A risk register is a living list of the risks an organization has identified, kept in one place with enough detail to manage them. Each entry typically records what could happen, how likely and how damaging it would be, who owns it, what is being done about it and whether that work is on track. In IT and security, a risk register might hold items such as an unsupported system, a single point of failure in connectivity, a critical vendor without an independent security report or an open audit finding.
At a glance
- A risk register turns risk assessment results into a tracked list with owners and actions.
- Each risk usually gets a likelihood and impact rating, combined into an overall score or level.
- Responses typically fall into four types: reduce, accept, transfer (for example through insurance or contract) or avoid.
- Accepted risks should be signed off by someone with the authority to accept them.
- The register is reviewed regularly and updated when systems, vendors or threats change.
What problem it solves
Risks get discovered all the time: in risk assessments, audits, incidents, vendor reviews and everyday operations. Without a register, they live in meeting notes and emails, get raised again months later and are never clearly accepted or fixed. When something goes wrong, nobody can show that the risk was known, who decided what and why.
A risk register gives leadership one view of what could hurt the business, makes ownership explicit and creates a record of decisions. That record matters to boards, auditors, cyber insurers and, for public companies, to the people preparing disclosures about how cyber risk is managed under the SEC cybersecurity disclosure rules.
How it works
Identify. Risks come from assessments, audits, vendor reviews, incident lessons, staff reports and planning for new projects. Each is written as a clear statement: cause, event and consequence.
Rate. Score likelihood and impact on a simple scale, often 1 to 5, and combine them into a rating such as low, medium, high or critical. Some registers rate both inherent risk and residual risk after existing controls.
Assign. Give each risk an owner who has the authority and budget to act, not just the person who found it.
Respond. Choose a treatment: reduce the risk with controls, transfer it through cyber insurance or contract terms, avoid it by changing plans, or accept it with documented sign-off. Record actions and due dates.
Monitor and report. Review the register on a schedule, update ratings when things change, close risks that are resolved and escalate the top risks to leadership or the board. Many organizations run the register inside a governance, risk and compliance (GRC) platform, and a virtual CISO often maintains it for companies without a full-time security leader.
When it matters for buyers
- When the board or investors ask about technology risk. A register is the backbone of that conversation.
- When choosing or renewing critical providers. Vendor risks found during third-party risk management (TPRM) need an owner and a decision.
- When an audit or assessment produces findings. The register tracks them to closure.
- When deciding between investing in a control and buying insurance. The ratings help compare options.
Our governance, risk and compliance overview covers GRC platforms and advisory services that help build and run a risk register.
Questions to ask vendors
- Does your GRC platform support custom rating scales and both inherent and residual risk?
- Can risks be linked to controls, vendors, assets and audit findings?
- Does it support approval workflows for risk acceptance with expiry dates?
- What board-level reporting is available out of the box?
- If you provide a vCISO or advisory service, who maintains the register and how often is it reviewed with us?
- Can we export the register if we leave the platform?
How it differs from a risk assessment
A risk assessment is an activity: a structured review that identifies and rates risks at a point in time or for a specific scope, such as a new system or a vendor. A risk register is the ongoing record where those results, and risks from many other sources, are kept, assigned and tracked. Assessments feed the register; the register shows what happened to the risks afterwards. An assessment without a register tends to produce a report that sits on a shelf, while a register without fresh assessments goes stale.
