Home · Glossary · Risk Register
Business continuity glossary

Risk Register

سجل المخاطر
The living record of identified risks with their owners, assessments, controls and treatment actions. A management tool, not a filing exercise.

The register exists so that risk knowledge survives beyond the meeting where it was discussed. It fixes each risk with an owner, an assessment, its controls and its treatment actions — which makes accountability enforceable. The dependent decision is follow-through: the register is where a leader checks whether the mitigation promised in March exists in September. Without it, risk management resets to zero with every staff change.

The register is maintained by the risk function, but its content belongs to the risk owners; entries are reviewed quarterly and the top risks monthly. It can live in a GRC platform or in a disciplined spreadsheet — the tool matters less than the rhythm. A healthy entry reads like a decision record: "dependence on a single logistics provider; impact — 3 days of stopped exports; mitigation — second provider contracted by Q3; owner — supply chain director". Stale dates and empty action columns are the first things an auditor looks for.

The notorious failure is the register as a cemetery: hundreds of entries, no closures, no link to budgets or continuity plans, updated only before the audit. A register no executive reads is not a control, it is an alibi. The role of the register in a working resilience system is examined in module M2 "From enterprise risk management to business resilience" of the ERGP programme.

What a risk register contains

FieldPurpose
Identifier and date raisedTraceability and ageing, so stale entries are visible
Risk statementCause, event and consequence in one sentence
CategoryGrouping for reporting and for spotting concentrations
OwnerA named person with authority to act, not a department
Inherent assessmentLikelihood and impact before controls
Existing controlsWhat is already in place and how effective it is
Residual assessmentLikelihood and impact after controls, the number that drives decisions
Treatment and actionsWhat will change, by whom, by when
IndicatorsEarly warning measures that show the risk moving before it materialises
Status and review dateWhether the entry is live, closed or overdue for review

Writing a usable risk statement

Most weak registers fail at the sentence level. A risk written as one word — cyber, staff, supplier — cannot be assessed, owned or treated. The reliable structure names the cause, the event and the consequence.

WeakUsable
Cyber riskBecause privileged access is not reviewed quarterly, an attacker could encrypt the core banking database, suspending payments for more than 24 hours
Key person riskBecause settlement reconciliation is documented only by one specialist, their departure could delay month-end close by two weeks
Supplier riskBecause the card processing service has no contracted alternative, a supplier outage could stop card transactions with no workaround
Regulatory riskBecause the continuity plan still refers to a superseded regulation, a supervisory review could result in a finding and a remediation deadline

Register, report and issue log

Three artefacts are routinely confused. The risk register holds things that might happen and how the organisation intends to influence them. The issue log holds things that have already happened and now need fixing. The risk report is the extract prepared for a committee, showing movement, breaches and decisions required. Keeping issues inside the register inflates it and hides the risks that still deserve a decision.

Common mistakes

Questions

What is a risk register? A structured record of identified risks with their assessment, owner, controls, treatment and current status, maintained as a live management tool.

How often should a risk register be reviewed? Live entries at least quarterly, the full register at least annually, and immediately after any significant incident, organisational change or change in regulation.

Who owns the risk register? The risk function maintains it. Individual risks are owned by named executives who can authorise treatment. The board or a risk committee reviews the significant entries.

What is the difference between inherent and residual risk? Inherent risk is the exposure before existing controls are considered. Residual risk is what remains after them, and it is the figure against which appetite is compared.

Should a risk register include opportunities? It can, where the governance framework treats risk as effect of uncertainty in both directions. In practice most organisations keep a separate view so that downside exposure remains clearly visible.

Related termsRisk Owner Risk Assessment KRI · Key Risk Indicator
Free handbookBCM without illusions (Gulf edition) — a practical map of business continuity for executives. Download free →

This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.

Explore the ERGP programme