An AI product landing page can create a risk before a visitor ever uses the product. A headline may imply accuracy, autonomy, safety, privacy, availability, or savings that the model, workflow, or service cannot consistently support. A risk register makes those failure modes visible and gives the team a control, evidence, owner, and recovery path.
Use the template before launch, after a model or policy change, or when a conversion test changes the promise.
Define the page and decision purpose
State the buyer role, product, model or workflow, market, next action, owner, review date, and stop condition. Specify whether the page informs a demo, technical review, pilot, documentation request, or another decision.
Write a complete risk statement
Use: “Because [cause], [event] may happen, leading to [impact], evidenced by [signal].” Add affected visitor, data class, model boundary, page element, system, owner, and review date.
“AI claim risk” is too broad to drive a control. Name the exact promise and failure mode.
Cover capability and performance claims
Register claims about accuracy, speed, autonomy, reliability, bias, security, privacy, savings, human review, integrations, customer outcomes, and typicality. Record source, evaluation method, date, scope, population, limitation, reviewer, permission, and expiry.
The NIST AI Risk Management Framework offers a voluntary vocabulary for managing AI risk. It is not a certification, model evaluation, legal opinion, or proof that a claim is true.
Cover data and privacy risks
List form fields, chat, prompts, uploaded files, analytics, recordings, account matching, and remarketing signals. For each, record purpose, permission, access, retention, deletion, processor, transfer, and owner. Avoid requesting sensitive information to qualify a general enquiry.
The NIST Privacy Framework can structure questions about identifying, governing, controlling, communicating, and protecting privacy risk. It is voluntary guidance, not permission to collect or combine data.
Cover measurement risks
Define view, engaged visit, interaction, form start, completion, reachable lead, accepted conversation, opportunity, and outcome. Record denominator, source, identity rule, attribution window, exclusions, lag, owner, and correction path.
The Google Analytics events documentation is a useful reference for event names and parameters. Analytics events do not prove AI quality, customer fit, or revenue.
Cover user-understanding risks
Register ambiguous language, hidden human review, unclear limitations, inaccessible explanations, misleading examples, and a next step that suggests more certainty than the product offers. Test comprehension with the actual buyer context.
The GOV.UK Service Standard provides general prompts about user needs, joined services, privacy, success, and reliable operation. It is not an AI conversion standard, but it helps expose gaps in the complete journey.
Cover security and operational risks
Include prompt or input exposure, account access, integration boundaries, incident route, vendor outage, model change, logging, human escalation, and deletion. Record control, evidence, owner, trigger, and recovery.
Cover routing and capacity risks
Register enquiries that require unavailable model specialists, privacy review, security review, solution consulting, or human escalation. Define queue guardrail, fallback route, response target, and customer communication when the target is missed.
Score residual risk transparently
Use a documented likelihood, impact, detectability, and residual-risk scale. Explain evidence, uncertainty, accepted risk, expiry, and decision threshold. A red cell should trigger an action or escalation rather than remain a dashboard decoration.
Review advertising and comparison claims
Keep a claim ledger for performance, savings, testimonials, comparison, benchmark, customer result, and urgency wording. The FTC advertising and marketing guidance is a useful prompt for truthful and supportable promotion. It is not global AI or privacy law.
Define control evidence
Specify the observable proof: evaluation report, approved wording, limitation note, permission record, event test, accessibility check, queue sample, incident ticket, correction, or rollback test. Name source, frequency, owner, and retention.
Plan incident response and rollback
For each material risk, record trigger, containment, approver, notification, evidence preservation, page or campaign pause, claim correction, access removal, restoration, and closure test. Rehearse an inaccurate output claim, data-submission error, vendor outage, and withdrawn customer story.
What should the register contain?
Minimum columns: risk ID, page element, cause, event, impact, affected visitor or data, model boundary, signal, likelihood, control, evidence, owner, trigger, mitigation, escalation, rollback, residual score, accepted by, due date, review date, status, and notes.
This article is a local noindex draft. It does not certify an AI system, guarantee accuracy, privacy, safety, conversion, revenue, or customer outcomes. Complete editorial, source, overlap, privacy, security, accessibility, implementation, and owner review before publication.
How did this article land?
Choose one reaction. You can change it anytime.