---
title: "The AI Risk Register — Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You | Len P. van der Hof"
description: "RISK gives teams a living register for AI failure modes: named risks, accountable owners, tests, mitigations, escalation paths, and review cadence."
image: "https://lenvanderhof.com/books/covers/the-ai-risk-register-en-front.jpg?v=20260819-hitll-nobg"
---

![The AI Risk Register — front cover](https://lenvanderhof.com/books/covers/the-ai-risk-register-en-front.jpg?v=20260819-hitll-nobg)

![The AI Risk Register — back cover](https://lenvanderhof.com/books/covers/the-ai-risk-register-en-back.jpg?v=20260819-hitll-nobg)

No. 55 · Manuscript complete · AI & agents · RISK

# The AI Risk Register

Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You

The AI Risk Register: Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You.

RISK gives teams a living register for AI failure modes: named risks, accountable owners, tests, mitigations, escalation paths, and review cadence. Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You. The framework: RISK.

Look inside↓Notify me at launch→← All books

pages

224

chapters

14

hours of reading

± 3

editions

EN · NL

Production status

1. Design
2. Drafting
3. Manuscript
4. Production
5. Launched

The editions

## Kindle and Paperback

Production shots of the editions. Not for sale yet — this page is the public working version.

- ![The AI Risk Register, kindle](https://lenvanderhof.com/books/editions/the-ai-risk-register/en-kindle-190cc758d6cf.jpg)



### Kindle



The digital edition, ready in any Kindle app.
- ![The AI Risk Register, paperback](https://lenvanderhof.com/books/editions/the-ai-risk-register/en-paperback-b1f7557f9e50.jpg)



### Paperback



The working copy. Mark it up. Take it into the meeting.

The book

## Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You

The board meeting ends on time. Seventeen items, all green or yellow, and everyone walks out relieved to have "done the risk thing." Two weeks later a model update in the customer-success agent starts misclassifying tickets, the errors feed three other agents, and churn is climbing before anyone notices. None of the seventeen items mentioned it. The post-mortem ends the way every serious AI failure does: "This risk was not on the register."

The reflex is to add more items and schedule another review. That scales the document, not the protection. A longer list is a snapshot of what you already knew to name, not a map of what breaks you.

*The AI Risk Register* introduces the **RISK** framework: Register what matters, Inspect with evidence, Scenario-plan the unlikely, Kill-switch before deployment. Four moves turn a static compliance artifact into a living decision system that changes what your team ships. RISK is an operating heuristic, not a validated instrument: a lens you test against your register.

What you learn

## What this book puts in your hands

- Register what matters: give every material risk one owner, a first evidence date, and an update trigger.
- Inspect with evidence, replacing "we talked about it" with a measured condition and a last-inspected date.
- Scenario-plan the unlikely with cards that trace the second-order path and name the tail condition before it cascades.
- Build tested kill-switches before deployment, so you stop a system on purpose.
- Wire the register into how the team sets risk appetite, escalates, and reports.

Practice: risk surface audit 11

From the book

## Practice: risk surface audit 11

The AI Risk Register, printed page: Practice: risk surface audit 11

Inspect more pages↓

## Look inside

Pages from the print edition.

- [Practice: ownership assignment session 6 12 89⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-107-p107-9528ddf6c27c96cec82b5413-6c3a3d246b68c2ff73177142.webp)
- [First, a new deployment adds a node. Every time an agent, model,⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-120-p120-9528ddf6c27c96cec82b5413-24142179b15b504d8f2e09bc.webp)
- [Practice: appetite statement session 8 12 117⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-135-p135-9528ddf6c27c96cec82b5413-9cfc14dc052a079e174473f2.webp)
- [Practice: risk surface audit 11⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-29-p029-9528ddf6c27c96cec82b5413-79e4aaa7445a98d7f154b257.webp)
- [Repeat when a new consumer is added. Define the required detection⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-51-p051-9528ddf6c27c96cec82b5413-f7e0e438357a8bcd3fe541f6.webp)
- [Step 1, confirm: the owner must verify the breach from an existing⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-79-p079-9528ddf6c27c96cec82b5413-b46d8a1b7ca7b5c12fdf2483.webp)
- [Graduated containment lowers the price of acting. A nar-⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-82-p082-9528ddf6c27c96cec82b5413-5266cd1b88b08431a6486cc8.webp)
- [Rows where nothing fired get ten seconds: “no trigger, within age⤢](https://lenvanderhof.com/books/previews/the-ai-risk-register/en/approved-page-90-p090-9528ddf6c27c96cec82b5413-25d16754b7c764e334826776.webp)

·

The contents

## Chapter by chapter

14 chapters

Every chapter of The AI Risk Register with its printed epigraph, what you can do afterwards, and the moment it is built for.

1. IntroductionThe Invisible Risk SurfaceRisk registers document what the team already knows how to name. Material exposure can remain in the paths no one wrote down.What you can do afterwardsYou will see why your current risk list is a snapshot of yesterday's knowns. You will learn the four quadrants of the actual risk surface and run a field test that shows exactly where your register has no language.Use this chapter whenYou have a slide deck or spreadsheet labeled "risk register" that the board nods at, yet near-misses and surprises keep arriving from directions the list never mentioned.
2. Chapter 1Register What MattersA risk is registered only when it is named, owned, and updated with evidence. Unregistered risks remain real; the problem is that no operating control can find them.What you can do afterwardsYou will leave with a prioritised starter register in which every material risk has a specific name and one accountable human owner. Every row carries a status, an evidence date, and a living update trigger.Use this chapter whenYou have inherited or created a risk list in which many items are known to the team yet never assigned, never inspected, and never acted upon.
3. Chapter 2Inspect with EvidenceDemos, vendor claims, and "it passed internal testing" do not establish that a named risk is managed. Inspection requires evidence at the granularity of the decision.What you can do afterwardsYou will replace trust with inspection. You will leave with four inspection designs matched to the four evidence classes, an independence rule, a cadence tied to change velocity, and a fifteen-minute falsification protocol.Use this chapter whenA model or agent "seems fine" in demo or internal test, yet you have no protocol for what evidence would support a bounded production claim.
4. Chapter 3Scenario Planning for the Unlikely"That will never happen" can end inquiry precisely where consequence demands it. Scenario planning gives an unlikely but material path a trigger and a pre-committed response.What you can do afterwardsYou will run a ninety-minute session that produces scenario cards for your highest-impact tails. You will write signposts that pass the observable-cheap-leading test, and rehearse one card before reality runs it for you.Use this chapter whenThe register contains only first-order items and the team still says "that tail will never matter to us."
5. Chapter 4Kill-Switches Before DeploymentA material-risk system needs a tested path to a defined safe state before deployment. The path, authority, and maximum response time depend on the harm it is meant to contain.What you can do afterwardsYou will design a kill-switch around four principles and audit everything it is entangled with. Then you build the containment ladder and verify the control path with a timed test.Use this chapter whenYou are shipping agents or models into production where a bad output at scale would be expensive, irreversible, or reputationally damaging.
6. Chapter 5The Living RegisterA static quarterly document records a point in time. A living register carries triggers, owners, evidence, and version history into the decisions between reviews.What you can do afterwardsYou will leave with a register design that runs on triggers, pruning rules, and an operating calendar measured in minutes. You will also start the one metric that proves the register is alive: the decision that changed.Use this chapter whenYour risk register is updated the week before the board meeting and then sits untouched until the next quarter.
7. Chapter 6Ownership and EscalationDiffuse ownership is how risk registers become theater; every risk must have a single named human owner with a clear escalation path or it is not a managed risk.What you can do afterwardsYou will assign a single accountable owner and derive an escalation clock for every top risk. The chapter uses 24/48/72 hours as one worked clock for slow-moving operational drift, then shows when a much shorter safety, legal, or customer-harm clock overrides it.Use this chapter whenRisks have "the team" or "engineering" as owner and no one can say whose calendar actually changes when the risk moves.
8. Chapter 7Second-Order and Tail RisksA first-order row can miss consequential paths through customers, systems, suppliers, and institutions. Mapping those paths widens the register without pretending to measure their prevalence.What you can do afterwardsYou will build a second-order map for three material first-order risks using a repeatable tracing protocol. You will learn where to pause, when to continue, and how to promote one consequential, actionable link into the register.Use this chapter whenYour register contains only the risks that are easy to name and the team still believes the expensive surprises will be first-order.
9. Chapter 8Risk Appetite and Trade-offsRisk appetite governs only the exposure an organization is permitted to choose. Law, safety, rights, contracts, and professional duties set non-waivable floors; explicit trade-offs operate above them.What you can do afterwardsYou will write a one-page appetite statement with testable boundaries per risk category, build a trade-off table with three worked rows, and pressure-test both against your last three deployment decisions.Use this chapter whenThe board says "zero tolerance for compliance risk" while the team is paralyzed, or a competitor ships the segment you could have taken.
10. Chapter 9Integrating Risk into Decision MakingA risk register that does not change go/no-go decisions, feature prioritization, or deployment timing is not a register; it is a compliance artifact.What you can do afterwardsYou will wire the register into the four rooms where decisions actually happen, using four copyable artifacts that each cost minutes, and start a decision log that records whether the register changed an outcome.Use this chapter whenRisk review happens the week before launch and the launch still happens because "we're already late."
11. Chapter 10Regulatory and External RiskTreating regulatory requirements as a separate compliance track is how companies get surprised by rules that were visible for years; the register must include the external map or it is incomplete by design.What you can do afterwardsYou will add regulatory rows to the register as first-class entries with classification, triggers, owners, and obligation dates. A thirty-minute monthly monitoring loop will surface rule changes before they arrive as surprises.Use this chapter whenThe team treats the EU AI Act or sector rules as "legal will handle it" while the register has no regulatory row.
12. Chapter 11Risk CommunicationA register that is buried in slides or written in compliance language is not a register; how it is communicated determines whether anyone will use it when it matters.What you can do afterwardsYou will build a versioned communication protocol for five audience views, create one engineer brief, and test whether a cold reader can retrieve its signal, action, and owner under a worked ninety-second constraint.Use this chapter whenThe risk register is structurally sound but the engineer who needed its trigger and response had never seen the relevant page.
13. Chapter 12Building Your Risk Protocol"We have a document" is the starting point, not the achievement; a living risk protocol that the leadership team runs as an operating system is what turns dread into proportionate, calm capability.What you can do afterwardsYou will assemble twelve chapter artifacts into one protocol page, derive the operating cadence from your risks and capacity, and leave with a thirty-day installation sequence, completion evidence, and explicit stop conditions.Use this chapter whenThe team has a beautiful risk register but still made three major deployment decisions last quarter without consulting it.
14. ConclusionCalm CapabilityA living register does not eliminate uncertainty or harm. It gives operators a prepared way to recognize a material condition, inspect the evidence, contain what they can, and escalate what they cannot accept.What you can do afterwardsYou will see every chapter contribute to one composite eleven-minute decision, then create a dated commitment to register, inspect, scenario-test, and contain one real risk under your control.Use this chapter whenThe team has installed the protocol and needs to test whether the parts meet in one decision rather than living as separate artifacts.

Who it is for

## Who this book was written for

The result is a one-page living register with named owners, tested kill-switches, and scenario cards that trace what a static list never sees. It turns vague dread about AI into proportionate capability.

If you run material AI in production and refuse to meet your exposure in the post-mortem, start with the register you have and the effect it never named.

### The reader it was written for

Risk leads, COOs, heads of product or engineering, founders, and board risk or audit members at organizations with material AI deployments. They have seen the gap between a risk list and a risk system that changes decisions. They are systems-oriented, skeptical of risk theater, and willing to maintain a small set of useful artifacts.

### Probably not for you if

- Specialists seeking a technical model-risk textbook.
- Organizations with no material AI exposure.
- Readers seeking a one-time compliance checklist or a substitute for legal,

Editions

## Editions and specifications

Edition Formats Chapters Pages Reading time ISBN (paperback) English The AI Risk Register In production 14 224 ± 3 hours — Dutch Het AI-risicoregister In production 14 100 ± 3 hours —

Both editions are written natively. The Dutch text is not a machine translation of the English. · Trim size: 6x9″

Frequently asked

## What readers usually want to know

### What is The AI Risk Register about?

RISK gives teams a living register for AI failure modes: named risks, accountable owners, tests, mitigations, escalation paths, and review cadence. The subtitle is: Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You.

### Is there a Dutch edition?

Yes. The Dutch edition is Het AI-risicoregister, written as a native edition rather than a machine translation. It moves through the same production line.

### How long is The AI Risk Register?

This edition runs 14 chapters, 224 pages in print and roughly 3 hours of reading.

### Who is The AI Risk Register for?

If you run material AI in production and refuse to meet your exposure in the post-mortem, start with the register you have and the effect it never named.

The production system

## How this book was made

Every title moves through the same gated production line: sourced research, a claim-level evidence ledger, structural review, fact-checking, red-team critique, and a bilingual final edit. AI agents do specialist work inside those gates; judgment, voice, and accountability stay human.

- Claims enter an evidence ledger with a source and a confidence grade before they reach the page
- English and Dutch are two native editions, not a translation of one another
- Every chapter clears readability, rhythm, and style gates before it is typeset

Read the system in The Agentic Author→Production filesFront PDFBack PDFFull cover PDFKindle front JPG

The series

## More in this theme

AI Agents for Startup StrategyThe Agentic CodebaseThe Multi-Agent OrganizationThe RAG EngineerThe Model PortfolioThe Agent Dream Team
