A well-maintained risk register helps management identify, prioritise, and respond to risks effectively. All entities, regardless of size, complexity, or service delivery role, should document and regularly update their risks in a risk register to support effective management and ongoing monitoring.
Risk registers also support communication between those responsible for overseeing risk management and risk owners responsible for managing individual risks. They provide a clear record of key risks, planned responses, and accountability for managing each risk. This clarity is important because treating risks often requires collaboration between internal subject matter experts and, where necessary, external specialists.
Our earlier blog, Risk management – where do we start?, introduced the principles of risk management and discussed our Risk management maturity model tool. Our latest blog, Performing a risk assessment, explains how entities can assess likelihood, consequence, overall risk ratings, residual risks, and treatment actions.
In this blog, we highlight why a reliable risk register is integral to managing risk and what it should include.
What should entities include in their risk register?
Risk statements
A risk statement describes the risk and clearly explains the:
- event – what could happen
- cause – why it could happen
- effect/consequence – the potential impact on the entity, such as financial loss, reputational damage, legal liability, or disruption to critical services.
Risk statements should be specific, concise, and written in language that stakeholders can easily understand – they should be jargon free or technical information should be explained.
To illustrate what this might look like in practice, let's consider an example called ‘Entity A’, which is documenting a cyber security risk in its register. Entity A may describe this risk as follows:
'Entity A may experience a cyber security incident (the event), due to unauthorised access, a data breach, software vulnerabilities, outdated systems, or increasingly sophisticated cyber threats (the causes). This could disrupt critical services and result in financial loss, reputational damage, legal liability, and regulatory non-compliance (the effect).’
Risk ownership
Each risk should be assigned to an appropriately senior officer in the entity (risk owner) who is accountable for tracking, managing, and reporting on the risk to those charged with governance (accountable officer, executive leadership team, board, or other oversight body).
Risk owners are responsible for ensuring appropriate controls and treatment plans are in place to effectively manage that risk. They may be supported by other officers who have responsibility for implementing the controls or treatment plans.
The risk owner should be clearly identified in the risk register to ensure this responsibility is visible to everyone within the entity. For example, Entity A could assign responsibility for managing the cyber security risk to its chief information officer.
Risk categories
Entities may benefit from grouping risks based on their causes, threats, type, or potential impacts. Common risk categories include:
- strategic
- financial
- operational
- regulatory compliance
- reputation
- people
- technology.
Categorising risks allows management and those charged with governance to analyse the risk register to identify trends, understand common risk drivers, and assign ownership more effectively. The classifications an entity adopts will depend on its size, operations, and risk profile. In our example, Entity A might categorise the risk under ‘technology’ or ‘information security’. Entities should ensure consistency in how they categorise risks and types of risks over time.
Risk assessment, controls, and treatment
Once an entity has performed an assessment of its risks, it should record the results in its risk register, including the:
- likelihood rating
- consequence rating
- overall inherent risk rating
- effectiveness of controls in mitigating the risk
- residual risk rating
- assessment date.
The risk register should also document a brief description of the key controls the entity uses to manage each risk and any treatment actions required to further reduce risk exposure.
In addition, entities may also include the risk appetite for each risk. Risk appetite is the level (or range) of residual risk the entity considers acceptable and justifiable. The risk appetite of individual entities will differ depending upon the environment within which the entity operates. The level of risk appetite may also be different for different risk types or different risk categories.
Including the risk appetite in the risk register allows management and those charged with governance to easily identify those risks for which the residual risk rating is outside of the approved risk appetite and where further action may be required to mitigate the risk. For guidance on assessing likelihood, consequence, controls, and treatment actions, see our blog on Performing a risk assessment.
Why do all entities need a risk register?
To monitor and review their risks
Risks change over time. New threats emerge, controls evolve, and organisational priorities shift.
Entities should periodically review and update their risk registers to ensure they accurately reflect the current risk environment, risk management activities, and risk appetite.
To communicate findings to those charged with governance
Management should provide regular risk updates to those charged with governance so they understand matters that may affect the entity. The approach and timing of these updates should reflect the entity’s size, complexity, and operations.
Those charged with governance may assign oversight of risk management to an audit and risk committee or a dedicated risk committee. This allows the committee to examine detailed information from management and operational staff, including the risk register, and seek clarification where needed. It also reinforces accountability for management and risk owners in managing risks effectively.
For example, Entity A could create a risk committee to oversee risk management and review reports from management. It might also request risk owners responsible for addressing cyber security risks to attend meetings to present on these risks and answer questions from the committee members. Management could then provide quarterly summaries to those charged with governance on any significant developments, impacts, or actions taken on Entity A’s cyber security risks.
This reporting would help leaders gain assurance that Entity A’s controls are designed to prevent breaches and safeguard its data. It would also support informed strategic decisions, such as shaping Entity A’s IT strategy or information security framework.
Overall, a risk register is more than a list of risks. It brings together information about an organisation's key risks, ownership, assessment outcomes, controls, and treatment actions in a single source. By maintaining an up-to-date risk register, entities can strengthen oversight, improve decision-making, and support proactive risk management.
Resources
Blogs: