Learn

What is a risk register?

A risk register is the list of an organization's identified risks with their ratings, owners, treatments, and status. Here is what to include and how to keep it current.

In short

A risk register is a structured list of an organization's identified risks, recording for each one a description, an owner, ratings such as likelihood and impact, the controls that mitigate it, the chosen treatment (mitigate, accept, transfer, or avoid), and its status. It is the working tool of risk management and the basis for risk reporting to leadership.

This page is for you if
  • You are trying to get a straight answer before you sit through a sales call
  • You need language you can take to a CISO, auditor, or procurement

Typical fields

FieldPurpose
Risk descriptionWhat could happen and why
OwnerWho is accountable
Likelihood, impact, velocityHow probable, how severe, and how fast
Inherent and residual ratingBefore and after controls
Linked controls, assets, vendorsWhat mitigates it and what it affects
Treatment and due dateWhat will be done and by when
Status and historyWhere it stands and how it changed

Keeping it alive

Registers decay when they are updated by hand once a quarter. Feeding them from assessment findings, merging duplicates, and recalculating residual risk as controls change keeps them current.

When this becomes a buying decision

If the register is updated for the meeting, it is not a register. The buying test: can findings, exceptions, and scans become owned entries without a workshop?

If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.

Questions

Who maintains the risk register?

Usually the risk or GRC team, with risk owners across the business updating their entries.

How often should a risk register be reviewed?

At least periodically (often quarterly) and whenever significant changes occur.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.