The register exists so that risk knowledge survives beyond the meeting where it was discussed. It fixes each risk with an owner, an assessment, its controls and its treatment actions — which makes accountability enforceable. The dependent decision is follow-through: the register is where a leader checks whether the mitigation promised in March exists in September. Without it, risk management resets to zero with every staff change.
The register is maintained by the risk function, but its content belongs to the risk owners; entries are reviewed quarterly and the top risks monthly. It can live in a GRC platform or in a disciplined spreadsheet — the tool matters less than the rhythm. A healthy entry reads like a decision record: "dependence on a single logistics provider; impact — 3 days of stopped exports; mitigation — second provider contracted by Q3; owner — supply chain director". Stale dates and empty action columns are the first things an auditor looks for.
The notorious failure is the register as a cemetery: hundreds of entries, no closures, no link to budgets or continuity plans, updated only before the audit. A register no executive reads is not a control, it is an alibi. The role of the register in a working resilience system is examined in module M2 "From enterprise risk management to business resilience" of the ERGP programme.
| Field | Purpose |
|---|---|
| Identifier and date raised | Traceability and ageing, so stale entries are visible |
| Risk statement | Cause, event and consequence in one sentence |
| Category | Grouping for reporting and for spotting concentrations |
| Owner | A named person with authority to act, not a department |
| Inherent assessment | Likelihood and impact before controls |
| Existing controls | What is already in place and how effective it is |
| Residual assessment | Likelihood and impact after controls, the number that drives decisions |
| Treatment and actions | What will change, by whom, by when |
| Indicators | Early warning measures that show the risk moving before it materialises |
| Status and review date | Whether the entry is live, closed or overdue for review |
Most weak registers fail at the sentence level. A risk written as one word — cyber, staff, supplier — cannot be assessed, owned or treated. The reliable structure names the cause, the event and the consequence.
| Weak | Usable |
|---|---|
| Cyber risk | Because privileged access is not reviewed quarterly, an attacker could encrypt the core banking database, suspending payments for more than 24 hours |
| Key person risk | Because settlement reconciliation is documented only by one specialist, their departure could delay month-end close by two weeks |
| Supplier risk | Because the card processing service has no contracted alternative, a supplier outage could stop card transactions with no workaround |
| Regulatory risk | Because the continuity plan still refers to a superseded regulation, a supervisory review could result in a finding and a remediation deadline |
Three artefacts are routinely confused. The risk register holds things that might happen and how the organisation intends to influence them. The issue log holds things that have already happened and now need fixing. The risk report is the extract prepared for a committee, showing movement, breaches and decisions required. Keeping issues inside the register inflates it and hides the risks that still deserve a decision.
What is a risk register? A structured record of identified risks with their assessment, owner, controls, treatment and current status, maintained as a live management tool.
How often should a risk register be reviewed? Live entries at least quarterly, the full register at least annually, and immediately after any significant incident, organisational change or change in regulation.
Who owns the risk register? The risk function maintains it. Individual risks are owned by named executives who can authorise treatment. The board or a risk committee reviews the significant entries.
What is the difference between inherent and residual risk? Inherent risk is the exposure before existing controls are considered. Residual risk is what remains after them, and it is the figure against which appetite is compared.
Should a risk register include opportunities? It can, where the governance framework treats risk as effect of uncertainty in both directions. In practice most organisations keep a separate view so that downside exposure remains clearly visible.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme