The Risk Register

Learn

Plain-English explainers on the concepts behind the product.

What is a risk register?

A structured, living list of the risks an organisation faces, each with an owner, a description of existing controls, a likelihood and impact score, and the actions being taken to reduce it. The point of a register is that it stays current: a risk you identified last year should reflect what you know now, not what you knew then.

Likelihood and impact scoring

Most risk scoring works on two axes: how likely a risk is to occur, and how severe the consequences would be if it did. Multiplying the two gives a rough risk score, which is what a heat map plots. Scoring both the inherent risk (before controls) and the residual risk (after controls) shows whether your mitigation is actually working.

Business impact analysis (BIA)

A BIA maps what happens if a business function stops working: which systems, suppliers and sites it depends on, which roles are critical to keep it running, how long you could operate without it (your Recovery Time Objective), and how much data loss is acceptable (your Recovery Point Objective). It's the foundation of business continuity planning, because you can't plan recovery priorities without knowing what actually matters most.

Incident management

An incident is a risk that has materialised. Logging it, with a severity, a timeline, and the actions taken, and linking it back to the risk record it relates to, closes the loop: your risk register stops being a forward-looking guess and starts reflecting what's actually happened.

Key risk indicators (KRIs)

A KRI is a measurable signal that gives early warning a risk is materialising, before it becomes an incident. Unlike a risk score, which is a judgement, a KRI is a number you track over time against a target: days of cash runway, percentage of overdue patches, staff turnover in a critical role. The value of a KRI is in watching the trend, not a single reading.

Risk treatment strategies

Once a risk is identified, there are four broad ways to treat it: accept it (the cost of mitigation exceeds the exposure), avoid it (stop the activity that creates it), transfer it (insurance, contracts), or reduce it (controls that lower likelihood or impact). Recording which strategy applies, and why, is what turns a risk register from a list into a decision record.