AI governance checklist

AI Risk Register for NZ Businesses Using AI Agents

Track AI agent risk before it reaches customers, systems, or public content

A simple AI risk register helps a New Zealand business decide what an agent may prepare, what a person must approve, and which workflows should wait.

An AI risk register for a New Zealand business should list each AI use case, data source, system access, failure mode, risk owner, human approval point, exception log, and build decision: build now, prepare first, wait, or avoid.

The register is not a legal guarantee or cybersecurity programme. It is an operating tool for owners who want useful AI adoption without invisible automation risk. If you are choosing the first workflow, pair it with an AI adoption roadmap for NZ small businesses.

What is an AI risk register?

An AI risk register is a plain-English list of AI uses, likely failure points, controls, owners, and review decisions. It turns vague concerns into visible workflow choices.

Plain-English definition for NZ businesses

For a small business, the register answers: where are we using AI, what information does it touch, what could go wrong, who checks the output, and what should happen when the AI is uncertain or wrong?

Why AI agents need workflow-level risk controls

AI agents are different from casual prompting because they may use tools, read files, draft messages, inspect websites, or summarise systems. Risk needs to be mapped by workflow, not handled as one broad policy statement.

Official New Zealand guidance, including Business.govt.nz's safe AI guidance and MBIE's responsible AI guidance, is useful background. The register turns guidance into daily checkpoints.

What to include in an AI risk register

Keep the first version short enough to maintain. The goal is not a perfect document; it is a shared view of where AI needs boundaries.

Use case or workflow

Name the actual work: "draft newsletter sections from approved posts" or "prepare stale-opportunity lists from CRM records".

Data involved

List the sources AI may use: CRM notes, emails, website pages, tickets, invoices, policies, spreadsheets, call summaries, or public pages. Mark sensitive data clearly.

Tools, permissions, and integrations

Record whether AI can read, draft, create tasks, update fields, send messages, publish pages, or trigger systems. Begin with read and prepare permissions.

Possible failure modes

Write the mistakes in concrete language: exposes private information, invents a claim, drafts the wrong offer, changes a CRM field, uses outdated pricing, misreads a note, or publishes inaccurate copy.

Human approval point

Define where the agent stops. Name what the human reviews and whether they can approve, edit, reject, or escalate.

Risk owner

Assign a person, not a department: owner, sales lead, operations manager, account manager, marketing lead, or privacy/security owner.

Logging and review rhythm

Decide where AI output, human decisions, exceptions, and changes are recorded. Review early workflows often, then settle into a practical rhythm.

Build, prepare, wait, or avoid decision

Every row should end with a decision. Build means narrow and reviewable. Prepare means data, ownership, or policy needs cleanup. Wait means value is unclear. Avoid means risk or review burden is too high.

Example AI-agent risks to capture before implementation

These examples are not client results. They are common patterns to consider before connecting AI to live work.

Private or sensitive data exposure

An agent may need customer notes, staff information, financial context, or supplier details. Show whether that information is needed, can be minimised, or must stay out of the tool.

Incorrect customer communication

A sales or service agent might prepare a message with the wrong tone, price, promise, or next step. Customer-facing drafts should begin behind a human approval gate.

Unapproved CRM or financial changes

CRM fields, forecasts, invoices, discounts, and payment notes can change business decisions. Define which updates are allowed, need approval, or are off-limits.

Publishing inaccurate public content

Website, social, and SEO workflows create public trust risk. AI may prepare observations, metadata, FAQ drafts, or broken-link notes, but offers, proof claims, pricing, legal/privacy wording, and publishing should stay human-approved.

Staff using unsanctioned AI tools

Include informal AI use, not just official agents. If staff use personal accounts or unapproved tools, connect the row to your AI policy for small business NZ.

Simple AI risk-register table for owner-operated businesses

Use a lightweight table before you build.

Example row: sales follow-up agent

Workflow: prepare follow-up drafts from approved CRM notes. Data: contact details, conversations, deal stage, and offer notes. Risk: wrong promise, poor timing, or private context. Approval: sales lead reviews before sending. Owner: sales lead. Decision: draft preparation first. See AI CRM Automation for NZ Sales Teams.

Example row: website maintenance agent

Workflow: prepare weekly page checks. Data: public pages, analytics summaries, Search Console exports if available, and approved service copy. Risk: unapproved claims, stale pricing, broken forms, or publishing without review. Approval: website owner approves public changes. Owner: marketing lead. Decision: review queue before publishing. See the AI Website Maintenance Checklist.

Example row: management reporting agent

Workflow: summarise weekly notes and exceptions. Data: dashboards, task lists, CRM summaries, and meeting notes. Risk: wrong conclusion, missing context, or sensitive staff information. Approval: manager reviews before decisions affect staff, spending, clients, or commitments. Owner: operations manager. Decision: build if sources and review standards are clear.

How risk registers connect to human approval gates

A risk register is most useful when it becomes an approval map. The register identifies risk; the approval gate controls the moment risk could turn into action.

What AI may prepare

AI can prepare research notes, summaries, draft replies, stale-record lists, page observations, checklist results, and internal answers.

What AI may update

Low-risk updates may be allowed after testing, such as creating tasks, tagging records, or saving draft notes. Permissions should stay narrow, logged, and reversible.

What a human must approve

A person should approve customer messages, public copy, pricing, legal or privacy wording, sensitive CRM changes, finance actions, staff decisions, and trust-sensitive actions. The AI approval gates guide explains these checkpoints.

What AI must never do alone

The register should also say no. AI should not quietly make commitments, invent proof, expose restricted information, change core records, or act outside the approved workflow.

Bounded access

How the AI Agent Assessment uses risk to decide what to build first

Risk is not a reason to avoid AI entirely. It is how you choose the right first workflow.

Risk is a prioritisation tool

A low-risk workflow can become a first pilot. A valuable but risky workflow may need better data, policy, permissions, or approval design. A vague workflow may wait.

Assessment turns risk into a decision

The AI Agent Assessment reviews workflows, source data, value, tool access, approval gates, and operating risk. The outcome is a decision: build now, prepare first, wait, or do not automate.

The output is a safer first workflow

Instead of asking "can AI do this?", the assessment asks "can this workflow be prepared by AI and reviewed by a human in a way the business can trust?"

Frequently asked questions

What is an AI risk register?

An AI risk register lists AI use cases, data sources, possible failures, controls, owners, approval points, logs, and build decisions. It shows where AI needs boundaries before implementation.

Does a small business need an AI risk register?

A small business should use a lightweight register when AI touches customers, staff, private data, CRM records, website content, finances, or management decisions.

What AI risks should a New Zealand business track?

Track sensitive data exposure, inaccurate customer messages, public claims, unapproved system changes, staff misuse, wrong source data, missing ownership, and unclear approvals.

Who should own AI risk in a small business?

The business owner should assign a named owner for each workflow: operations manager, sales lead, marketing lead, account manager, or privacy/security owner.

How does an AI risk register relate to human approval gates?

The register identifies what could go wrong. The approval gate defines where AI must stop so a person can approve, edit, reject, or escalate before action.

Next step

Do not wait for a full compliance programme. Start with one workflow, one owner, one approval point, and one build decision.

If you want help turning AI risk into a practical workflow decision, start the $1,000 AI Agent Assessment. We will map what an agent can prepare, what a person must approve, and which first workflow is safe enough to build.