Likelihood and Impact scored 1–5. Risk Score = Likelihood × Impact. Scores ≥16 = Critical; 10–15 = High; 5–9 = Medium; <5 = Low.
| ID | Category | Risk Description | L | I | Score | Owner | Mitigation | Status |
|---|---|---|---|---|---|---|---|---|
| R-01 | Privacy | Google Workspace Gemini AI features active for under-14 students with no parental consent — violates Ley 1581/2012 / Decreto 1377/2013 | 5 | 5 | 25 | IT Director | Admin console restrictions applied (Week 1). Parent consent form issued and collected before feature re-enabled. | Closed |
| R-02 | Data Protection | No Data Processing Agreements with any AI vendor — student PII potentially processed without legal basis | 5 | 4 | 20 | IT Director | DPAs signed with Google, Schoology, Canva, Grammarly. Edmodo DPA pending (tool suspended). 3 tools permanently removed. | Mitigated |
| R-03 | Academic Integrity | Students in Grades 9–12 submitting AI-generated work as their own in IB assessments — risk of IBO investigation and student disqualification | 4 | 5 | 20 | Head of School | AI use disclosure policy embedded in academic integrity framework. Turnitin AI detection enabled. Curriculum-level AI literacy integrated in Grades 7–12. | Mitigated |
| R-04 | Safeguarding | AI-generated deepfake or manipulated images of students created and shared via social media or messaging apps — reputational and emotional harm | 3 | 5 | 15 | Pastoral Director | Digital citizenship module updated with AI image misuse content. Incident response pathway documented. Any prior incident logged and reviewed — record its reference here, or state that none is known. | Mitigated |
| R-05 | Vendor Risk | Third-party AI vendor data breach exposes student PII — school held liable under Ley 1581/2012 for insufficient vendor oversight | 3 | 5 | 15 | IT Director | Vendor due diligence checklist adopted. Annual security review clause added to all new DPAs. Breach notification SLA (15 business days to SIC) documented. | Monitoring |
| R-06 | Equity | AI-powered assessment tools producing biased outcomes for EAL/ESL students or students with learning differences — discriminatory impact | 3 | 4 | 12 | Learning Support Coordinator | Equity audit completed in Pilot Phase. Schoology AI analytics reviewed — no evidence of bias found for current configuration. Annual equity audit added to governance calendar. | Mitigated |
| R-07 | Compliance | Edmodo data sharing practices unverified — potential student data transfer to commercial third parties | 4 | 3 | 12 | IT Director | Edmodo suspended pending DPA review. Replacement LMS (Google Classroom integration) activated for affected classes. | Monitoring |
| R-08 | Reputational | Parent/community trust erosion due to school using AI tools without disclosure or consent — media or board-level escalation | 4 | 3 | 12 | Superintendent | Parent information session held Jan 2026 (attendance: [N]%). AI policy published on school website. Regular AI governance updates added to school newsletter. | Closed |
| R-09 | Operations | Staff using personal free-tier AI accounts (ChatGPT, Claude, Gemini) with student data — no school oversight or DPA coverage | 4 | 3 | 12 | IT Director | Policy §5 explicitly prohibits input of student PII into non-approved tools. Communicated in mandatory staff training. If an occurrence is known, log it and record the reference here. | Mitigated |
| R-10 | Safeguarding | Student interactions with AI chatbots (tutoring tools) revealing safeguarding concerns — no escalation pathway to a human | 2 | 5 | 10 | Pastoral Director | Policy §7 requires all AI chatbot tools to route disclosures to a qualified human. Reviewed in counsellor training. Added to chatbot tool approval checklist criteria. | Closed |
| R-11 | Compliance | No formal incident register — inability to demonstrate compliance or investigate patterns of AI misuse | 5 | 2 | 10 | AI Policy Owner (IT Director) | Policy Incident Register created and active from January 2026. 4 incidents logged to date (see below). | Closed |
| R-12 | Operations | AI features automatically activated in future Google Workspace updates — governance oversight bypassed | 3 | 3 | 9 | IT Director | Quarterly IT admin review of Google Workspace release notes added to governance calendar. Policy §8 requires IT Director sign-off before any new AI feature is activated. | Monitoring |
| R-13 | Curriculum | Teachers over-relying on AI for feedback generation — students receiving generic, AI-authored feedback without teacher review | 3 | 3 | 9 | Academic Director | Policy §4 requires human review before AI-generated feedback is delivered. Pedagogical guidance included in teacher training module. | Closed |
| R-14 | Equity | Students without home internet access disadvantaged by AI-assisted homework tools — equity gap widens | 2 | 3 | 6 | Academic Director | AI homework tools restricted to in-school use for Grades 1–5. Equity impact included in annual equity audit criteria. | Mitigated |
| R-15 | Governance | AI Policy Owner role unfilled after staff turnover — governance cadence breaks down | 2 | 3 | 6 | Superintendent | Governance Panel acts as backup authority. Succession plan included in handover checklist. Two staff designated as co-deputies. | Closed |
| R-16 | Compliance | Colombia CONPES 4144 (2025) introduces new AI requirements — school not aware or not compliant in time | 2 | 2 | 4 | IT Director | Policy includes 6-month mandatory review with regulatory scan. SIC guidance monitoring added to governance calendar. | Monitoring |
All incidents are logged below. The two entries shown are worked examples, not events at any school — they exist to show the shape of a complete entry: what happened, who was told, what changed as a result. Replace them with your own, or empty the register and say so. This register demonstrates the school's accountability posture and provides evidence for regulatory review. Incidents are classified P1 (Critical), P2 (Serious), or P3 (Minor).
What Happened
A group of Grade 10 students used a free AI image generator (not a school tool) to create manipulated images of two female classmates and shared them in a private WhatsApp group. Screenshots reached school staff via a parent complaint.
Impact
Two students experienced significant distress. One family threatened formal complaint to SIC. No student data from school systems was involved — images were based on personal social media photos.
Response Timeline
Policy Outcome
Added to Risk Register as R-04. AI image misuse module added to Digital Citizenship curriculum. Policy §5 explicitly prohibits AI-generated images of students.
What Happened
A primary school teacher (Grade 4) used a personal free-tier ChatGPT account to draft student report comments. She pasted a spreadsheet containing student names, grades, and teacher notes into the prompt. The incident was self-reported after the teacher attended an external AI workshop.
Impact
PII of 24 students (names + academic performance data) was processed by OpenAI systems without a Data Processing Agreement. No evidence of data misuse. Rated P3 due to limited scope and self-disclosure.
Response Timeline
Policy Outcome
Strengthened Risk R-09. Policy §5 prohibition on student PII in unapproved tools made explicit. Report-writing AI workflow using school-approved Gemini (within DPA) created as approved alternative.
What Happened
A Grade 12 student submitted a draft Extended Essay that Turnitin AI detection flagged at [N]% AI-generated probability. On review, the essay showed no evidence of the student's own voice or research process. The student admitted using ChatGPT to write the full draft and "editing it slightly."
Impact
Student required to resubmit. IBO Academic Integrity policies triggered. Student placed on academic integrity monitoring for remainder of DP. Family briefed. No formal IBO investigation triggered as the submission was a draft stage.
Response Timeline
Policy Outcome
Triggered Policy §5 academic integrity provisions. AI disclosure requirement added to all IB assessment cover sheets. Turnitin AI detection enabled for all Grade 9–12 submissions.
What Happened
A Grade 6 student using a school-approved AI tutoring feature within Schoology received a response to a homework question that included an adult-level discussion of a political conflict when the student asked a vague geography question. No harmful content — the response was simply age-inappropriate in depth and framing. Parent notified school.
Impact
No student harm. Parent concern was resolved after explanation. Rated P3. Highlighted the need for content guardrail review in LMS AI features.
Response Timeline
Policy Outcome
Age-appropriate content filtering added as mandatory criterion in Tool Approval Checklist. Schoology vendor informed. Annual content guardrail review added to governance calendar.