The AI risk register for surveying firms: what goes in it, and the quarterly rule
RICS-regulated firms using AI materially must run a RAG-rated AI risk register, reviewed at least quarterly. What the standard says it must contain, with worked examples for QS practices.
Under section 3.3 of the RICS AI standard, firms whose AI use has a material impact on services must create and operate a risk register — and review and update it at least quarterly, by the people responsible for the firm's AI decisions. It is the living half of AI governance: the systems register says what you use; the risk register says what could go wrong and what you're doing about it.
What the standard says it must document
Overarching risks the register must cover:
- inherent bias in the AI system and its outputs,
- erroneous outputs,
- limits to the quantity and quality of information available about the system and its training data, and
- retention or use of data the firm puts into the system.
And for each risk, the entry must include:
- a description of the risk,
- likelihood and likely impact,
- the mitigation and management plan,
- the firm's risk appetite,
- regular status updates, and
- a RAG rating (red / amber / green) or similar categorisation.
Worked examples for a QS practice
- Drawing-measurement tool under-detects openings on scanned PDFs — likelihood medium, impact high (feeds cost plans); mitigation: surveyor re-measures a sample per project, logged; amber.
- Drafting assistant retains prompt content — information from vendor unclear; mitigation: no client-identifying data in prompts pending written vendor answers (see due diligence); amber until answered.
- Transcription mishears figures in meeting minutes — likelihood high, impact low-medium; mitigation: minutes reviewed before issue; green.
The quarterly rule is where firms fail
March-scramble registers die in drawer. The standard's cadence is explicit — reviewed and updated at least quarterly — and the reviewers are named in kind: staff responsible for AI decisions, not whoever is free. A firm that stood its register up for 9 March is on review two by now. What changes between reviews: new tools adopted mid-project, vendors changing models under your feet, and answers arriving (or not) to due-diligence letters. The compliance checklist pairs this with the other recurring duties.
Is the risk register the same as the AI systems register?
No. The systems register lists the AI systems, purposes and review dates (four fields, section 3.2). The risk register documents risks, likelihood/impact, mitigation, appetite, status and a RAG rating (section 3.3), and carries the quarterly review duty.
Can we fold AI risks into our existing firm risk register?
The standard requires the documented content and the quarterly AI review; it does not prescribe a separate binder. A clearly identifiable AI section in an existing register, meeting the content list above and actually reviewed quarterly by the right people, is a defensible implementation.
ComplyQS runs a RAG-rated AI risk register with review nudges, tied to the tools and projects it relates to — see the registers-and-logs guide for the walkthrough.
Set yours up freeThis article is general information, not legal or professional advice. ComplyQS is not affiliated with or endorsed by RICS. Related guide: /guides/registers-and-logs/.