What is inside
Four sheets. Register: 21 columns and a worked example in the first row, covering identification, scoring, treatment, residual risk, indicator and review dates; score and zone are formulas, zones are colour-coded, scoring cells accept only 1 to 5. Scales: five levels of likelihood and impact expressed in frequency and share of revenue. Categories: seven categories with typical owners, including compliance with NCEMA and sector rules. Summary: risks by zone.
| Column group | Columns | Who fills it |
|---|---|---|
| Identification | ID, category, risk event, causes, consequences, owner | Risk owner at the risk workshop |
| Scoring | Likelihood, impact, score (formula), zone (formula) | Owner, validated by the risk function |
| Treatment | Existing controls, actions, action owner, due date, status | Owner |
| Residual risk | Residual likelihood, impact, score (formula) | Owner after actions |
| Monitoring | KRI and threshold, assessed on, next review | Owner, risk function |
How to write a risk that can be managed
Half of all registers are useless because of one column: the risk is a single word. "Suppliers", "people", "IT" are categories, not risks. A workable statement has three parts: event, cause, consequence. Weak: "supplier risk". Strong: "production stops because the single supplier of component X ceases deliveries; cause: supplier insolvency or sanctions; consequence: line down for up to three weeks, missed shipments worth Y". From that sentence the treatment (second supplier, buffer stock), the indicator (share of spend with one supplier) and the impact score follow directly.
Download the template
Download the template. Register sheet with 30 rows, formulas and colour-coded zones; Scales, Categories and Summary sheets. Xlsx, opens in Excel, LibreOffice and Google Sheets.
Download xlsx (risk-register-template.xlsx)
Zone thresholds (1-4, 5-9, 10-14, 15-25) are edited in the Zone column formulas and in the conditional formatting. No registration, no forms. Need it adapted to your organisation or a full programme: see how we work.
Five rules that keep a register alive
- One owner for the register (the risk function) and one owner per row (the risk owner). Owners edit rows; the function consolidates.
- Review by calendar: red zone monthly, the rest quarterly, the whole register at the annual workshop. Overdue reviews are visible in the review column.
- Closed risks move to an archive sheet with a reason; history is what auditors and the next BIA use.
- Size discipline: 30-60 risks for a mid-size organisation, 5-10 of them key risks with their own one-page profile.
- Every change of score has a one-line reason; without it nobody remembers next year where the "4" came from.
When Excel stops being enough
The file works with one administrator and up to about 50 risks. Signs that a system is due: several people edit at once and versions diverge, you need change history with authors, indicators arrive from different sources and are collected by hand, the board report takes a week. The resilience metrics template covers the indicator side; the board reporting guide shows what the register has to feed.
Frequently asked questions
What columns must a risk register have?
At minimum: ID, risk stated as event, cause and consequence, owner, likelihood, impact, score, treatment actions with owner and due date, review date. The full 21-column set with formulas is in the template on this page.
How is the risk score calculated?
Likelihood multiplied by impact on five-point scales, giving 1 to 25. Scores map to zones: green 1-4, amber 5-9, orange 10-14, red 15-25; thresholds are set by the organisation and tied to its risk appetite.
How many risks should a register contain?
For a mid-size organisation 30-60, of which 5-10 are key risks. Registers with hundreds of rows become archives that nobody reviews.
How often should the register be updated?
Red-zone risks monthly, the rest quarterly, the full register at the annual workshop, and ad hoc after incidents, new projects or regulatory change.