Risk register template in Excel: formulas, scales, heat map zones

Template · Excel · Risk

Risk register template: Excel with formulas and a worked example

The register is where risk management lives or dies: the heat map, the board report and the indicators all read from it. This template scores and colours risks by formula and comes with the scales a GCC organisation needs. What a risk register is, in one definition, is in the glossary; this page is about the file and how to run it.

What is inside

Four sheets. Register: 21 columns and a worked example in the first row, covering identification, scoring, treatment, residual risk, indicator and review dates; score and zone are formulas, zones are colour-coded, scoring cells accept only 1 to 5. Scales: five levels of likelihood and impact expressed in frequency and share of revenue. Categories: seven categories with typical owners, including compliance with NCEMA and sector rules. Summary: risks by zone.

Column groupColumnsWho fills it
IdentificationID, category, risk event, causes, consequences, ownerRisk owner at the risk workshop
ScoringLikelihood, impact, score (formula), zone (formula)Owner, validated by the risk function
TreatmentExisting controls, actions, action owner, due date, statusOwner
Residual riskResidual likelihood, impact, score (formula)Owner after actions
MonitoringKRI and threshold, assessed on, next reviewOwner, risk function

How to write a risk that can be managed

Half of all registers are useless because of one column: the risk is a single word. "Suppliers", "people", "IT" are categories, not risks. A workable statement has three parts: event, cause, consequence. Weak: "supplier risk". Strong: "production stops because the single supplier of component X ceases deliveries; cause: supplier insolvency or sanctions; consequence: line down for up to three weeks, missed shipments worth Y". From that sentence the treatment (second supplier, buffer stock), the indicator (share of spend with one supplier) and the impact score follow directly.

Download the template

Download the template. Register sheet with 30 rows, formulas and colour-coded zones; Scales, Categories and Summary sheets. Xlsx, opens in Excel, LibreOffice and Google Sheets.

Download xlsx (risk-register-template.xlsx)

Zone thresholds (1-4, 5-9, 10-14, 15-25) are edited in the Zone column formulas and in the conditional formatting. No registration, no forms. Need it adapted to your organisation or a full programme: see how we work.

Five rules that keep a register alive

  1. One owner for the register (the risk function) and one owner per row (the risk owner). Owners edit rows; the function consolidates.
  2. Review by calendar: red zone monthly, the rest quarterly, the whole register at the annual workshop. Overdue reviews are visible in the review column.
  3. Closed risks move to an archive sheet with a reason; history is what auditors and the next BIA use.
  4. Size discipline: 30-60 risks for a mid-size organisation, 5-10 of them key risks with their own one-page profile.
  5. Every change of score has a one-line reason; without it nobody remembers next year where the "4" came from.

When Excel stops being enough

The file works with one administrator and up to about 50 risks. Signs that a system is due: several people edit at once and versions diverge, you need change history with authors, indicators arrive from different sources and are collected by hand, the board report takes a week. The resilience metrics template covers the indicator side; the board reporting guide shows what the register has to feed.

Frequently asked questions

What columns must a risk register have?

At minimum: ID, risk stated as event, cause and consequence, owner, likelihood, impact, score, treatment actions with owner and due date, review date. The full 21-column set with formulas is in the template on this page.

How is the risk score calculated?

Likelihood multiplied by impact on five-point scales, giving 1 to 25. Scores map to zones: green 1-4, amber 5-9, orange 10-14, red 15-25; thresholds are set by the organisation and tied to its risk appetite.

How many risks should a register contain?

For a mid-size organisation 30-60, of which 5-10 are key risks. Registers with hundreds of rows become archives that nobody reviews.

How often should the register be updated?

Red-zone risks monthly, the rest quarterly, the full register at the annual workshop, and ad hoc after incidents, new projects or regulatory change.

More on risk and resilience

Register full of risks and short of decisions? A gap assessment prices each one in days of downtime.

Request a gap assessmentTake the free readiness check
NCEMA-ready gap assessment
Turn it into numbersResilience audit and improvement

We audit your continuity system against AE/SCNS/NCEMA 7000 and ISO 22301, then raise the metrics that decide survival — with risk surveys, methodology and on-site training included where you need them.

How the audit works →