Build a risk register for your own process. It is the document that turns this module from reading into something you can hand to a legal team.
What to do
- List every point where AI touches hiring, across everything you built in Modules 4 to 9.
- For each, write what could go wrong for a candidate — not for you.
- Rate how likely it is and how bad it would be: low, medium or high. Avoid scoring out of ten; it suggests a precision you do not have.
- Name what already stops it happening, if anything.
- Name the gap, and one action with a person's name against it.
- Use the four questions from Lesson 1 to work out which rules apply to you.
Risks to include as a minimum
| Risk | Comes from |
|---|---|
| A CV format is read badly, so a whole group is quietly excluded | Module 4, Lesson 2 |
| Rules are too strict and remove good people invisibly | Module 4, Lesson 3 |
| A tool learning from past hires repeats old patterns | Module 5, Lesson 1 |
| The explanation given is decoration, not the real reason | Module 5, Lesson 4 |
| Found profiles kept with no reason and no deletion date | Module 3, Lesson 7 |
| A chatbot screens people without them knowing | Module 6, Lesson 4 |
| Automation follows instructions hidden inside a CV | Module 9, Lesson 2 |
| You cannot find all of one person's data to delete it | Module 11, Lesson 4 |
What to hand in
The register, plus three things you will actually fix this quarter — each with a person's name and a date.
How to know you have done it right
| Check | Good looks like |
|---|---|
| It is about candidates | Risks describe harm to people, not just exposure to you |
| Nothing is missed | Every point where AI touches hiring appears |
| Honest about controls | Nothing listed that you do not actually do |
| Named owners | Every action has a person, not a team |
| Accepted risks are marked | Where you are choosing to live with something, it says so |
That last row is what makes a register real. Every organisation accepts some risk. The ones in trouble are the ones that never wrote down which.
Check yourself before Module 12
- Which risk did you most want to leave off the list? That is usually the one to look at hardest.
- Could you hand this to a lawyer tomorrow without rewriting it?
- Is there a control listed that you believe happens but have never actually checked?
- Which set of rules applies to you that you had not thought about?
Review it on a date, not after an incident
Every three months, in the calendar, alongside your list of tools. Registers that only get reviewed after something goes wrong are incident reports written in advance and never read.