ComplyQS
HomeArticles › The AI risk register for surveying firms: what goes in it, and the quarterly rule

The AI risk register for surveying firms: what goes in it, and the quarterly rule

RICS-regulated firms using AI materially must run a RAG-rated AI risk register, reviewed at least quarterly. What the standard says it must contain, with worked examples for QS practices.

Under section 3.3 of the RICS AI standard, firms whose AI use has a material impact on services must create and operate a risk register — and review and update it at least quarterly, by the people responsible for the firm's AI decisions. It is the living half of AI governance: the systems register says what you use; the risk register says what could go wrong and what you're doing about it.

What the standard says it must document

Overarching risks the register must cover:

And for each risk, the entry must include:

Worked examples for a QS practice

The quarterly rule is where firms fail

March-scramble registers die in drawer. The standard's cadence is explicit — reviewed and updated at least quarterly — and the reviewers are named in kind: staff responsible for AI decisions, not whoever is free. A firm that stood its register up for 9 March is on review two by now. What changes between reviews: new tools adopted mid-project, vendors changing models under your feet, and answers arriving (or not) to due-diligence letters. The compliance checklist pairs this with the other recurring duties.

Is the risk register the same as the AI systems register?

No. The systems register lists the AI systems, purposes and review dates (four fields, section 3.2). The risk register documents risks, likelihood/impact, mitigation, appetite, status and a RAG rating (section 3.3), and carries the quarterly review duty.

Can we fold AI risks into our existing firm risk register?

The standard requires the documented content and the quarterly AI review; it does not prescribe a separate binder. A clearly identifiable AI section in an existing register, meeting the content list above and actually reviewed quarterly by the right people, is a defensible implementation.

ComplyQS runs a RAG-rated AI risk register with review nudges, tied to the tools and projects it relates to — see the registers-and-logs guide for the walkthrough.

Set yours up free

This article is general information, not legal or professional advice. ComplyQS is not affiliated with or endorsed by RICS. Related guide: /guides/registers-and-logs/.