Risk Register
The Risk Register is the organization-wide list of things that could go wrong with your AI and cyber estate, scored twice — before controls and after them — so you can prove your control program is actually reducing exposure.
What belongs in the register
Anything with a plausible adverse outcome that you want tracked, owned, and reviewed. In practice that means AI-specific risks (bias, hallucination, prompt injection, model drift, training-data provenance), operational risks (vendor failure, key-person dependency), and cyber risks when Cybersecurity Mode is enabled. Risks raised inside an AI System or Use Case record flow into the same register rather than living in a separate list.
Inherent and residual scoring
Every risk carries two scores on the same 5x5 grid. Inherent is the exposure with no controls operating. Residual is what remains once your mapped controls work as designed. Score is likelihood multiplied by impact, banded into Low, Medium, High, and Critical. Because both scores use the same scale, the difference between them is the measurable benefit of your controls — and a risk where inherent equals residual is a signal that no effective control is mapped.
- Likelihood: 1 (Rare) through 5 (Almost certain).
- Impact: 1 (Negligible) through 5 (Severe).
- Residual can never exceed inherent; the form blocks it.
- Unscored risks appear in the register but are excluded from heatmap totals.
The 5x5 heatmap
The heatmap plots likelihood against impact with a toggle between the inherent and residual views. Each cell shows the count of risks in that position; clicking a cell filters the register beneath it. Switching from inherent to residual should visibly pull the population down and to the left — if it does not, your control coverage has a gap.
Treatment and ownership
- Treatment strategy: Mitigate, Transfer, Avoid, or Accept. Accepted risks require a documented rationale and an accepting authority.
- Owner: a named user accountable for the risk, not a team mailbox.
- Target residual: where you intend the risk to land once treatment completes.
- Review cadence: how often the risk must be revisited; overdue risks surface on the dashboard and in scheduled reports.
- Linked controls: the safeguards claimed to reduce this risk. These drive the crosswalk between the register and your framework coverage.
Linkage to the rest of RAIC
Risks link to AI Systems, Use Cases, Suppliers, and Controls. Those links are bidirectional: opening a system shows its risks, and opening a risk shows what it threatens. PowerGRYD's Gap & Risk Heatmap maps register entries onto pyramid layers, and the AI Maturity Index reads risk coverage as one of its sub-metrics, so keeping the register current improves the accuracy of both.
Reporting and export
- CSV export with dates formatted MM/DD/YYYY HH:MM and a RhindonCyber_ filename prefix.
- Branded DOCX risk report suitable for board and audit-committee packs.
- Heatmap image included in the executive summary and QBR report families.
- Every create, score change, treatment change, and acceptance writes an org-scoped audit entry that is mirrored to the platform audit log.
