Really Simple AI Risk Framework
Really Simple AI Risk Framework is your go to tool to identify and mitigate AI/ML-specific risks. The AI Risk Register of this framework is carefully curated based on various sources and internal incident learnings of our clients.
AI Lifecycle
Every AI initiative moves through lifecycle stages such as Development, Deployment, Use, and Monitoring. Not every organization develops AI models, but all AI initiatives involve Deployment and Use. Gaps in Monitoring and shadow Deployments are common sources of risk.
- Development: You design or materially change AI behavior (for example, selecting data, training, tuning, evaluation).
- Deployment: You do not build the model, but you integrate, configure, and release AI components into production workflows.
- Use: You consume a deployed AI solution in business operations and make decisions or actions based on its outputs (via chat, CLI, or another interface).
- Monitoring: You track risk, quality, and incidents over time; this is continuous and should run across all other stages.
How to use this framework?
- Check which lifecycle stages are applicable for your initiative. If unclear, run a discovery session with your technical team.
- For the stage(s) your initiative is currently in, consult the register.csv. Stage tags in the risk register indicate where each risk is typically introduced or first exploitable. Several risks span more than one stage and are tagged accordingly.
- For every risk that applies to your system, record: likelihood, impact, an owner, and a mitigation or control. Reference risks by their AIR## ID in your project’s risk log, security review, or audit so findings stay traceable back to this register. “AIR” stands for AI Risk.
Re-check the register at each stage transition (e.g., moving from Development to Deployment) — a risk that was out of scope earlier may now apply.
The AI Risk Register (AIRs)
Treat risk register as a living list: if you identify a risk not represented in register.csv, propose it by creating an issue in this repository, your contribution may help other teams.
| ID | Risk | Lifecycle Stage(s) | Description |
|---|---|---|---|
| Loading risk register from register.csv… | |||
No risks match the selected stage — try a different filter.
Start
Check which lifecycle stages are applicable for your initiative. If unclear, run a discovery session with your technical team.
For the stage(s) your initiative is currently in, consult
register.csv. Stage tags indicate where each risk is typically introduced or first exploitable; several risks span more than one stage.For every risk that applies to your system, record: likelihood, impact, an owner, and a mitigation or control. Reference risks by their AIR## ID so findings stay traceable.
Missing risk in register.csv?
- YesCreate a repository issue with the missing risk.
- NoContinue.
Any new stage transition or newly in-scope risk?
- Yes↶ Back to step 1.
- NoEnd.
End
