What is a risk register?
A risk register is the list of an organization's identified risks with their ratings, owners, treatments, and status. Here is what to include and how to keep it current.
A risk register is a structured list of an organization's identified risks, recording for each one a description, an owner, ratings such as likelihood and impact, the controls that mitigate it, the chosen treatment (mitigate, accept, transfer, or avoid), and its status. It is the working tool of risk management and the basis for risk reporting to leadership.
- You are trying to get a straight answer before you sit through a sales call
- You need language you can take to a CISO, auditor, or procurement
Typical fields
| Field | Purpose |
|---|---|
| Risk description | What could happen and why |
| Owner | Who is accountable |
| Likelihood, impact, velocity | How probable, how severe, and how fast |
| Inherent and residual rating | Before and after controls |
| Linked controls, assets, vendors | What mitigates it and what it affects |
| Treatment and due date | What will be done and by when |
| Status and history | Where it stands and how it changed |
Keeping it alive
Registers decay when they are updated by hand once a quarter. Feeding them from assessment findings, merging duplicates, and recalculating residual risk as controls change keeps them current.
When this becomes a buying decision
If the register is updated for the meeting, it is not a register. The buying test: can findings, exceptions, and scans become owned entries without a workshop?
If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.
Questions
Who maintains the risk register?
Usually the risk or GRC team, with risk owners across the business updating their entries.
How often should a risk register be reviewed?
At least periodically (often quarterly) and whenever significant changes occur.
Related
A live register rated on likelihood, impact, velocity, and dollars.
→Use casesRisk registerA live, explained register built from what you already know.
→LearnInherent vs. residual riskRisk before controls, and risk after them.
→LearnRisk quantificationExpressing risk in dollars, not colors.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.