AI risk assessment template for small and mid-size teams
✳By Hero Published Oct 9, 2026 · Updated Oct 9, 2026
The useful detailsAn AI risk assessment is a short, written review of each AI tool your organization uses: what information goes into it, what could go wrong, how likely and how bad that would be, who owns the risk, and which control brings it down. This page gives you a one-page AI risk register, a 20-question AI vendor risk assessment questionnaire scored green, amber or red, and the Canadian privacy checks to add. It's a practical assessment you can run in an afternoon. It is not a certified audit, a SOC 2 report, an ISO certification or a penetration test.
What an AI risk assessment covers (and what it doesn't)
A useful AI risk assessment answers five questions for every tool and use: what is it for, what data touches it, what could go wrong, who owns it, and what are we doing about it. That's the same shape the big frameworks use. The NIST AI Risk Management Framework organizes the work into four functions, Govern, Map, Measure and Manage, and notes that its actions "do not constitute a checklist" and can be selected to suit an organization's resources (NIST AI RMF Core). This template is a small-team version of the Map and Manage steps.
What it won't do:
Certify anything. If a client or regulator needs a certification, that's a different engagement with an accredited body.
Test the vendor's security. You're reviewing what the vendor documents and contracts for, not probing their systems.
Replace legal advice. The Canadian checks below tell you which questions to ask, not the answers for your situation.
You can't rate what you haven't found. Before opening the register, list each AI tool in use, on which account type (personal or business), and the tasks people use it for. One tool can carry several uses with different risks: drafting marketing copy in ChatGPT is not the same risk as summarizing a client file in it.
If you don't have that list yet, start with the anonymous survey in our guide to finding shadow AI, then record what you find with our guide to AI tools and connected apps. Personal accounts used for work are the usual blind spot; how each vendor treats them is set out in does AI train on your data?
The one-page AI risk register
Copy this table into a spreadsheet, or download the AI risk register as a CSV that opens in Excel or Google Sheets. Use one row per tool-and-use. The example rows are fictional.
Tool and use
Account
Data class
Likelihood (1–3)
Impact (1–3)
Score
Owner
Current control
Next action
Canadian check
Review by
ChatGPT: drafting client emails
Personal Plus accounts
Confidential (client names, matter details)
3
3
9
Operations lead
None written
Move to a business workspace; ban client details in personal accounts today
PIPEDA processor terms needed
2 weeks
Copilot Chat: summarizing internal policy drafts
Work (Entra) account
Internal
2
1
2
IT admin
Enterprise data protection on work sign-in
Confirm staff sign in with work accounts
None beyond policy
6 months
AI meeting note-taker joining client calls
Free plan, connected to calendar
Confidential and personal
3
3
9
Owner
None
Disconnect from calendars; decide on an approved tool
Consent of call participants; data location
1 week
AI screening of job applicants (through recruiter)
Recruiter's system
Personal
2
3
6
HR lead
Recruiter contract only
Ask the vendor questionnaire below; add disclosure
Ontario job-posting disclosure; Quebec s.12.1 if decisions are automated
1 month
How to fill each column:
Data class. Use four levels: Public (already on your website), Internal (no harm if leaked, but not public), Confidential (client, contract, financial or strategy information), Personal (anything about an identifiable person). A row takes the highest class that appears.
Likelihood. 1 = unlikely in the next year; 2 = could plausibly happen; 3 = already happening or very likely (for example, staff are already pasting this data into a personal account).
Impact. 1 = minor embarrassment or rework; 2 = a client complaint, a contract issue or notable cost; 3 = a privacy breach that may need reporting, a lost client, or a decision about a person that was wrong and hard to reverse.
Score = likelihood × impact. 6 to 9: act this month and name a deadline. 3 to 4: fix within the quarter. 1 to 2: accept and review at the next cycle.
Owner. One named person, not "IT" or "everyone". The owner decides whether the risk is accepted.
Next action. A specific change: move to a business plan, switch a setting, add a policy line, stop the use. NIST's Manage function lists the four standard responses: mitigate, transfer, avoid or accept.
The 20-question AI vendor risk assessment questionnaire
Use this before approving a new tool, and once a year for tools you keep. Most answers are in the vendor's privacy centre, trust page or data processing agreement; email the vendor for the rest. Score each answer: green (meets the bar), amber (partly, or only on a higher plan), red (no, or no answer). The questionnaire is also available as a CSV with an answer column.
#
Question
Green looks like
Data use
1
Is our content (prompts, files, outputs) used to train or improve models by default on the plan we'd buy?
No, in writing, for our plan
2
If feedback buttons send data to the vendor, can an admin switch them off?
Yes, organization-wide
3
Are humans at the vendor able to read our content, and when?
Only for abuse, support with permission, or legal reasons, and documented
4
Do connected apps or plug-ins follow the same terms?
Terms say so, or admins can block third-party connectors
5
Will the vendor sign a data processing agreement?
Yes, standard DPA available
Retention and deletion
6
How long are chats and files kept by default?
A stated period, and admins can shorten it
7
When a user deletes something, how long until it's gone from back-end systems?
A stated period, such as 30 days
8
Can we export and delete all our data when we leave?
Yes, admin-run export and deletion
Access and security
9
Can we enforce sign-in with our own identity provider (single sign-on)?
Yes, on the plan we'd buy
10
Can an admin remove a departing employee's access in one step?
Yes
11
Are there admin audit logs of who used what?
Yes, exportable
12
Does the tool respect existing file permissions when it reads our documents?
Yes, documented
13
Does the vendor publish independent security reports or attestations we can review?
Yes, available under NDA or publicly
Location and transfers
14
Where is our data stored and processed?
Stated regions, ideally selectable
15
Which subprocessors handle our data, and are we told about changes?
Published list with change notices
16
Does the contract give our data comparable protection when it's processed outside Canada?
Contractual commitments in the DPA
Outputs and accountability
17
Does the tool show sources or let users check where an answer came from?
Citations or source links where relevant
18
Is the tool used to make or recommend decisions about people (hiring, pricing, eligibility)?
No; or yes with human review and an explanation process
19
Can we switch specific features off (web search, image generation, agents, memory)?
Yes, admin controls
20
Who at the vendor do we contact for a security or privacy incident, and how fast do they notify us?
Named channel and stated notification commitment
Reading the result. Any red on questions 1, 5, 7, 14 or 16 means the tool shouldn't touch personal or confidential information until it's fixed, usually by moving to a business plan. Three or more ambers elsewhere: approve for public and internal data only, and revisit in six months. All green: approve, record it in the register, and still keep the never-enter list in your AI use policy.
The Canadian columns: PIPEDA, Quebec Law 25 and Ontario
Most templates online are written for the EU or the US. These are the Canadian checks to add to the "Canadian check" column. This is general information, not legal advice.
PIPEDA: you stay accountable for what you send to a processor. An organization remains responsible for personal information it transfers to a third party for processing, and must use contractual or other means to provide a comparable level of protection while the third party has it (OPC, Guidelines for processing personal data across borders). In the register, this is why a business plan with a DPA scores better than a personal account.
Federal privacy principles for generative AI. Canada's privacy commissioners expect organizations to know their legal authority for collecting and using personal information in generative AI, and point to privacy impact assessments as a key protective measure (OPC, generative AI principles).
Quebec: a privacy impact assessment before data leaves the province. Under Quebec's private-sector privacy act (as amended by Law 25), an enterprise must conduct a privacy impact assessment before communicating personal information outside Québec, including when it entrusts a person outside Québec with keeping or using that information on its behalf, and the communication needs a written agreement (P-39.1, s. 17). Many AI tools process data outside Québec, so if you hold Quebecers' personal information, check where each tool processes it.
Quebec: a privacy impact assessment for new systems. The same act requires one for any project to acquire, develop or overhaul an information system involving personal information, proportionate to the sensitivity of the data (s. 3.3).
Quebec: decisions made only by automated processing. If you use personal information to make a decision based exclusively on automated processing, you must tell the person no later than when you tell them the decision, explain the main factors on request, and let them submit observations to someone who can review it (s. 12.1).
Ontario: AI in job postings. Since January 1, 2026, Ontario employers with 25 or more employees must state in publicly advertised job postings whether AI is used to screen, assess or select applicants (Ontario). Flag any hiring row in the register.
Ontario: electronic monitoring policy. Employers with 25 or more employees on January 1 must have a written policy on whether and how they electronically monitor employees (Ontario). If you plan to review AI usage logs, it belongs there.
A risk register is right for tools staff use to draft, summarize and analyze. When an AI system makes or recommends decisions about people, such as who gets hired, approved or prioritized, you need a deeper AI impact assessment.
The Government of Canada's Algorithmic Impact Assessment is a good model. It's mandatory for federal institutions under the Treasury Board's Directive on Automated Decision-Making, not for private businesses, but it's openly licensed and shows what a thorough review asks: 65 risk questions and 41 mitigation questions across the project, system, algorithm, decision, impact and data, producing an impact level from I (little to no impact) to IV (very high impact). Borrow its impact section if a register row involves decisions about individuals.
How this template maps to NIST AI RMF and ISO/IEC 42001
If a client asks which framework your assessment follows, here's the honest mapping.
This template
NIST AI RMF 1.0
ISO standards
Tool and use list
Map: context is established; Govern 1.6, AI systems inventoried
ISO/IEC 42001: an AI management system covers AI you develop, provide or use
Data class, likelihood, impact, score
Map 5: likelihood and magnitude of impacts characterized
ISO/IEC 23894: guidance on AI risk management
Owner and review date
Govern 2: accountability structures
ISO/IEC 42001: Plan-Do-Check-Act and continual improvement
Next action
Manage 1.3: mitigate, transfer, avoid or accept
ISO/IEC 42001: from risk assessment to treatment of the risks
Vendor questionnaire
Govern 6 and Manage 3: third-party risks
ISO/IEC 42001: written for organizations that use AI products, not only builders
For generative AI tools, NIST's Generative AI Profile (NIST AI 600-1) lists 12 risks that are unique to or made worse by generative AI, including confabulation, data privacy, information security, intellectual property and value chain and component integration; it's a good prompt list for the "what could go wrong" conversation. ISO/IEC 42001 is a management system standard that organizations can be certified against; using a template like this one is a step toward that kind of discipline, not a substitute for certification.
Run it in 90 minutes
Gather (15 min). The tool list, the account types, and one person from each team who uses AI most.
Fill the register (40 min). One row per tool-and-use. Argue about likelihood and impact out loud; the disagreement is where the useful information is.
Score the vendors (20 min). Run the questionnaire for any tool scoring 6 or more. Mark unknowns red until someone confirms them.
Decide (15 min). Every row gets an owner, a next action and a review date. Write the top three actions in an email to the whole team the same day.
Then put a reminder in the calendar: review the register every six months, and whenever a new tool or a new use is proposed.
FAQ: AI risk assessment template
Is there an Excel version of this AI risk assessment template?
Yes. Both the risk register and the vendor questionnaire download as CSV files that open in Excel or Google Sheets. Set the score column to likelihood × impact.
What's the difference between an AI risk register and an AI impact assessment?
A risk register tracks risks for every tool and use in one place and is updated over time. An impact assessment goes deep on a single system, usually one that makes or supports decisions about people, and asks who could be harmed and how.
Who should own the AI risk assessment in a small business?
One named person with authority to say no, often the owner, an operations lead or whoever is responsible for privacy. In Quebec, the person exercising the highest authority in the enterprise is by default the person in charge of the protection of personal information.
How often should we redo it?
Every six months, plus whenever someone proposes a new tool, a new use of an existing tool, or a vendor changes its terms or plans.
Does completing this make us compliant with PIPEDA or Law 25?
No single document does. It shows you've identified the risks and assigned actions, which supports accountability, but compliance depends on what you then do, your contracts and your specific obligations.
Where Hero fits
If you'd rather have someone run it with you, Hero's AI security assessment, from C$1,500, covers the same ground with your team: which tools and accounts are really in use, the AI settings in Microsoft 365 or Google Workspace, where sensitive information goes, and a ranked list of what to fix first. It's a practical assessment, not a certification. If the bigger question is which AI uses are worth the risk at all, start with an AI Readiness Assessment, from C$1,500, or the free AI Readiness Score.
Sources checked (October 9, 2026): NIST, AI RMF 1.0 Core (AIRC) and Generative AI Profile, NIST AI 600-1 (July 26, 2024) · ISO, ISO/IEC 42001:2023 · Government of Canada, Algorithmic Impact Assessment · OPC, Guidelines for processing personal data across borders and Principles for responsible, trustworthy and privacy-protective generative AI technologies · LégisQuébec, P-39.1, Act respecting the protection of personal information in the private sector, ss. 3.1, 3.3, 12.1 and 17 · Ontario, Your guide to the Employment Standards Act: publicly advertised job postings, and written policy on electronic monitoring.
A CLEAR NEXT STEP STARTS HERE
Find out what your team already puts into AI.
A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.