AI should help write your risk register. It should also be on it

Across the country, school and college leaders are beginning the annual process of reviewing risk registers and board assurance frameworks for the next academic year. It is rarely anyone’s favourite task.

Too often, the process begins by opening last year’s document, changing a few dates, adjusting some risk scores and adding whatever new issue has dominated leadership conversations during the past twelve months.

For 2026–27, there is a better way. Artificial intelligence can be used to make the review process more rigorous, more challenging and more useful. But there is an important catch. AI should help you review your risk register. It should also be on it.

Start with the risks you may have missed

One of the most useful applications of AI is not asking it to write your risk register from scratch. It is asking it to challenge the one you already have.

Give an approved AI tool your existing risk categories, appropriately anonymised and with no personal or sensitive information, alongside your strategic priorities and relevant national guidance. Then ask better questions.

1. What significant risks are missing?

2. Which risks are described too broadly?

3. Which controls are activities rather than genuine controls?

4. Where is the evidence that a mitigation is actually working?

5. Which risks have changed most significantly over the past twelve months?

6. What emerging risks should a board be discussing now?

This is where AI can be particularly valuable. Leadership teams are understandably close to their own organisations. They know their risks well, but familiarity can also create blind spots.

AI can act as a critical friend

It can compare the organisation’s stated priorities with its identified risks. It can identify inconsistencies. It can suggest alternative scenarios. It can challenge whether the controls listed genuinely reduce the likelihood or impact of a risk. It should never make the decision, but it can ask some very good questions.

Use AI to strengthen the line between risk and assurance

A good risk register should not simply describe what might go wrong. It should help leaders and boards understand whether the organisation is genuinely in control. This is where a board assurance framework can be particularly powerful. For each major strategic risk, leaders should be able to answer:

1. What are we trying to achieve?

2. What could prevent us from achieving it?

3. What controls are in place?

4. What evidence tells us those controls are working?

5. Where are the gaps in our assurance?

AI can help leaders test each of these questions systematically.

For example, an organisation may identify cyber security as a major risk and list staff training, filtering systems and incident response procedures as controls. AI can be asked to challenge the assurance behind those controls.

When was the training last completed? What percentage of staff completed it? Has its impact been tested? When was the incident response plan last rehearsed? What does internal scrutiny tell us? What external assurance exists?

The result is a shift from saying, “We have a policy” to asking, “How do we know it works?”

That is a much more useful conversation for a board.

Let AI find the gaps between your documents

Schools and colleges produce a huge amount of information about risk. It sits in strategic plans, committee minutes, audit reports, safeguarding reviews, complaints, staff surveys, cyber assessments, financial forecasts, internal scrutiny reports and school improvement plans.

The problem is that these documents are rarely considered together. Used within secure and approved systems, AI can help leaders identify patterns across large volumes of organisational information.

1. Does the strategic plan identify a major dependency that is absent from the risk register?

2. Does an internal audit repeatedly identify the same control weakness?

3. Are complaints or staff surveys revealing a cultural risk that has not reached the board?

4. Does the risk register describe something as well controlled while other evidence suggests otherwise?

This is potentially one of the most powerful uses of AI in governance: helping leaders connect information that already exists but is dispersed across the organisation.

But do not outsource judgement

There is a danger here. A polished AI-generated risk register can look very impressive. It can contain professional language, neat controls and plausible mitigations. It can also be completely generic.

AI does not know your organisation unless you give it the right context. It does not understand the culture in a particular school, the fragility of a key relationship, the quality of leadership in a department or the likelihood that a control will work in practice. Nor should confidential, personal or sensitive organisational information simply be uploaded to a public AI tool.

The leadership task remains human. AI can analyse, compare, challenge and draft. Leaders must decide. Boards must scrutinise. Those responsible for risk must own the final judgement. The purpose of using AI is not to make risk management quicker by automating thought. It is to make the thinking better.

And now ask the difficult question: where is AI on your risk register?

There is an irony in using AI to improve a risk register that says nothing about AI. For many schools and colleges, AI is already being used by staff and students. It may be used to create resources, draft communications, support planning, analyse information and complete work.

Yet the organisation may have no strategic risk relating to its use. That needs to change.

Leaders should consider risks around:

Data protection and the sharing of sensitive information;

Safeguarding and inappropriate AI-generated content;

Inaccurate or fabricated outputs;

Bias and discrimination;

Intellectual property and copyright;

Assessment integrity;

Cyber security and unapproved tools;

Inconsistent practice between staff and departments;

Over-reliance on AI and the erosion of human judgement;

Inequality of access and capability; and

Reputational damage arising from inappropriate use

But there is another side to this. Boards should also consider the risk of not acting. What is the risk if staff are not trained? What is the risk if students leave school without AI literacy? What is the risk if individual enthusiasts race ahead while the rest of the organisation is left behind? What is the risk if schools continue buying technology without developing the capability to use it well?

Failure to adopt AI safely and strategically is itself becoming an organisational risk.

A useful structure

The five pillars of the AiEd Certified Framework offer a practical lens through which schools and colleges can review their AI-related risks and assurance.

AI Literacy: Do staff, leaders and students understand AI sufficiently to use it critically and safely?

Policies and Ethics: Are expectations clear? Are data protection, safeguarding, bias, transparency and accountability properly addressed?

Tools and Systems: Do we know which tools are being used? Are they approved, secure and appropriate?

Digital Pedagogy: Is AI improving teaching and learning, or simply being adopted because it is available?

Collaboration and Community: Are governors, parents, students and staff part of the conversation, and are we learning from others?

These five pillars can be used as a simple audit. For each one, ask:

1. What is the risk?

2. What controls do we have?

3. What evidence tells us those controls work?

4. Where are the gaps?

5. What further action is needed?

That turns the framework from a statement of good practice into a source of board-level assurance.

Five ways to use AI in your 2026–27 risk review

As leaders review their frameworks for the coming academic year, we suggest five practical uses of AI.

Challenge the existing register. Ask what is missing, duplicated, outdated or poorly defined.

Stress-test  major risks. Ask AI to generate plausible scenarios and test whether current controls would be sufficien

Interrogate the assurance. Ask what evidence would genuinely demonstrate that each control is working.

Connect different sources of evidence. Use approved tools to identify patterns  and contradictions across organisational documents.

Review AI itself as a strategic risk. Use the five pillars of the AiEd Certified Framework to assess readiness and identify gaps.

The aim is not to produce a longer risk register. It is to produce a better one.

The question boards should be asking

The annual review of the risk register should not be a compliance exercise. It should be one of the most important strategic conversations a board has. AI gives leaders a new tool to make that conversation more rigorous. It can challenge assumptions, expose gaps, connect evidence and help boards ask better questions.

But it also creates new risks, responsibilities and opportunities that can no longer sit outside the governance framework. So, as you review your risk register for 2026–27, ask two questions.

How could AI help us understand our risks better?

And then:

What are the risks if we fail to understand AI?

The answer to both may be more important than you think.

DfE academy trust risk management guidance: Academy trust risk management - GOV.UK

DfE governance guide: Academy trusts: governance guide - GOV.UK