Risks

Manage AI risks

The AI Risk Register brings together material risks identified through Swell’s governance process.

Each risk records what could happen, its likelihood and consequence, who owns it, what treatment is planned and which controls reduce it. As controls are implemented, the residual risk can be reviewed to reflect the risk that remains.

Where a residual risk cannot or will not be reduced further, an authorised person may be asked to accept it formally. Risk acceptance and approval of the AI use are separate decisions.

Use the Risk Register

The Risk Register is the organisation’s working list of material AI risks recorded through Swell.

Use filters and attention indicators to find risks that need confirmation, ownership, treatment, controls or acceptance. Open the risk before acting so you can read the full statement and supporting assessment.

How to use the Risk Register

  1. Open AI Risks and stay on Risk Register.
  2. Review the summary for current risks, AI uses awaiting assessment, risks outside tolerance and control or evidence gaps.
  3. Use Residual rating, Category or Overdue only to narrow the list.
  4. Select a risk statement to open its detail.

Use the fixed 3×3 risk matrix

The risk matrix groups risks by likelihood and consequence so you can see their relative distribution and open the records behind each cell.

Swell uses a fixed 3×3 matrix. The visual grouping supports comparison; it does not replace the documented reasoning and authorised rating on each risk.

How to use the fixed 3×3 risk matrix

  1. Open AI Risks → Risk Matrix.
  2. Choose Residual or Inherent.
  3. Read the 3×3 cells from Low to High consequence and likelihood.
  4. Select a populated cell to open the matching filtered Risk Register.

Important: Swell uses a fixed 3×3 matrix that cannot be configured for individual organisations.

Review a risk

A risk record explains the event or consequence the organisation is managing, its rating, owner, planned treatment and supporting controls.

Read the complete record before changing one part of it. A new control, changed treatment or material change may require the residual rating to be reconsidered.

How to review a risk

  1. Open a risk from the register, matrix or AI use.
  2. Read the reference, statement, category, AI use and current status.
  3. Compare inherent and residual ratings.
  4. Review appetite, owner, treatment and next review.
  5. Use Assessment, Treatment and History for the supporting detail.

Confirm or recalculate a risk rating

Risk rating is a business judgement based on the assessment, available evidence and the organisation’s risk approach.

Confirm the inherent rating before relying on controls, then confirm or recalculate the residual rating using only controls that are evidenced and working as intended.

Before you start

  • You need authority to confirm the rating.
  • Review the supporting facts and controls before changing the remaining-risk rating.

How to confirm or recalculate a risk rating

  1. On the Risk Assessment tab, review the suggested inherent and residual positions.
  2. Choose the Stage you are assessing.
  3. Choose a likelihood and consequence from the three-level scale.
  4. Enter the reason for the judgement.
  5. Select Confirm rating. Use Recalculate when changed controls or evidence may affect the remaining risk.

Assign ownership and choose treatment

The risk owner is accountable for ensuring the risk is understood and managed. Treatment records the organisation’s intended response, such as reducing, avoiding, transferring or accepting the risk.

Choose an owner with the authority to act and record a treatment that reflects the real plan. Naming an owner does not by itself reduce the risk.

How to assign ownership and choose treatment

  1. Open the Risk and choose Manage risk.
  2. Assign the Risk owner.
  3. Choose Mitigate, Avoid, Transfer or Accept.
  4. Set treatment status: Not started, Underway, Awaiting evidence, Ready for review or Completed.
  5. Set the next review date where appropriate.
  6. Choose Standard or Restricted visibility and save.

Common situations

  • Use Restricted only when the Risk contains genuinely sensitive information. Restricted visibility limits ordinary access but remains subject to privileged administrative and support boundaries.
  • If ownership changes, update the risk owner and check that open treatment, control or acceptance work is assigned to the right people.

Add a treatment action

Use a treatment action for practical follow-up that helps manage the risk but is not itself a formal control assignment.

Describe a clear action, owner and expected timing. If the action becomes a safeguard relied on to reduce residual risk, record and evidence it through the control process.

How to add a treatment action

  1. On Manage risk, find Add a treatment action.
  2. Enter a short action title and clear description.
  3. Add an optional due date.
  4. Save the action.

Add and review controls

Controls are the safeguards the organisation relies on to prevent, detect or reduce the risk.

Link only controls that genuinely apply to this risk. Residual-risk reduction should rely on controls with current evidence and an appropriate effectiveness decision.

How to add and review controls

  1. Open the Risk Treatment tab.
  2. Review linked controls and their eligibility.
  3. Under Recommended controls, select Add [control name] when the recommendation applies.
  4. When authorised and evidence supports it, select Confirm effective for this risk.
  5. Recalculate the remaining-risk rating when the recognised controls or their evidence change.

Request risk acceptance

Risk acceptance is used when a risk will remain after available controls and treatment have been considered, and the organisation needs an authorised person to decide whether it is prepared to proceed.

It is different from approving the AI use itself. An AI use may have several risks, and accepting one residual risk does not automatically authorise the overall use.

Before requesting acceptance, make sure the risk rating, treatment and supporting evidence reflect the current situation.

Before you start

  • Risk acceptance is separate from approving the AI use.

How to request risk acceptance

  1. Confirm that the remaining-risk rating and treatment plan are current.
  2. On the Risk, select Request Risk Acceptance.
  3. Choose the authorised assignee and explain why acceptance is being requested.
  4. Submit the request and monitor the resulting Risk Acceptance assignee action.

Decide a risk acceptance request

The acceptance decision belongs to the authorised person assigned to the request. Review the risk, residual rating, treatment, controls and supporting rationale before deciding.

Accept only the remaining risk described in the request. Reject it when further treatment or clarification is needed; the decision does not approve the AI use as a whole.

How to decide a risk acceptance request

  1. Open the Risk Acceptance assignee action.
  2. Review the Risk statement, residual rating, treatment, controls and request rationale.
  3. Choose Accept, Accept with conditions, Return for changes or Reject.
  4. Enter the rationale. Add conditions when accepting with conditions.
  5. Select Record decision.

Common situations

  • Return the request for changes when the evidence or proposed treatment must be improved before the acceptance decision can be made.