01

Register workflows, not AI in the abstract

A single AI tool can draft marketing copy, summarize private documents, screen applicants or answer customer questions. Those uses carry different consequences even when they use the same model. A useful risk register therefore begins with the workflow: intended purpose, inputs, outputs, affected people, decision owner and the action that follows.

This approach keeps governance proportional. A reversible internal draft can have a light review. A public claim, sensitive-data workflow or decision affecting access to employment, health, finance or legal support needs narrower authority, stronger testing and an accountable human able to stop the process.

The unit of AI governance is the real workflow and its consequences—not the novelty of the model.
02

Map data and affected people before the prompt

Record whether the workflow uses public, internal, confidential, personal or sensitive information. Note where prompts and outputs are stored, whether a vendor may use them for training, who can access logs, how long data is retained and how deletion works. If personal information is unnecessary, do not add it merely because the tool can accept it.

The Office of the Privacy Commissioner of Canada advises businesses using generative AI to establish authority for personal-information use, be transparent, limit sharing of personal or confidential information and build privacy safeguards into the system. Its broader principles also emphasize necessity, proportionality, accuracy and attention to significant impacts. The register turns those questions into a pre-deployment gate rather than an afterthought.

03

Describe plausible failure modes

Avoid a generic risk label such as hallucination. Describe what failure looks like in the workflow: an unsupported public claim, disclosure of confidential data, unfair exclusion, stale recommendation, prompt injection, unauthorized action, missing source, incorrect calculation or silent automation failure. Then record who could be affected and whether the harm is reversible.

Score likelihood and impact using a simple documented scale. The number is not scientific certainty; it helps the team prioritize controls and decide whether the residual risk is acceptable. High-consequence workflows should not pass merely because a demo looked accurate.

  • Evidence risk: the output cannot be traced to reliable, current sources.
  • Privacy and confidentiality risk: data is unnecessary, over-shared, retained or exposed.
  • Fairness and access risk: errors or design choices burden a person or group unevenly.
  • Security and agency risk: the system can retrieve, change or send more than the workflow requires.
  • Operational risk: the workflow fails silently, cannot be monitored or lacks a manual fallback.
  • Reputation and disclosure risk: users misunderstand the AI's role or the organization's accountability.
04

Match controls to the consequence

Controls should be testable. Examples include approved data classes, source requirements, structured output validation, restricted tool permissions, representative test cases, human approval, dual review for high-impact actions, audit logs, rate limits, content labels, monitoring thresholds and a manual fallback. Name the person who owns each control.

Human review only works when the reviewer has enough context and authority to reject the output. A hurried click on approve is not a control. Define what evidence the reviewer sees, what must trigger escalation and which decisions AI is never allowed to finalize.

05

Approve, monitor and know how to stop

The register should end with a decision: approve, approve with conditions, pilot only, redesign or do not deploy. Record residual risk, evidence, owner, review date and rollback steps. Material changes to the model, prompt, data, integrations, permissions, audience or purpose should trigger a new review even when the calendar date has not arrived.

After launch, monitor the failures that matter to the workflow: unsupported-output rate, correction rate, privacy incidents, escalation frequency, override rate, latency, cost and user complaints. The downloadable register provides a workflow intake, risk matrix, control plan, approval record, incident log and change-review checklist sized for a small operating team.

Sources

References and scope

This register is an educational operating tool, not legal, privacy, employment, security or regulatory advice and not a certification. Applicable requirements depend on the organization, sector, province, data and use case.

  1. AI, privacy, and your businessOffice of the Privacy Commissioner of Canada
  2. PIPEDA fair information principlesOffice of the Privacy Commissioner of Canada
  3. Guidelines for obtaining meaningful consentOffice of the Privacy Commissioner of Canada
  4. Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI SystemsInnovation, Science and Economic Development Canada
  5. AI Risk Management Framework CoreU.S. National Institute of Standards and Technology