The #1 Mistake in AI Risk Management
People treat AI risk management like traditional IT or cyber risk: write a policy, buy a scanner, call it done. That fails fast. The real starter failure is an incomplete inventory – especially shadow AI. You can’t Map, Measure, or Manage what you don’t know exists.
Reverse the order. Start with discovery and a living register. Then apply the NIST functions lightly. This works for a solo founder using ChatGPT daily or a small team shipping an internal bot. Skip the full enterprise GRC theater until you need it.
Quick Context: Why AI Risks Behave Differently
AI fails probabilistically. Outputs drift. Hosted models hide data paths. Generative tools invent answers with a straight face. NIST’s AI RMF 1.0 (January 2023) stays voluntary on purpose: four ongoing functions – Govern, Map, Measure, Manage – not a one-time audit checklist. The July 2024 Generative AI Profile (NIST AI 600-1) calls out 12 risks GenAI creates or worsens. Confabulation – confidently stated false content – is usually the first one small teams actually feel.
Need a certifiable management system later? ISO/IEC 42001:2023 is the AIMS route. Selling or deploying high-risk uses in the EU? Article 9 still wants continuous risk management; 2026 amendments deferred some high-risk clocks (examples cited in analyses run into 2027-2028). As of late 2026, NIST also flags AI RMF 1.0 itself under revision for the White House AI Action Plan. Put the document date on whatever you adopt.
Hands-On: Build Your AI Risk Register in Four Steps
Shared spreadsheet is enough. Timebox the first pass to one afternoon.
1. Discover everything (Map first)
Run a short no-penalty amnesty. Ask every person: what AI tools, plugins, browser extensions, embedded features (Notion AI, Salesforce Einstein, coding assistants), APIs, or agents do you use for work? What data goes in?
Add technical signals: OAuth grants, expense lines for AI subs, browser extension lists, SaaS logs if you have them. Personal accounts used for company tasks belong on the list – they’re the loudest leakage path.
- Tool name + provider
- Owner (named human)
- Purpose / use case
- Data classes touched (PII, code, customer, financial, none)
- Account type (corporate, personal, API key)
- Approval status (unknown / sanctioned / restricted)
IBM’s 2025 Cost of a Data Breach reporting (widely cited in industry roundups; confirm against the current IBM release) put high shadow-AI environments about $670k above average breach cost. You can’t control a row you never wrote down.
Think of the register like a home key inventory. The fancy alarm does nothing if a spare still sits under the mat – and half your “AI stack” is usually still under the mat.
2. Score each entry simply
Likelihood 1-5. Impact 1-5. Multiply. Sort descending. Rank first the high scores that touch sensitive data or decisions people will act on.
| Factor | 1 (low) | 3 | 5 (high) |
|---|---|---|---|
| Likelihood | Internal only, no tools, rare use | Team tool, occasional external calls | Public chatbot + sensitive paste, always-on agent |
| Impact | Drafting internal notes | Customer-facing content | Hiring, credit, medical, legal output, IP code |
Tag NIST AI 600-1 hits when you see them: confabulation, data privacy leakage, information security (prompt-injection surface), intellectual property, value-chain / third-party components.
3. Apply light controls (Measure + Manage)
Top rows only – don’t boil the ocean.
- Ground outputs – RAG or source citations for factual claims that matter.
- Human review gate on high-impact uses. No auto-send of AI text to customers or regulators without a named checker.
- Data rules: never paste secrets, full customer records, or unreleased code into public models. Use enterprise/API tiers whose current terms say they don’t train on your inputs (terms move – recheck).
- Log prompts/outputs where feasible for later audit.
- Residual-risk acceptance: who signs that the leftover risk is okay?
Pro tip: Treat confabulation as calibration, not a single accuracy score. Count confidently wrong answers. Surface uncertainty on anything that can cause real harm.
Park the control next to the risk row. Revisit quarterly or after a major model/provider change.
4. Close the Govern loop
One named owner for the whole register. Three rules max: approved tools, data that never leaves, review cadence. NIST’s Playbook has optional action lists if you outgrow the one-pager. Short enough that people read it – or it doesn’t exist.
Common Pitfalls to Avoid
One-time inventory. New embedded features show up weekly. Discovery has to stay living.
Policy with no sanctioned path. Blanket bans on public AI tools backfire; work slides onto personal phones and accounts, and you lose the little visibility you had.
Value-chain blind spot. Foundation-model API risk lives mostly in vendor controls and your contract, not your application code. Ask for evidence. Marketing pages aren’t control descriptions.
Accuracy-only metrics. Users act on confidently false outputs. Standard “% correct” misses that.
What Good Looks Like (Results)
Two weeks in, does anyone still answer “what AI do we run?” with a shrug? That’s the real maturity test – not a glossy framework diagram.
A complete-enough register with owners. Top five risks scored and controlled. A one-page acceptable-use note. A calendar ping for the next review. Teams that finish this stop the worst leakage early and can answer the inventory question in under five minutes. Same artifact becomes evidence later if you chase ISO 42001 or EU high-risk compliance – you won’t start from zero.
When Not to Use This Lightweight Approach
Building or deploying EU AI Act high-risk systems (recruitment, credit, medical devices, critical infrastructure – check current Annexes and deferred dates)? Spreadsheet-only won’t carry Article 9 continuous management, defined-metric testing, or conformity assessment. Foundation-model providers under systemic-risk duties: step up. Pure personal hobby, no sensitive data, no external decisions – even this may be excess. Still don’t paste secrets.
FAQ
Do I need the full NIST AI RMF on day one?
No. Map plus a simple score is enough to start. Grow Govern and deeper Measure only as the register grows – the framework is voluntary.
What’s the fastest way to cut confabulation risk in a customer chatbot?
Retrieve from your own verified docs, force citations, add an “I don’t know” path, and require human review before high-stakes replies. Red-team with prompts that push for made-up policies. Skip that stack and you get the classic failure mode: invented refunds, invented advice, real money or trust gone.
How does this relate to ISO 42001 or the EU AI Act?
Inventory rows and residual-risk sign-offs are the core artifact both regimes expect to see behind the paperwork. ISO 42001 wants an AI management system with assessment and lifecycle controls; EU Article 9 for high-risk uses wants continuous identification, evaluation, mitigation, and testing. This lightweight loop won’t satisfy an auditor alone, but it gives ownership and evidence so you’re not inventing the system during the audit window. Recheck application dates – they have already moved once.
Next action: Open a blank sheet. List every AI tool you personally used this week for work. Data types. Owner. First Map row. Expand tomorrow.