RecommendationModerate riskComparison recommended

AI Playbook for Enterprise AI Risk Register

A $2.4B financial services holding company has deployed AI across 9 subsidiaries in 14 use cases. The Chief Risk Officer needs a consolidated AI risk register for the board's enterprise risk committee meeting in 30 days. No single risk inventory currently exists across the subsidiaries.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A $2.4B financial services holding company has deployed AI across 9 subsidiaries in 14 use cases.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Enterprise AI Risk Register".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • AI deployment inventory from 9 subsidiaries (self-reported)
  • Enterprise risk framework and risk appetite statement
  • Regulatory guidance: OCC Model Risk, CFPB AI fairness, SEC AI disclosure
  • Board risk committee reporting template
  • Peer company AI risk disclosure examples

Attachments: Documents (Documents)

The Prompt

You are an enterprise risk officer building a consolidated AI risk register for a financial services holding company. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Classify each of the 14 AI use cases by risk tier: Tier 1 (regulatory/reputational, customer-facing), Tier 2 (operational, internal), Tier 3 (administrative, low stakes).
2. For Tier 1 use cases, identify the specific risk dimensions: model failure, bias/fairness, explainability gap, regulatory non-compliance, and third-party dependency.
3. Identify risk register gaps: which subsidiaries have not provided adequate documentation?
4. Map each AI risk to the board's existing enterprise risk framework.
5. Format the board presentation: executive summary, risk heat map, top 5 risks requiring immediate attention, and recommended governance actions.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Tiered AI risk classification for all 14 use cases
  • Tier 1 risk dimension analysis
  • Documentation gap inventory
  • Enterprise risk framework mapping
  • Board presentation with heat map and governance recommendations

Review before you act

  • Validate this output against source files before relying on it: Classify each of the 14 AI use cases by risk tier: Tier 1 (regulatory/reputational, customer-facing), Tier 2 (operational, internal), Tier 3 (administrative, low stakes).
  • Validate this output against source files before relying on it: For Tier 1 use cases, identify the specific risk dimensions: model failure, bias/fairness, explainability gap, regulatory non-compliance, and third-party dependency.
  • Validate this output against source files before relying on it: Identify risk register gaps: which subsidiaries have not provided adequate documentation?.
  • Validate this output against source files before relying on it: Map each AI risk to the board's existing enterprise risk framework.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Enterprise AI Risk Register, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface tiered ai risk classification for all 14 use cases; tier 1 risk dimension analysis; documentation gap inventory; enterprise risk framework mapping. Those are comparison artifacts — they only exist if more than one model runs. Reconciliation protocols exist because models disagree. The playbook's job is to make disagreement inspectable, not to hide it behind a single blended answer.

AI Governance LayerControl Plane and ScoringRecommendationModerateDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.