Risk Register
The Risk Register is included in Premium and Enterprise, and it works during
the demo too. Exporting it comes with a plan.
The AI risk register tracks the ways your AI systems could fail or cause harm. Each risk names:
- the trustworthy characteristic it threatens, from the NIST AI Risk Management Framework: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair, with harmful bias managed;
- for a risk about a generative system or model, the generative AI risk from NIST AI 600-1 (for example confabulation, information security, value chain). It is accepted only when the system or model the risk is about is generative; on any other risk the save is refused and asks you to link one or clear it;
- the AI system and model it is about, or neither for an organization-wide risk such as a policy gap. A risk that names only a model is about that model, not the organization;
- an inherent rating, likelihood × impact (1–25), before treatment, and a residual rating after it. The residual rating is what the owner judges once the treatment is in place: give both residual values or neither, and a risk with none is shown as not rated, never as low;
- the framework controls that treat it (at most 30), and a treatment decision.
Only organization administrators create and edit risks. Contributors see the register and the risks on each AI system's page.
Treatments
- Mitigate — reduce the risk with controls.
- Accept — acknowledge and tolerate it (document why).
- Transfer — shift it (e.g. insurance, a vendor).
- Avoid — stop the activity that creates it.
From risk to action
When you set a risk to Mitigate, you can have Backsplice generate a tracked remediation task automatically. Its priority is set from the risk score, and it links back to the risk so the work is visible from both sides. A risk can also be linked to the finding that surfaced it.
Treatment SLAs
Give a risk a due date and Backsplice tracks the treatment SLA. The register flags risks that are due soon (within a week) or overdue (with how many days past). Once an open or in-treatment risk passes its due date, the risk owner is escalated automatically (falling back to org admins) — at most once a week, so overdue work surfaces without becoming noise. Closing the risk or moving the due date stops the escalation.
Portfolio view
Portfolio view shows the open and in-treatment risks on two likelihood × impact grids, inherent beside residual, narrowed to one AI system or one risk tier if you choose. It lists the systems by risk tier, highest tier first, and within a tier by their highest current risk (residual where stated, inherent otherwise). Risks with no residual rating are counted beside the residual grid rather than drawn on it, and organization-wide risks are counted separately. An AI system's own page lists the risks about it.
The heatmap on the register itself is different: it plots the inherent rating of every risk, closed ones included.
Sorting the list
Click a column header to sort the register by that column; click again to reverse it. The sort is applied on the server, so it orders the whole register — not just the rows on the current page — and it is kept when you page through the results or change a filter. The active column shows an arrow, and screen readers announce it through the header's aria-sort state. Twelve of the fifteen register lists sort on the server this way; the evidence, remediation and vendor lists still sort the rows currently displayed.