Skip to content
moirai
Product
Pricing
Buyers
Follow-up previewSynthetic follow-up evidence loopSecurityPrivacy and control posturePublic verifierHash-only evidence lookup
Research
Demo
Take the tour15-minute compatibility loopInteractive demoFollow-up status walkthroughBlogEvidence and operations notes
About
Sign inVerifyPreview
Menu
ProductPricing
Buyers
OverviewFollow-up previewSecurityPublic verifier
Research
Demo
OverviewTake the tourInteractive demoBlog
About
Sign inPreviewOpen Follow-up Preview
placeholder
  • Route4.00 kB
  • First-load160 kB
  • StatusBudget
moirai

The evidentiary backbone for clinical AI oversight. Built around current Australian governance references.

Stay informed

Monthly digest of regulatory changes and clinical AI best practices.

Platform

  • Overview
  • Security
  • Trust Center
  • Pricing
  • Changelog
  • Demo

Proof

  • Research Ledger
  • Follow-up Preview
  • Public Verifier

Resources

  • Follow-up Preview
  • Security
  • Blog

Company

  • About
  • Contact
  • System Status

AU data sovereignty·Encryption at rest & in transit·Trust Center →

Trust signals

Hash VerifiedSHA-256 sealed
Enterprise SecurityAES-256, RLS, audit
External RefsRANZCR, TGA, Ahpra
Risk ControlsMonitoring + incidents
on the record.
Mapped toRANZCRChapter 9TGASaMDAhpraAI obligationsACSQHCNSQHSDISRAI plan
© 2026 Moirai Health Pty Ltd. All rights reserved.
Privacy PolicyTerms of ServiceSecurityTrust CenterDPA
All systems operational
Back to Guide posts
GuideJanuary 30, 202612 min read

Building a clinical AI risk register from scratch

M

Moirai Team

Clinical AI Governance

Share

A clinical AI risk register is the foundational document that underpins your practice's governance framework. It catalogues every risk associated with your AI tools, assesses their likelihood and severity, and documents the controls you have in place to mitigate them. Without one, your governance framework lacks the structure needed to demonstrate due diligence to regulators, insurers, or courts.

Start by identifying all AI tools in clinical use and listing the specific risks each one introduces. For a radiology AI tool, these might include false negative findings, alert fatigue from excessive false positives, workflow disruption during system outages, or patient data exposure through cloud processing. For each risk, assess the likelihood of occurrence and the severity of potential harm using a standard risk matrix aligned with ISO 14971 principles.

Next, document the controls in place for each identified risk. Controls can be preventive (e.g., requiring radiologist sign-off before AI findings are included in reports), detective (e.g., monthly concordance audits), or corrective (e.g., a defined process for disabling a tool that falls below accuracy thresholds). Each control should have an assigned owner and a review frequency. At minimum, risk assessments should be reviewed annually and whenever a tool, workflow, intended use, or vendor release materially changes.

The final step is making the register a living document. Schedule quarterly reviews, integrate it with your incident reporting process, and ensure new AI tool deployments trigger a risk assessment before clinical use begins. Moirai automates much of this workflow, pre-populating risk categories based on tool type and generating review reminders, but the clinical judgment behind each assessment must come from your team.

Found this useful?

Share

Ready to govern your AI?

See the synthetic follow-up evidence loop and how Moirai surfaces the recommendations already written in your reports.

See the follow-up preview

Related articles

Guide

Building a clinical AI governance framework from scratch

Regulatory

TGA's evolving approach to AI as a medical device

Case Study

What we learned auditing 12 radiology AI tools