Awakening Security
Appendices: Risk, Impact and Incident Templates and Standards Mapping
Ready-Made Templates and Standards Mapping
Risk Register Template
A single register for information risks and AI risks, with a column identifying which standard covers each risk. Fill in one row per risk, and review the register every quarter or after any significant change.
| Risk | Asset | Likelihood × Impact | Treatment | Owner |
|---|---|---|---|---|
| Pre-release footage leak | Dailies | Medium × High | Mitigate: encrypted drives | Digital imaging technician |
| Prompt injection into support agent | AI agent | High × Medium | Mitigate: tool isolation | AI officer |
| Cloud provider outage | Asset library | Low × High | Transfer: second copy | Operations manager |
AI System Impact Assessment Template
| Item | Guiding question |
|---|---|
| Purpose and intended use | What is the task? Which uses are explicitly prohibited? |
| Affected parties | Who is the direct user? Who is touched by the outputs? Are any vulnerable groups among them? |
| Data | Where does it come from? Do we have the right to use it? Does it contain personal data? |
| Potential impacts | Bias? Misinformation? Harm to privacy, ownership or reputation? |
| Controls | Human oversight? Disclosure? Usage limits? Drift monitoring? |
| Decision | Launch, conditional launch, redesign, or stop. |
AI Incident Report Template
- Description: What did you notice? A harmful output, a leak in a prompt, or unexpected agent behaviour.
- System and version: The tool or model name, its version, and its owner.
- Impact: Who was affected? Did the output reach a client or the public?
- Containment: Did you stop use? Were logs and prompts preserved as evidence?
- Escalation: The system owner, the AI officer, and legal where needed.
Mapping ISO 42001 to Other Frameworks
| Framework | Relationship to ISO 42001 |
|---|---|
| ISO 27001:2022 | The same structure (Clauses 4–10); covers the security of the data and systems AI depends on. |
| ISO 27701 | Privacy information management; complements personal-data controls in AI systems. |
| ISO 23894 | Guidance on AI risk management; a reference for the Clause 6.1 methodology. |
| ISO 42005 | Guidance on AI system impact assessment; details Clause 6.1.4. |
| NIST AI RMF | Its four functions (Govern, Map, Measure, Manage) intersect with the system cycle. |
| EU AI Act | Legal obligations by risk level; the system helps demonstrate compliance with them. |
Tip: use ← → to move between sections.

