Risk Register: A Step-by-Step Guide

This article discusses developing and populating a risk register, shedding light on its significance and providing practical guidance for its creation and maintenance.

Contents

Download Our Guide to Risk Management

Learn about risk management with this risk management guide. Covering the full cycle of risk management from identifying risks to closing them, and risk registers too, you can get this free guide here:

Name(Required)
We will send the risk management guide by email, so please ensure you put the correct email in the field below. We may also send you follow up emails to showcase some of our products and services, but you can unsubscribe from these at any time.
Would you like to sign up to our newsletter?
Get articles like this, the latest news and exclusive offers direct to your inbox with our regular newsletter. This is separate from our other emails and we won't use your data for anything else. You can unsubscribe at any time

What is a Risk Register?

A risk register is a structured document or tool used in risk management to systematically identify, assess, and track risks within an organisation or a project. It serves as a central repository for information about potential risks, helping organisations or project teams understand and manage uncertainty effectively.

The primary components of a risk register typically include:

Risk Background

  • ID: A unique identifier for each risk, often a numerical or alphanumerical code.

  • Description: A clear and concise explanation of the risk, detailing its nature, potential consequences, and any relevant context.

  • Category: The categorisation of risks based on their nature, such as financial, operational, or reputational.

  • Owner: The individual or team responsible for managing and mitigating the risk. This person or group is held accountable for risk-related actions.

Risk Management

  • Impact: An assessment of the potential magnitude of the consequences if the risk were to materialise.

  • Likelihood: An evaluation of the probability or frequency with which the risk event might occur within a specified timeframe.

  • Risk Score: A combined measure of impact and likelihood that helps in prioritising risks. It often uses a scoring system or matrix.

  • Mitigation: Strategies and actions to reduce the risk’s impact or likelihood. This may include preventive measures or contingency plans.

  • Assurance: The evidence that your approach to risk mitigation is working.

  • Date Updated: The data on which the last update to the risk on the risk register was made.

In addition to these basic components, organisations may include custom fields in their risk registers to capture industry-specific metrics, compliance requirements, or any other information relevant to their specific context.

The process of developing and populating a risk register involves identifying potential risks, categorising them, assigning risk owners, collecting relevant data, conducting risk assessments, prioritising risks, and regularly updating and reviewing the register to reflect changes in the risk landscape.

The Anatomy of a Risk Register

Let’s explore the elements of a risk register as set out above.

Risk ID

Each risk needs a unique identifier. This risk identification helps prevent confusion between different risks and ensures updates can be applied to the right risk at the right time. It doesn’t really matter what system you use, so long as it is consistent.

Risk Description

The risk description sets out the the risk in terms of

  • cause

  • event

  • effect

For example “if we do not provide adequate health and safety training to employees, there is a greater change of a workplace accident. This could result in harm to employees, disruption to operations, and legal action.”

Note that this risk is written in uncertain terms. This is because a risk is something that could happen, not something that has happened. Something that has happened is known as an issue.

  • read more about the difference between risks and issues here.

Risk Category

Categorisation helps in organising risks, with common categories including financial, operational, and reputational.

A risk can under two, or even all three of these categories. The key to deciding which categories a risk falls under it to understanding the consequences of that risk. For example, we can see from the risk above that the consequences are set out in operational and financial terms.

Note: legal action is not usually a risk category in its own right, because legal action can lead to financial, operational, and reputational outcomes.

Risk Owner

The risk owner is the person responsible for the day to day management of the risk. A risk owner can own more than one risk. However, the risk owner must be able to provide active management of their risks so should be a subject matter expert in the area to which the risk applies.

Risk Impact

Risk impact describes the magnitude of the consequences should the risk materialise. This is usually described in terms of a number on a scale. We usually use a ranking system from one to five, with five being the highest consequence (see risk score, below). Very roughly this looks like:

Financial Operational Reputational
1 No significant costs No significant disruption No real reputational effect
2 Some costs that may impact part of the business Some parts of the business may be disrupted An increase in complaints received from customers
3 High costs felt across the business: savings needed The business could experience minor disruption Local media interest in the business
4 Very high costs that may require restructuring Significant disruption should be expected business-wide National media interest in the business
5 Costs could bankrupt the business The business may not be able to continue Brand damage could be fatal to the business

Risk Likelihood

This describes the probability of the risk occurring within a specified timeframe. Again this is set out on a scale of one to five, with one being very unlikely and five being highly likely. Remember, because risks are uncertain events that could happen they can never be certainties. The scale might look something like this:

1 1 to 19% chance: highly unlikely to occur
2 20 to 39% chance: there is a low but moderate chance the risk will occur
3 40 to 59% chance: broadly equally likely and unlikely to occur
4 60 to 79% chance: quite likely to occur
5 80 to 99% chance: highly likely to occur

Risk Score

This is the combined measure of impact and likelihood. By multiplying the two scores you end up with a score from 1 (1×1) to 25 (5×5). This ranks your scores from lowest to highest helping to prioritise risks.

To help prioritise risks you may want to breakdown your scores into bands of red, amber and green. You can then map your risks on a grid, like this:

risk scoring matrix

Risk Mitigation

Mitigation is the strategies and actions proposed and implemented to reduce the risk’s impact or likelihood. The overall approach should result in a risk score post mitigation that is one you are comfortable with. The aim should not be to eliminate all possible risks. That is not achievable, and all organisations should actively seek to take risks from time to time.

What approach you take depends on your prioritisation of a particular risks. Low rated risks may not need any action. The highest rated risk may need significant resources thrown at them.

Each risk needs a risk response plan or risk management plan. It does not need to be very detailed, at least not in the risk register, where a summary will do.

If we consider the health and safety risk set out above then the mitigation strategy could be: “a minimum of 95% of all staff will complete mandated health and safety training annually. Senior managers and other specialists will have job-specific training annually.”

  • read more about approaches to risk mitigation strategies here.

Risk Assurance

Risk assurance is how you can check if your risk mitigation strategies are working. Each risk on your risk register should have evidence against the risk assurance section that demonstrates that your approach to managing that risk is effective. For example, using our health and safety risk, we could get assurance from:

  • confirmation a training provider has been appointed;

  • evidence that the required proportion of staff have completed their training;

  • assurance that the number of health and safety incidents remains low and stable, or is declining.

Date Updated

The date the risk on the risk register was last updated. This helps ensure risks are being kept live, and are being reviewed in good time.

________________________________________________________________________________________________

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won’t use your data for anything else.

Sign Up Here:

 

________________________________________________________________________________________________

Developing a Risk Register

The first thing to do when populating your risk register is to think about the risks you need to include. How do you go about risk identification?

Identifying Risks

You can identify your risks in many ways. Risks can be internal (coming from within the organisation) and external (coming from outside the organisation).

  • you can explore how to identify internal risks using a SWOT analysis here.

  • to identify external risks you can use a PESTLE analysis. Learn more here.

To populate the risk register, data must be collected from various sources. The reliability and relevance of this data are critical for accurate risk assessments.

Data can be sourced from historical records, subject matter experts, industry reports, and even feedback from project or operational teams. It’s imperative that data used to identify risks is reliable, up-to-date, and reflective of the current business or project environment.

Brainstorming

You could identify risks by gathering a diverse group of stakeholders to brainstorm potential risks based on their knowledge and experience. This will involve looking forward to identify potential threats and consider their likelihood and consequence.

Historical Data Analysis

Another approach is to examine past projects or business operations to identify recurring risks and issues. If the same thing has gone wrong on different projects in the past, it may be there are real risks to similar projects in the future.

Describing, Categorising and Scoring Risks

Once identified, risks should be described, scored and categorised based on their nature and potential impact. Remember risks are uncertain events and should be described in terms of cause, event and effect.

Whatever scoring system you use you should be consistent so your risks cane be scored by severity and prioritised according.

The effects of the risk will help you decide what categories the risk falls under.

Assigning Risk Owners

Each risk in the register should have a designated owner. Giving ownership of risks to people ensures accountability and defines who is responsible for monitoring, mitigating, and reporting on the risk. This step requires a clear delineation of roles and responsibilities.

Prioritising Risks

Risk prioritisation is a critical step that helps in focusing resources on the most significant risks. It’s often done by exploring an organisation’s appetite for and tolerance for risk in different areas.

Risk appetite it the willingness of an organisation to take risks, while risk tolerance is the maximum risk it is willing to allow. Risk appetite and tolerance may vary by risk category. For example, again using our health and safety risk, a company may be willing to take a financial risk by paying more for training than it needs to, because this is more tolerable than the operational risk of inadequate training.

  • gain a deeper understanding of risk appetite and tolerance with this guide.

Generally you will want to prioritise your highest rated or highest scoring risks first.

Mitigation Strategies and Risk Assurance

Based on your understanding of the:

  • risk;

  • the risk score;

  • categories of risk; and

  • your risk appetite and tolerance;

you can identify your approach to the risk and what evidence will provide assurance that your approach is working. The risk owner will have a key role in developing and implementing mitigation strategies. More senior management will help define what assurance is needed.

Updating and Maintaining the Risk Register

Like risk management generally a risk register is not a static document; it requires regular updates and maintenance. This involves:

Regular Reviews

Frequent reviews and updates to reflect changes in the risk landscape, the status of risk responses, and new risks that emerge.

Change Management

A systematic approach to managing changes in the risk register, ensuring that all updates are well-documented and communicated.

Communication and Reporting

The risk register aids in stakeholder engagement and reporting by providing a structured overview of risks and their management status.

Challenges in Developing and Populating a Risk Register

Despite its importance, developing and populating a risk register comes with challenges, including:

Data Quality and Accuracy

Ensuring the data used in risk assessments is accurate and of high quality is a constant challenge. There’s also a risk of data overload, where organisations capture excessive information that hinders effective risk assessment.

User Adoption

Getting all stakeholders to consistently use and update the risk register can be a challenge, especially in larger organisations. However risk management becomes difficult if the risks become stale or it is not uniformly adopted across the organisation. You may have local risk registers like a project risk register, but these should all follow a consistent template and scoring scheme.

Regular Updates and Reviews

Frequent updates and reviews are essential to ensure the risk register remains aligned with the current risk landscape. It is not helpful, for example, to identify immediate financial risks and then not review them for six months. A failure to review risks at the right time would severely undermine risk assurance.

Integration with Decision-Making

You should ensure that the risk register is actively used to inform decision-making, strategy development, and resource allocation. Too often risk management sits separately to the decision making and management processes of organisations.

________________________________________________________________________________________________

Learn About Risk Management

Gain the practical skills you need to identify and manage risk with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

 

Five star training testimonial

________________________________________________________________________________________________

Conclusion: Summary of the Importance of a Risk Register

In the realm of risk management, the development and population of a risk register are not merely administrative tasks; they are the cornerstone of an organisation’s ability to anticipate, manage, and mitigate risks effectively. A well-structured and regularly updated risk register is a valuable tool that supports strategic decision-making, enhances accountability, and ultimately contributes to an organisation’s resilience in the face of an ever-evolving risk landscape.