Security · Hero

AI risk assessment template for small and mid-size teams

The useful detailsAn AI risk assessment is a short, written review of each AI tool your organization uses: what information goes into it, what could go wrong, how likely and how bad that would be, who owns the risk, and which control brings it down. This page gives you a one-page AI risk register, a 20-question AI vendor risk assessment questionnaire scored green, amber or red, and the Canadian privacy checks to add. It's a practical assessment you can run in an afternoon. It is not a certified audit, a SOC 2 report, an ISO certification or a penetration test.

What an AI risk assessment covers (and what it doesn't)

A useful AI risk assessment answers five questions for every tool and use: what is it for, what data touches it, what could go wrong, who owns it, and what are we doing about it. That's the same shape the big frameworks use. The NIST AI Risk Management Framework organizes the work into four functions, Govern, Map, Measure and Manage, and notes that its actions "do not constitute a checklist" and can be selected to suit an organization's resources (NIST AI RMF Core). This template is a small-team version of the Map and Manage steps.

What it won't do:

  • Certify anything. If a client or regulator needs a certification, that's a different engagement with an accredited body.
  • Test the vendor's security. You're reviewing what the vendor documents and contracts for, not probing their systems.
  • Replace legal advice. The Canadian checks below tell you which questions to ask, not the answers for your situation.

Free downloadSetting rules for your team? Start from the free one-page AI use policy template.

Step 1: list every tool and every use

You can't rate what you haven't found. Before opening the register, list each AI tool in use, on which account type (personal or business), and the tasks people use it for. One tool can carry several uses with different risks: drafting marketing copy in ChatGPT is not the same risk as summarizing a client file in it.

If you don't have that list yet, start with the anonymous survey in our guide to finding shadow AI, then record what you find with our guide to AI tools and connected apps. Personal accounts used for work are the usual blind spot; how each vendor treats them is set out in does AI train on your data?

The one-page AI risk register

Copy this table into a spreadsheet, or download the AI risk register as a CSV that opens in Excel or Google Sheets. Use one row per tool-and-use. The example rows are fictional.

Tool and useAccountData classLikelihood (1–3)Impact (1–3)ScoreOwnerCurrent controlNext actionCanadian checkReview by
ChatGPT: drafting client emailsPersonal Plus accountsConfidential (client names, matter details)339Operations leadNone writtenMove to a business workspace; ban client details in personal accounts todayPIPEDA processor terms needed2 weeks
Copilot Chat: summarizing internal policy draftsWork (Entra) accountInternal212IT adminEnterprise data protection on work sign-inConfirm staff sign in with work accountsNone beyond policy6 months
AI meeting note-taker joining client callsFree plan, connected to calendarConfidential and personal339OwnerNoneDisconnect from calendars; decide on an approved toolConsent of call participants; data location1 week
AI screening of job applicants (through recruiter)Recruiter's systemPersonal236HR leadRecruiter contract onlyAsk the vendor questionnaire below; add disclosureOntario job-posting disclosure; Quebec s.12.1 if decisions are automated1 month

How to fill each column:

  • Data class. Use four levels: Public (already on your website), Internal (no harm if leaked, but not public), Confidential (client, contract, financial or strategy information), Personal (anything about an identifiable person). A row takes the highest class that appears.
  • Likelihood. 1 = unlikely in the next year; 2 = could plausibly happen; 3 = already happening or very likely (for example, staff are already pasting this data into a personal account).
  • Impact. 1 = minor embarrassment or rework; 2 = a client complaint, a contract issue or notable cost; 3 = a privacy breach that may need reporting, a lost client, or a decision about a person that was wrong and hard to reverse.
  • Score = likelihood × impact. 6 to 9: act this month and name a deadline. 3 to 4: fix within the quarter. 1 to 2: accept and review at the next cycle.
  • Owner. One named person, not "IT" or "everyone". The owner decides whether the risk is accepted.
  • Next action. A specific change: move to a business plan, switch a setting, add a policy line, stop the use. NIST's Manage function lists the four standard responses: mitigate, transfer, avoid or accept.

The 20-question AI vendor risk assessment questionnaire

Use this before approving a new tool, and once a year for tools you keep. Most answers are in the vendor's privacy centre, trust page or data processing agreement; email the vendor for the rest. Score each answer: green (meets the bar), amber (partly, or only on a higher plan), red (no, or no answer). The questionnaire is also available as a CSV with an answer column.

#QuestionGreen looks like
Data use
1Is our content (prompts, files, outputs) used to train or improve models by default on the plan we'd buy?No, in writing, for our plan
2If feedback buttons send data to the vendor, can an admin switch them off?Yes, organization-wide
3Are humans at the vendor able to read our content, and when?Only for abuse, support with permission, or legal reasons, and documented
4Do connected apps or plug-ins follow the same terms?Terms say so, or admins can block third-party connectors
5Will the vendor sign a data processing agreement?Yes, standard DPA available
Retention and deletion
6How long are chats and files kept by default?A stated period, and admins can shorten it
7When a user deletes something, how long until it's gone from back-end systems?A stated period, such as 30 days
8Can we export and delete all our data when we leave?Yes, admin-run export and deletion
Access and security
9Can we enforce sign-in with our own identity provider (single sign-on)?Yes, on the plan we'd buy
10Can an admin remove a departing employee's access in one step?Yes
11Are there admin audit logs of who used what?Yes, exportable
12Does the tool respect existing file permissions when it reads our documents?Yes, documented
13Does the vendor publish independent security reports or attestations we can review?Yes, available under NDA or publicly
Location and transfers
14Where is our data stored and processed?Stated regions, ideally selectable
15Which subprocessors handle our data, and are we told about changes?Published list with change notices
16Does the contract give our data comparable protection when it's processed outside Canada?Contractual commitments in the DPA
Outputs and accountability
17Does the tool show sources or let users check where an answer came from?Citations or source links where relevant
18Is the tool used to make or recommend decisions about people (hiring, pricing, eligibility)?No; or yes with human review and an explanation process
19Can we switch specific features off (web search, image generation, agents, memory)?Yes, admin controls
20Who at the vendor do we contact for a security or privacy incident, and how fast do they notify us?Named channel and stated notification commitment

Reading the result. Any red on questions 1, 5, 7, 14 or 16 means the tool shouldn't touch personal or confidential information until it's fixed, usually by moving to a business plan. Three or more ambers elsewhere: approve for public and internal data only, and revisit in six months. All green: approve, record it in the register, and still keep the never-enter list in your AI use policy.

The Canadian columns: PIPEDA, Quebec Law 25 and Ontario

Most templates online are written for the EU or the US. These are the Canadian checks to add to the "Canadian check" column. This is general information, not legal advice.

  • PIPEDA: you stay accountable for what you send to a processor. An organization remains responsible for personal information it transfers to a third party for processing, and must use contractual or other means to provide a comparable level of protection while the third party has it (OPC, Guidelines for processing personal data across borders). In the register, this is why a business plan with a DPA scores better than a personal account.
  • Federal privacy principles for generative AI. Canada's privacy commissioners expect organizations to know their legal authority for collecting and using personal information in generative AI, and point to privacy impact assessments as a key protective measure (OPC, generative AI principles).
  • Quebec: a privacy impact assessment before data leaves the province. Under Quebec's private-sector privacy act (as amended by Law 25), an enterprise must conduct a privacy impact assessment before communicating personal information outside Québec, including when it entrusts a person outside Québec with keeping or using that information on its behalf, and the communication needs a written agreement (P-39.1, s. 17). Many AI tools process data outside Québec, so if you hold Quebecers' personal information, check where each tool processes it.
  • Quebec: a privacy impact assessment for new systems. The same act requires one for any project to acquire, develop or overhaul an information system involving personal information, proportionate to the sensitivity of the data (s. 3.3).
  • Quebec: decisions made only by automated processing. If you use personal information to make a decision based exclusively on automated processing, you must tell the person no later than when you tell them the decision, explain the main factors on request, and let them submit observations to someone who can review it (s. 12.1).
  • Ontario: AI in job postings. Since January 1, 2026, Ontario employers with 25 or more employees must state in publicly advertised job postings whether AI is used to screen, assess or select applicants (Ontario). Flag any hiring row in the register.
  • Ontario: electronic monitoring policy. Employers with 25 or more employees on January 1 must have a written policy on whether and how they electronically monitor employees (Ontario). If you plan to review AI usage logs, it belongs there.

A next stepNot sure what your team already puts into AI tools? An AI security assessment finds out. Start with a free 30-minute call.

When you need an AI impact assessment instead

A risk register is right for tools staff use to draft, summarize and analyze. When an AI system makes or recommends decisions about people, such as who gets hired, approved or prioritized, you need a deeper AI impact assessment.

The Government of Canada's Algorithmic Impact Assessment is a good model. It's mandatory for federal institutions under the Treasury Board's Directive on Automated Decision-Making, not for private businesses, but it's openly licensed and shows what a thorough review asks: 65 risk questions and 41 mitigation questions across the project, system, algorithm, decision, impact and data, producing an impact level from I (little to no impact) to IV (very high impact). Borrow its impact section if a register row involves decisions about individuals.

How this template maps to NIST AI RMF and ISO/IEC 42001

If a client asks which framework your assessment follows, here's the honest mapping.

This templateNIST AI RMF 1.0ISO standards
Tool and use listMap: context is established; Govern 1.6, AI systems inventoriedISO/IEC 42001: an AI management system covers AI you develop, provide or use
Data class, likelihood, impact, scoreMap 5: likelihood and magnitude of impacts characterizedISO/IEC 23894: guidance on AI risk management
Owner and review dateGovern 2: accountability structuresISO/IEC 42001: Plan-Do-Check-Act and continual improvement
Next actionManage 1.3: mitigate, transfer, avoid or acceptISO/IEC 42001: from risk assessment to treatment of the risks
Vendor questionnaireGovern 6 and Manage 3: third-party risksISO/IEC 42001: written for organizations that use AI products, not only builders

For generative AI tools, NIST's Generative AI Profile (NIST AI 600-1) lists 12 risks that are unique to or made worse by generative AI, including confabulation, data privacy, information security, intellectual property and value chain and component integration; it's a good prompt list for the "what could go wrong" conversation. ISO/IEC 42001 is a management system standard that organizations can be certified against; using a template like this one is a step toward that kind of discipline, not a substitute for certification.

Run it in 90 minutes

  1. Gather (15 min). The tool list, the account types, and one person from each team who uses AI most.
  2. Fill the register (40 min). One row per tool-and-use. Argue about likelihood and impact out loud; the disagreement is where the useful information is.
  3. Score the vendors (20 min). Run the questionnaire for any tool scoring 6 or more. Mark unknowns red until someone confirms them.
  4. Decide (15 min). Every row gets an owner, a next action and a review date. Write the top three actions in an email to the whole team the same day.

Then put a reminder in the calendar: review the register every six months, and whenever a new tool or a new use is proposed.

FAQ: AI risk assessment template

Is there an Excel version of this AI risk assessment template?

Yes. Both the risk register and the vendor questionnaire download as CSV files that open in Excel or Google Sheets. Set the score column to likelihood × impact.

What's the difference between an AI risk register and an AI impact assessment?

A risk register tracks risks for every tool and use in one place and is updated over time. An impact assessment goes deep on a single system, usually one that makes or supports decisions about people, and asks who could be harmed and how.

Who should own the AI risk assessment in a small business?

One named person with authority to say no, often the owner, an operations lead or whoever is responsible for privacy. In Quebec, the person exercising the highest authority in the enterprise is by default the person in charge of the protection of personal information.

How often should we redo it?

Every six months, plus whenever someone proposes a new tool, a new use of an existing tool, or a vendor changes its terms or plans.

Does completing this make us compliant with PIPEDA or Law 25?

No single document does. It shows you've identified the risks and assigned actions, which supports accountability, but compliance depends on what you then do, your contracts and your specific obligations.

Where Hero fits

If you'd rather have someone run it with you, Hero's AI security assessment, from C$1,500, covers the same ground with your team: which tools and accounts are really in use, the AI settings in Microsoft 365 or Google Workspace, where sensitive information goes, and a ranked list of what to fix first. It's a practical assessment, not a certification. If the bigger question is which AI uses are worth the risk at all, start with an AI Readiness Assessment, from C$1,500, or the free AI Readiness Score.

Related: Does AI train on your data? · How to reduce AI tool sprawl · AI use policy template

Sources checked (October 9, 2026): NIST, AI RMF 1.0 Core (AIRC) and Generative AI Profile, NIST AI 600-1 (July 26, 2024) · ISO, ISO/IEC 42001:2023 · Government of Canada, Algorithmic Impact Assessment · OPC, Guidelines for processing personal data across borders and Principles for responsible, trustworthy and privacy-protective generative AI technologies · LégisQuébec, P-39.1, Act respecting the protection of personal information in the private sector, ss. 3.1, 3.3, 12.1 and 17 · Ontario, Your guide to the Employment Standards Act: publicly advertised job postings, and written policy on electronic monitoring.

A CLEAR NEXT STEP STARTS HERE

Find out what your team already puts into AI.

A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.

Free 30-minute call with our founder · Video call, camera optional