Risk Register

Likelihood and Impact scored 1–5. Risk Score = Likelihood × Impact. Scores ≥16 = Critical; 10–15 = High; 5–9 = Medium; <5 = Low.

IDCategoryRisk DescriptionLIScoreOwnerMitigationStatus
R-01 Privacy Google Workspace Gemini AI features active for under-14 students with no parental consent — violates Ley 1581/2012 / Decreto 1377/2013 55 25 IT Director Admin console restrictions applied (Week 1). Parent consent form issued and collected before feature re-enabled. Closed
R-02 Data Protection No Data Processing Agreements with any AI vendor — student PII potentially processed without legal basis 54 20 IT Director DPAs signed with Google, Schoology, Canva, Grammarly. Edmodo DPA pending (tool suspended). 3 tools permanently removed. Mitigated
R-03 Academic Integrity Students in Grades 9–12 submitting AI-generated work as their own in IB assessments — risk of IBO investigation and student disqualification 45 20 Head of School AI use disclosure policy embedded in academic integrity framework. Turnitin AI detection enabled. Curriculum-level AI literacy integrated in Grades 7–12. Mitigated
R-04 Safeguarding AI-generated deepfake or manipulated images of students created and shared via social media or messaging apps — reputational and emotional harm 35 15 Pastoral Director Digital citizenship module updated with AI image misuse content. Incident response pathway documented. Any prior incident logged and reviewed — record its reference here, or state that none is known. Mitigated
R-05 Vendor Risk Third-party AI vendor data breach exposes student PII — school held liable under Ley 1581/2012 for insufficient vendor oversight 35 15 IT Director Vendor due diligence checklist adopted. Annual security review clause added to all new DPAs. Breach notification SLA (15 business days to SIC) documented. Monitoring
R-06 Equity AI-powered assessment tools producing biased outcomes for EAL/ESL students or students with learning differences — discriminatory impact 34 12 Learning Support Coordinator Equity audit completed in Pilot Phase. Schoology AI analytics reviewed — no evidence of bias found for current configuration. Annual equity audit added to governance calendar. Mitigated
R-07 Compliance Edmodo data sharing practices unverified — potential student data transfer to commercial third parties 43 12 IT Director Edmodo suspended pending DPA review. Replacement LMS (Google Classroom integration) activated for affected classes. Monitoring
R-08 Reputational Parent/community trust erosion due to school using AI tools without disclosure or consent — media or board-level escalation 43 12 Superintendent Parent information session held Jan 2026 (attendance: [N]%). AI policy published on school website. Regular AI governance updates added to school newsletter. Closed
R-09 Operations Staff using personal free-tier AI accounts (ChatGPT, Claude, Gemini) with student data — no school oversight or DPA coverage 43 12 IT Director Policy §5 explicitly prohibits input of student PII into non-approved tools. Communicated in mandatory staff training. If an occurrence is known, log it and record the reference here. Mitigated
R-10 Safeguarding Student interactions with AI chatbots (tutoring tools) revealing safeguarding concerns — no escalation pathway to a human 25 10 Pastoral Director Policy §7 requires all AI chatbot tools to route disclosures to a qualified human. Reviewed in counsellor training. Added to chatbot tool approval checklist criteria. Closed
R-11 Compliance No formal incident register — inability to demonstrate compliance or investigate patterns of AI misuse 52 10 AI Policy Owner (IT Director) Policy Incident Register created and active from January 2026. 4 incidents logged to date (see below). Closed
R-12 Operations AI features automatically activated in future Google Workspace updates — governance oversight bypassed 33 9 IT Director Quarterly IT admin review of Google Workspace release notes added to governance calendar. Policy §8 requires IT Director sign-off before any new AI feature is activated. Monitoring
R-13 Curriculum Teachers over-relying on AI for feedback generation — students receiving generic, AI-authored feedback without teacher review 33 9 Academic Director Policy §4 requires human review before AI-generated feedback is delivered. Pedagogical guidance included in teacher training module. Closed
R-14 Equity Students without home internet access disadvantaged by AI-assisted homework tools — equity gap widens 23 6 Academic Director AI homework tools restricted to in-school use for Grades 1–5. Equity impact included in annual equity audit criteria. Mitigated
R-15 Governance AI Policy Owner role unfilled after staff turnover — governance cadence breaks down 23 6 Superintendent Governance Panel acts as backup authority. Succession plan included in handover checklist. Two staff designated as co-deputies. Closed
R-16 Compliance Colombia CONPES 4144 (2025) introduces new AI requirements — school not aware or not compliant in time 22 4 IT Director Policy includes 6-month mandatory review with regulatory scan. SIC guidance monitoring added to governance calendar. Monitoring
Policy Incident Register

All incidents are logged below. The two entries shown are worked examples, not events at any school — they exist to show the shape of a complete entry: what happened, who was told, what changed as a result. Replace them with your own, or empty the register and say so. This register demonstrates the school's accountability posture and provides evidence for regulatory review. Incidents are classified P1 (Critical), P2 (Serious), or P3 (Minor).

INC-001 · P2 — Serious
AI-generated manipulated student images shared via WhatsApp
Resolved October 2025

What Happened

A group of Grade 10 students used a free AI image generator (not a school tool) to create manipulated images of two female classmates and shared them in a private WhatsApp group. Screenshots reached school staff via a parent complaint.

Impact

Two students experienced significant distress. One family threatened formal complaint to SIC. No student data from school systems was involved — images were based on personal social media photos.

Response Timeline

Day 0Pastoral Director informed by parent. Affected students offered counselling support immediately.
Day 1Head of School meets with involved students and families. Content removal requested.
Day 3Disciplinary process completed per Student Code of Conduct. Images confirmed removed.
Day 7All-school assembly on AI image misuse and digital respect. No SIC complaint filed.

Policy Outcome

Added to Risk Register as R-04. AI image misuse module added to Digital Citizenship curriculum. Policy §5 explicitly prohibits AI-generated images of students.

INC-002 · P3 — Minor
Teacher uploads student grade data into personal ChatGPT account for report writing
Resolved November 2025

What Happened

A primary school teacher (Grade 4) used a personal free-tier ChatGPT account to draft student report comments. She pasted a spreadsheet containing student names, grades, and teacher notes into the prompt. The incident was self-reported after the teacher attended an external AI workshop.

Impact

PII of 24 students (names + academic performance data) was processed by OpenAI systems without a Data Processing Agreement. No evidence of data misuse. Rated P3 due to limited scope and self-disclosure.

Response Timeline

Day 0Teacher self-reports to IT Director. Immediate support offered — no disciplinary action given voluntary disclosure.
Day 2IT Director assesses exposure. ChatGPT terms confirmed data not retained beyond session (free tier). Risk assessed as low.
Day 5Interim staff guidance issued school-wide prohibiting student PII in unapproved tools.
Day 14Incident highlighted (anonymised) in mandatory staff training as a teaching case.

Policy Outcome

Strengthened Risk R-09. Policy §5 prohibition on student PII in unapproved tools made explicit. Report-writing AI workflow using school-approved Gemini (within DPA) created as approved alternative.

INC-003 · P2 — Serious
IB student submits AI-generated extended essay without disclosure
Resolved January 2026

What Happened

A Grade 12 student submitted a draft Extended Essay that Turnitin AI detection flagged at [N]% AI-generated probability. On review, the essay showed no evidence of the student's own voice or research process. The student admitted using ChatGPT to write the full draft and "editing it slightly."

Impact

Student required to resubmit. IBO Academic Integrity policies triggered. Student placed on academic integrity monitoring for remainder of DP. Family briefed. No formal IBO investigation triggered as the submission was a draft stage.

Response Timeline

Day 0Turnitin flag reviewed by DP Coordinator. Student meeting called.
Day 1Student admits use. Academic Integrity team and Head of School informed. Family contacted.
Day 3Academic integrity process completed per IBO guidelines. Resubmission deadline set.
Day 10Grade 9–12 AI use in assessments lesson embedded in DP/MYP coordinator sessions.

Policy Outcome

Triggered Policy §5 academic integrity provisions. AI disclosure requirement added to all IB assessment cover sheets. Turnitin AI detection enabled for all Grade 9–12 submissions.

INC-004 · P3 — Minor
AI chatbot (tutoring app) provides inappropriate response to Grade 6 student
Resolved February 2026

What Happened

A Grade 6 student using a school-approved AI tutoring feature within Schoology received a response to a homework question that included an adult-level discussion of a political conflict when the student asked a vague geography question. No harmful content — the response was simply age-inappropriate in depth and framing. Parent notified school.

Impact

No student harm. Parent concern was resolved after explanation. Rated P3. Highlighted the need for content guardrail review in LMS AI features.

Response Timeline

Day 0IT Director notified. Schoology AI tutoring feature reviewed. Content settings assessed.
Day 1Parent meeting. School confirms no ongoing risk. Apology issued.
Day 4Schoology support ticket raised for content guardrail review. Settings tightened for Middle School accounts.

Policy Outcome

Age-appropriate content filtering added as mandatory criterion in Tool Approval Checklist. Schoology vendor informed. Annual content guardrail review added to governance calendar.