.
- Control: the specific, checkable step taken to prevent or reduce a risk, together with the person responsible for performing it.
- Dependency risk: the exposure created when a tool has become essential to daily operations without a documented manual fallback.
Related Lessons
- Privacy-Preserving Data Handling covers the information categories that belong on your do-not-paste list.
- AI Policy Documentation for Small Businesses turns the controls in your register into a written policy staff can follow.
- Incident Response Planning for AI Failures takes over at the point where a control has failed and something has already gone wrong.
- Vendor Risk Assessment for AI Tools addresses the risks that come from the tool provider rather than from how your team uses the tool.
- Bias Auditing and Fairness in AI Systems goes deeper on the sixth risk category, including what a quarterly spot check can and cannot tell you.
Closing
Emeka did not build his register because he was worried about AI in the abstract. He built it after three ordinary weeks produced three avoidable problems. What changed afterwards was not that he trusted his tools less; it was that he knew which of the eleven rows would actually hurt the bookstore, and he had named a person to check each one. That is the return on an hour of spreadsheet work.
Key Takeaways
- A risk register is a simple table, not a corporate document. It lists what could go wrong with each AI tool, how serious it would be, and what you are doing about it.
- Small businesses are more exposed to AI errors than large ones. A single mistake, whether wrong pricing, a wrong policy, or leaked cost data, hits harder when there are fewer resources to absorb it.
- Score risks by multiplying likelihood by impact, each rated 1 to 3. Add a control for every row scoring 4 or higher and let the arithmetic override your instincts about which risks feel urgent.
- Seven categories cover most small-business AI risk: wrong information to customers, unauthorized commitments, sensitive data in public tools, output used without review, tool dependency, bias in outputs, and staff over-reliance on AI judgment.
- Every high-scoring risk needs a named control. A specific action, performed on a stated cadence, by a specific person who can be asked whether they did it.
- Build the register in one hour by going through each tool you use and asking what could go wrong with it in your specific business.
- Review quarterly and after every AI incident. Thirty minutes four times a year, roughly two hours annually, is the maintenance cost of keeping the register true.
Frequently Asked Questions
Is a risk register overkill for a business with fewer than ten employees?
The register scales down to whatever your business is. With three tools and four staff you may end up with five or six rows, which is a fine register. The argument for doing it at a small scale is that a small business has less capacity to absorb a mistake, not more, so the ranking exercise matters more rather than less.
What score means I have to act immediately?
Add a control for anything scoring 4 or higher, and work down from the top of the list. A 9 means high likelihood combined with high impact, which is the row to handle first. Below 4 the row stays on the register without a control until something changes its score.
What if a risk does not fit any of the seven categories?
Add a row. The seven categories are a starting point drawn from what recurs across small businesses, not a fixed taxonomy. A risk specific to your sector or your tool stack is exactly the kind of row a general checklist cannot give you, and it usually scores higher than the generic ones because it is grounded in your actual operations.
Who should own the register in a small business?
Ownership of the register usually sits with the owner or whoever makes tool purchasing decisions, because that person can change a control when it is not working. Individual controls can be assigned to different people. What matters is that each control names one person rather than a team, so nobody assumes somebody else performed the check.
How is this different from an AI use policy?
The register is your ranked list of what could go wrong and what you are doing about it. A policy is the set of rules staff are expected to follow, which typically comes out of the controls in the register. In practice you build the register first, because the policy is easier to write once you know which risks are the ones worth writing rules about.
Skill.re