Skip to main content
Why Your Risk Register Won't Catch What AI ChangesEnterprise Risk Management
4 min readFor Risk Managers

Why Your Risk Register Won't Catch What AI Changes

Risk managers often rely on assumptions that worked when decisions followed predictable patterns. These assumptions falter when AI enters the picture. The myths below persist because they're based on frameworks that predate algorithmic decision-making. Each one limits your ability to manage risk in organizations where AI agents increasingly shape outcomes.

Myth 1: A comprehensive risk register is the foundation of effective risk management

Reality: Your register documents static threats, but risk management exists to support decision-making. ISO 31000 defines risk management as creating and protecting value through uncertainty management in pursuit of objectives. This is not merely a cataloguing exercise.

Grant Purdy, who chaired the committee that developed AS/NZS 4360 (the predecessor to ISO 31000), didn't focus on risk lists when hired to advance programs. He focused on decision-making processes. This distinction matters because decisions are where uncertainty converts to outcomes. If you're maintaining a register without understanding the decision processes it's meant to inform, you're documenting risks that may be irrelevant to the choices your organization actually faces.

When AI agents participate in decisions, this gap widens. Your register won't capture biases embedded in training data, logic gaps in algorithmic reasoning, or reliability issues in the information sources an AI agent accesses. These factors shape decisions directly.

Myth 2: Risk is a point value you can measure and track over time

Reality: Risk is a distribution of possible outcomes, not a coordinate on a heat map. Assigning a single likelihood-impact score to a risk collapses a range of scenarios into a false precision that obscures what decision-makers need to know.

This myth becomes dangerous with AI-driven decisions because algorithms operate on probabilities and confidence intervals, not fixed points. If your AI agent is making procurement recommendations based on supplier reliability models, the relevant question isn't "What's the risk level?" It's "What's the range of outcomes if we follow this recommendation, and what assumptions drive that range?"

You need to understand the distribution: best case, worst case, most likely case, and the factors that push outcomes toward each extreme. A point score tells you nothing about tail risks or the conditions under which an AI-generated decision might fail catastrophically.

Myth 3: AI tools are too new for risk managers to evaluate properly

Reality: The evaluation criteria haven't changed; you're still assessing whether decisions provide sufficient certainty that intended outcomes will be achieved. That's precisely how Purdy describes his work: assisting decision-makers to determine if their choices deliver adequate confidence in results.

You don't need to understand transformer architectures or gradient descent to evaluate AI-driven decisions. You need to ask:

  • What information is this AI agent accessing, and is that information complete, accurate, and current?
  • What logic or model is it applying, and does that logic align with your organization's objectives and constraints?
  • What assumptions underpin its outputs, and under what conditions do those assumptions fail?
  • How are decision-makers verifying the AI's recommendations before acting on them?

These questions apply whether the decision tool is an AI agent, a spreadsheet model, or a consultant's report. The technology changes; the evaluation framework doesn't.

Myth 4: Human oversight means having someone review AI outputs before implementation

Reality: Oversight requires understanding the decision process, not just checking the answer. If your human reviewer doesn't know how the AI agent reached its conclusion, what data it used, or what it ignored, that review adds false confidence rather than genuine control.

Consider a scenario where your finance team uses an AI agent to flag unusual transactions for investigation. If the agent is trained on historical patterns that reflect past biases (certain vendor types always flagged, certain geographies always cleared), your human reviewer will see a list of flagged transactions that looks reasonable because it matches historical practice. The bias perpetuates, undetected.

Effective oversight means interrogating the AI's reasoning: "Why did you flag these three transactions but not these two similar ones?" If your team can't answer that question, they can't provide meaningful oversight.

Myth 5: Risk management's role is to identify what could go wrong

Reality: Your role is to ensure decision-makers have sufficient certainty that their choices will achieve intended outcomes. That's a forward-looking, decision-centric function, not a threat-hunting exercise.

The distinction matters because "what could go wrong" thinking leads you to build defensive lists of potential problems. Decision-centric thinking leads you to ask, "What decision is being made, what outcome is intended, and what factors could prevent that outcome?" The first approach generates risk registers. The second approach generates insight.

When AI agents participate in decisions, this shift becomes essential. You can't enumerate every way an AI might fail. You can examine the decision the AI is supporting, the outcome that decision is meant to achieve, and the factors that would cause the AI's contribution to undermine rather than support that outcome.

What to do instead

Engage directly with the people making decisions in your organization. Ask them:

  • What decisions are you making that involve AI tools or AI-generated information?
  • How do you verify that the AI's outputs are reliable before you act on them?
  • What would you need to know about the AI's logic or data sources to have confidence in its recommendations?

Map the decision processes, not the risk list. For each significant decision, document: the intended outcome, the information sources (human and AI), the logic applied, the assumptions made, and the verification steps taken before action.

Then identify where AI introduces uncertainty that existing verification processes don't address. That's where you need controls: not generic "AI risks" on a register, but specific gaps in specific decision processes.

Your risk management framework should support better decisions, not document theoretical threats. If it's doing the latter, you're managing the wrong thing.

You Might Also Like