Most businesses that decide to take risk seriously start by building a register. Most of those registers are quietly abandoned within a year.
The usual explanation is that people were too busy. The more accurate explanation is that the register was built as a record rather than a tool — something to be produced and filed, not consulted before decisions. Once that is true, maintaining it becomes pure cost, and it is rational to stop.
A register that survives is designed backwards from the moment it needs to be useful: someone is about to make a decision, and needs to know what could go wrong.
What a register is actually for
A working register does three jobs and no others:
- Makes exposure visible and comparable — so ten risks across five functions can be ranked against each other on a consistent basis.
- Assigns accountability — so every material risk has one person answerable for it.
- Triggers action — so a rating above an agreed threshold produces a decision rather than a note.
Any column that does not serve one of those three is overhead. This is the test to apply when someone proposes adding a field.
Write the risk, not the topic
The single most common structural fault is registers full of topics rather than risks.
"Cybersecurity" is not a risk. Neither is "supply chain" or "staff turnover". They are categories. You cannot assign a likelihood to a category, cannot tell whether it is getting better or worse, and cannot say what action would address it.
A usable risk statement has three parts: cause, event, consequence.
Reliance on a single supplier for a critical component (cause) could lead to an extended production stoppage (event), delaying customer orders and triggering contractual penalties (consequence).
That version can be rated, owned and acted on. Someone reading it knows immediately what would have to change for the risk to reduce. "Supply chain" tells them nothing.
This discipline is unpopular because it is slower to write. It is also the difference between a register that informs decisions and one that catalogues anxieties.
The columns that earn their place
Registers tend to accumulate columns. Each addition seems reasonable; the cumulative effect is a spreadsheet nobody wants to open. A practical minimum:
| Column | Why it earns its place |
|---|---|
| Risk ID | Lets people refer to a risk without retyping it |
| Risk statement | Cause, event, consequence — in plain language |
| Category | Groups risks for reporting, nothing more |
| Owner | A named person, never a department |
| Existing controls | What already reduces this, so effort is not duplicated |
| Likelihood | Rated against a defined scale |
| Impact | Rated against a defined scale |
| Rating | The combination that drives prioritisation |
| Treatment | What is being done, or a conscious decision to accept |
| Action owner and due date | Without a date, an action is an intention |
| Last reviewed | Makes staleness visible at a glance |
| Direction | Increasing, stable or decreasing since last review |
Two columns worth resisting early on: separate inherent and residual ratings, and elaborate scoring formulas. Both are legitimate in a mature framework. Both, introduced too early, double the maintenance burden before the basic habit has formed.
Rating without false precision
Numerical scales invite an accuracy that is not there. A risk scored 14 is not meaningfully worse than one scored 12, and treating it as though it is leads to arguments about arithmetic rather than judgement.
Two things make ratings more honest:
Define each point on the scale in your own terms. Impact should be described using measures your business actually recognises — days of disruption, customers affected, proportion of revenue at stake, regulatory consequence. Generic descriptors like "moderate" mean different things to different people in the same room.
Keep the scale small. Fewer points force a decision. Wider scales let people cluster everything in the middle, which is the same as not rating at all.
Recognised standards set out principles for establishing risk criteria of this kind, and organisations in regulated sectors may have specific requirements governing how risk is assessed and reported.
{{ADD SOURCE: ISO 31000 official reference page}}
{{ADD SOURCE: relevant Indian regulatory requirements on risk assessment and reporting by entity type}}
Keeping it alive
Maintenance is where registers die. Three habits do most of the work:
Keep it short. A register of fifteen risks that leadership genuinely knows beats one of eighty that nobody has read. Risks that are not material can live in a functional list rather than the enterprise register.
Fix the cadence in advance. Quarterly is a reasonable default for most businesses, with a trigger for interim review after significant change — a new market, a major system, an acquisition, a serious incident.
Review changes, not everything. A useful review meeting covers what has moved, what is overdue, and what is new. Reading all fifteen rows aloud guarantees the meeting becomes an obligation.
Failure modes to watch for
- One person maintains it alone. The register becomes their opinion rather than the organisation's position, and it dies when they move on.
- Ratings never change. Static ratings across several cycles usually mean the review is happening on paper only.
- Actions without owners or dates. These accumulate silently and make the register look busy while nothing progresses.
- It duplicates the audit plan. A register describes exposure; an audit plan describes assurance activity. Merging them tends to produce something that serves neither.
Where to start
Do not start with software. Start with a single page: your ten most significant risks, written as cause–event–consequence, each with a named owner and a rating against a scale you have defined. If that page is still current in three months, you have a functioning register and can add structure. If it is not, more sophisticated tooling would not have helped.
We publish a free risk register template with the column structure above and guidance on how to use each field — a reasonable starting point if you would rather not design one from scratch.
If you are less certain whether a register is the right first step, our free two-minute risk health check covers visibility and ownership alongside continuity and compliance, and points at whichever area is weakest. For background on how a register fits into a wider framework, see what enterprise risk management actually means.
And if you would like the structure designed around your business rather than adapted from a template, book a consultation — the first conversation carries no obligation.