Lesson 13 / 26
The AI Risk Register
Score risks by likelihood times impact and assign owners and mitigations.
Likelihood times impact
A risk register lists each risk with a likelihood (1 to 5), an impact (1 to 5), the product as a score, an owner, and mitigations. Typical AI risks: wrong or invented outputs, privacy leaks, biased outcomes, security attacks such as prompt injection, vendor dependence or outage, model changes that alter behaviour, legal or regulatory breach, reputational harm, and over-reliance by staff. Review the register regularly, because new data, new features and new rules change the scores.
Name it, score it, treat it
Risk management turns vague worries into a ranked list with owners and actions.
Ranking a register, run
I ran this. A rare but severe biased outcome (likelihood 3, impact 5) scores 15 and tops the list, ahead of the more frequent hallucination (12).
risks = [("Hallucinated answer sent to customer", 4, 3),
("PII leak via logs", 2, 5),
("Vendor outage", 3, 2),
("Biased outcome", 3, 5)]
def band(s): return "HIGH" if s >= 15 else "MEDIUM" if s >= 8 else "LOW"
for name, l, i in sorted(risks, key=lambda r: -r[1] * r[2]):
print(l * i, band(l * i), name)
Output:
15 HIGH Biased outcome 12 MEDIUM Hallucinated answer sent to customer 10 MEDIUM PII leak via logs 6 LOW Vendor outage
Treat high scores first, but look at impact
Multiplying can hide a rare catastrophic risk behind frequent small ones. Give any very high-impact risk (impact 5) special attention regardless of its likelihood score.
Quick check: How is a risk score computed in a simple register?
- Likelihood plus cost
- Likelihood multiplied by impact
- The number of users
- The model size
Answer
Likelihood multiplied by impact — The product ranks risks so effort goes where expected harm is greatest.