The risk register is one of the most common documents in governance and one of the least used. It is compiled for the annual report or the audit committee, reviewed once a year, and otherwise sits unchanged while the risks it describes rise and fall. When something goes wrong, the risk is often found on the register, rated amber, with a control that nobody had tested.
Describe risks so they can be managed
A risk described as "regulatory risk" or "cyber risk" cannot be owned, measured or controlled, because it is a category rather than a risk. A useful description names the cause, the event and the consequence: "Because customer onboarding checks are performed manually by a small team, a surge in applications could lead to incomplete checks, resulting in regulatory breach and fines."
Written this way, each part suggests something to manage. The cause points to a preventive control, the event to a detective one, and the consequence to the impact that should drive the rating.
Rate consistently
Likelihood and impact scores are judgements, but they should be consistent judgements. That requires defined scales — what a "major" impact means in money, customers, regulatory standing and time — applied the same way across the organisation. Without them, two teams can rate identical risks differently, and the register ranks the confidence of the people filling it in rather than the risks themselves.
Record both the inherent rating, before controls, and the residual rating, after them. The gap between the two is a statement about how much the controls are doing, and it is the part of the register that most needs to be evidenced.
Test the controls
A control listed on a register is a claim. For the risks that matter most, the claim should be tested: is the control actually operating, as designed, by the person named? The test need not be elaborate — a sample of transactions, a walkthrough, a review of the evidence the control produces — but without it the residual rating is an assumption.
Watch the indicators, not just the ratings
Ratings change slowly because they are reviewed slowly. Key risk indicators change as the underlying conditions do. For each significant risk, choose one or two measures that would move before the risk crystallised — the backlog of onboarding files awaiting review, the number of unpatched systems, the proportion of spend outside contracts — and set thresholds at which the risk is reviewed and escalated.
Make it part of how decisions are made
The register earns its place when it is used: when a decision paper states which risks the decision affects, when a change in a key risk indicator triggers a discussion rather than waiting for the annual review, and when owners report on their risks as part of normal management. A register that is only ever read in preparation for an audit is a record of what the organisation once thought, not a tool for managing what it faces.
