Skip to content
Risk matrix templates

Risk Matrix — AI Customer Assistant Risk Register (NIST AI RMF)

An AI risk register for a fictional utility's LLM billing assistant, mapped to NIST AI RMF and EU AI Act transparency duties: across nine failure modes from wrong tariff answers to prompt injection, controls cut exposure from 99 to 45 (−55%) and take the Critical prompt-injection risk to Medium, leaving missed vulnerable-customer handoffs as the one High risk above appetite. Illustrative register.

Template previewRisk matrix
Brightwater Energy — AI billing assistant, AI risk registerLLM assistant answering customer billing questions · mapped to NIST AI RMF and EU AI Act transparency dutiesHEAT MAP · residual position, arrows from inherent11LOWLOW22LOWLOW33LOWLOW44MEDIUMMEDIUM55MEDIUMMEDIUM22LOWLOW44MEDIUMMEDIUM66MEDIUMMEDIUM88HIGHHIGH1010HIGHHIGH33LOWLOW66MEDIUMMEDIUM99HIGHHIGH1212HIGHHIGH1515CRITICALCRITICAL44MEDIUMMEDIUM88HIGHHIGH1212HIGHHIGH1616CRITICALCRITICAL2020CRITICALCRITICAL55MEDIUMMEDIUM1010HIGHHIGH1515CRITICALCRITICAL2020CRITICALCRITICAL2525CRITICALCRITICALAI-06AI-09AI-07AI-03AI-08AI-02AI-04AI-05AI-09AI-01AI-05AI-08AI-01AI-07AI-06AI-03AI-02AI-04Rare1Unlikely2Possible3Likely4Almost certain51Negligible2Minorone customer, quicklyfixed3Moderatemany customers or acomplaint trend4Majorregulator interest5Severeenforcement or massharmLIKELIHOOD →IMPACT →R1residual position (after controls)R1inherent positioneffect of existing controlsappetite boundary · red ring = above it25L×I score and rating bandRISK PROFILE BY BANDInherentResidual (current)Critical1 → 0High7 → 1Medium1 → 6Low0 → 2Low 1–3 · Medium 4–6 · High 8–12 · Critical 15–25EXPOSURE Σ L×I45residual, after current controlsfrom 99 inherent · −55%HIGHEST RESIDUAL RISKAI-01Vulnerable customers are not handed toa human adviser8 · Highowner Head of Customer CareRISK APPETITEMedium or below1 risk above: AI-01Risk register9 risks · sorted by residual rating, then score#IDRISK, CONTROLS AND ACTIONSOWNERINHERENTRESIDUALCHANGESAFETYVulnerable customers are not handed to a human adviserVulnerability classifier with one-click human handoffDaily review of conversations that mention debt or medical equipment→Add domain triggers for life-support equipment and bereavement — due 2027-03 · AI ProductOwner1AI-01Head of CustomerCare3 × 412 · High2 × 48 · HighABOVE APPETITE−4−33%↓ fallingACCURACYAssistant states a wrong tariff, refund or payment-plan policyAnswers grounded on the approved policy library, with citationsRefusal when retrieval confidence is lowWeekly human review of 500 sampled conversations2AI-02AI Product Owner4 × 312 · High2 × 36 · Medium−6−50%ROBUSTNESSVendor model update silently changes behaviourPinned model versions1,200-conversation regression evaluation gates every upgrade3AI-04ML EngineeringLead4 × 312 · High2 × 36 · Medium−6−50%FAIRNESSLower answer quality for Welsh speakers and non-native EnglishQuarterly language-parity evaluation with a 5-point tolerance4AI-05AI Product Owner3 × 39 · High2 × 36 · Medium−3−33%SECURITYPrompt injection exposes another customer's account dataTools scoped to the authenticated account onlyOutput filter for personal dataPrompt-injection red-team suite run in CI5AI-03Head ofApplicationSecurity3 × 515 · Critical1 × 55 · Medium−10−67%PRIVACYPrompts and transcripts retained beyond 30 daysZero-retention agreement with the model providerAutomatic transcript deletion and log redaction at 30 days6AI-07Data ProtectionOfficer3 × 412 · High1 × 44 · Medium−8−67%RESILIENCEModel provider outage during a bill-shock weekFallback to scripted self-service flowsSecond model provider on warm standby7AI-08Head of DigitalChannels3 × 39 · High2 × 24 · Medium−5−56%AGENCYAssistant issues account credits without authorityCredits above £25 require human approvalDaily reconciliation of every assistant-issued credit8AI-06Billing OperationsManager3 × 412 · High1 × 33 · Low−9−75%TRANSPARENCYCustomers are not told they are talking to an AIDisclosure banner and a first-turn statement in every conversation9AI-09Data ProtectionOfficer2 × 36 · Medium1 × 33 · Low−3−50%FINDINGS9 risks rated — inherent 1 Critical, 7 High, 1 Medium; after current controls 1 High, 6 Medium, 2 Low.Total exposure Σ(L×I) falls from 99 to 45 after current controls — a 55% reduction.Controls move 8 of 9 assessed risks into a lower band; 1 keeps its inherent band.1 of 9 risks sits above the Medium appetite on residual rating — AI-01 (High 8); it has a treatment action.Highest residual risk: AI-01 Vulnerable customers are not handed to a human adviser — High 8, owner Head of Customer Care.Controls do most for AI-03: 15 → 5 (−67%).Illustrative register for a fictional utility; failure modes, controls and ratings are examples, not an AI impact assessment.

Make it your own.

title "Brightwater Energy — AI billing assistant, AI risk register"
subtitle "LLM assistant answering customer billing questions · mapped to NIST AI RMF and EU AI Act transparency duties"
likelihood-levels: Rare, Unlikely, Possible, Likely, Almost certain
impact-levels: Negligible, Minor (one customer, quickly fixed), Moderate (many customers or a complaint trend), Major (regulator interest), Severe (enforcement or mass harm)
bands: Low 1-3, Medium 4-6, High 8-12, Critical 15-25
appetite: Medium
note "Illustrative register for a fictional utility; failure modes, controls and ratings are examples, not an AI impact assessment."

risk AI-01 "Vulnerable customers are not handed to a human adviser"
  category: Safety
  owner: Head of Customer Care
  likelihood: 3
  impact: 4
  control "Vulnerability classifier with one-click human handoff"
  control "Daily review of conversations that mention debt or medical equipment"
  residual: 2x4
  action "Add domain triggers for life-support equipment and bereavement" due: 2027-03 owner: "AI Product Owner"
  trend: falling

risk AI-02 "Assistant states a wrong tariff, refund or payment-plan policy"
  category: Accuracy
  owner: AI Product Owner
  likelihood: 4
  impact: 3
  control "Answers grounded on the approved policy library, with citations"
  control "Refusal when retrieval confidence is low"
  control "Weekly human review of 500 sampled conversations"
  residual: 2x3

risk AI-03 "Prompt injection exposes another customer's account data"
  category: Security
  owner: Head of Application Security
  likelihood: 3
  impact: 5
  control "Tools scoped to the authenticated account only"
  control "Output filter for personal data"
  control "Prompt-injection red-team suite run in CI"
  residual: 1x5

risk AI-04 "Vendor model update silently changes behaviour"
  category: Robustness
  owner: ML Engineering Lead
  likelihood: 4
  impact: 3
  control "Pinned model versions"
  control "1,200-conversation regression evaluation gates every upgrade"
  residual: 2x3

risk AI-05 "Lower answer quality for Welsh speakers and non-native English"
  category: Fairness
  owner: AI Product Owner
  likelihood: 3
  impact: 3
  control "Quarterly language-parity evaluation with a 5-point tolerance"
  residual: 2x3

risk AI-06 "Assistant issues account credits without authority"
  category: Agency
  owner: Billing Operations Manager
  likelihood: 3
  impact: 4
  control "Credits above £25 require human approval"
  control "Daily reconciliation of every assistant-issued credit"
  residual: 1x3

risk AI-07 "Prompts and transcripts retained beyond 30 days"
  category: Privacy
  owner: Data Protection Officer
  likelihood: 3
  impact: 4
  control "Zero-retention agreement with the model provider"
  control "Automatic transcript deletion and log redaction at 30 days"
  residual: 1x4

risk AI-08 "Model provider outage during a bill-shock week"
  category: Resilience
  owner: Head of Digital Channels
  likelihood: 3
  impact: 3
  control "Fallback to scripted self-service flows"
  control "Second model provider on warm standby"
  residual: 2x2

risk AI-09 "Customers are not told they are talking to an AI"
  category: Transparency
  owner: Data Protection Officer
  likelihood: 2
  impact: 3
  control "Disclosure banner and a first-turn statement in every conversation"
  residual: 1x3