What Is a Risk Register?

Also called: Risk log

Related problems: The board wants a clear view of our top technology risks; Known risks keep getting raised and then forgotten; Auditors ask how we track and accept risk; No record of who signed off on exceptions to our security policy

A risk register is a living list of the risks an organization has identified, kept in one place with enough detail to manage them. Each entry typically records what could happen, how likely and how damaging it would be, who owns it, what is being done about it and whether that work is on track. In IT and security, a risk register might hold items such as an unsupported system, a single point of failure in connectivity, a critical vendor without an independent security report or an open audit finding.

At a glance

  • A risk register turns risk assessment results into a tracked list with owners and actions.
  • Each risk usually gets a likelihood and impact rating, combined into an overall score or level.
  • Responses typically fall into four types: reduce, accept, transfer (for example through insurance or contract) or avoid.
  • Accepted risks should be signed off by someone with the authority to accept them.
  • The register is reviewed regularly and updated when systems, vendors or threats change.

What problem it solves

Risks get discovered all the time: in risk assessments, audits, incidents, vendor reviews and everyday operations. Without a register, they live in meeting notes and emails, get raised again months later and are never clearly accepted or fixed. When something goes wrong, nobody can show that the risk was known, who decided what and why.

A risk register gives leadership one view of what could hurt the business, makes ownership explicit and creates a record of decisions. That record matters to boards, auditors, cyber insurers and, for public companies, to the people preparing disclosures about how cyber risk is managed under the SEC cybersecurity disclosure rules.

How it works

Identify. Risks come from assessments, audits, vendor reviews, incident lessons, staff reports and planning for new projects. Each is written as a clear statement: cause, event and consequence.

Rate. Score likelihood and impact on a simple scale, often 1 to 5, and combine them into a rating such as low, medium, high or critical. Some registers rate both inherent risk and residual risk after existing controls.

Assign. Give each risk an owner who has the authority and budget to act, not just the person who found it.

Respond. Choose a treatment: reduce the risk with controls, transfer it through cyber insurance or contract terms, avoid it by changing plans, or accept it with documented sign-off. Record actions and due dates.

Monitor and report. Review the register on a schedule, update ratings when things change, close risks that are resolved and escalate the top risks to leadership or the board. Many organizations run the register inside a governance, risk and compliance (GRC) platform, and a virtual CISO often maintains it for companies without a full-time security leader.

When it matters for buyers

  • When the board or investors ask about technology risk. A register is the backbone of that conversation.
  • When choosing or renewing critical providers. Vendor risks found during third-party risk management (TPRM) need an owner and a decision.
  • When an audit or assessment produces findings. The register tracks them to closure.
  • When deciding between investing in a control and buying insurance. The ratings help compare options.

Our governance, risk and compliance overview covers GRC platforms and advisory services that help build and run a risk register.

Questions to ask vendors

  • Does your GRC platform support custom rating scales and both inherent and residual risk?
  • Can risks be linked to controls, vendors, assets and audit findings?
  • Does it support approval workflows for risk acceptance with expiry dates?
  • What board-level reporting is available out of the box?
  • If you provide a vCISO or advisory service, who maintains the register and how often is it reviewed with us?
  • Can we export the register if we leave the platform?

How it differs from a risk assessment

A risk assessment is an activity: a structured review that identifies and rates risks at a point in time or for a specific scope, such as a new system or a vendor. A risk register is the ongoing record where those results, and risks from many other sources, are kept, assigned and tracked. Assessments feed the register; the register shows what happened to the risks afterwards. An assessment without a register tends to produce a report that sits on a shelf, while a register without fresh assessments goes stale.

Frequently Asked Questions

What should a risk register include?
At minimum, a description of each risk, its likelihood and impact, an overall rating, an owner, the chosen response (reduce, accept, transfer or avoid), planned actions with dates, and current status. Many registers also record existing controls, residual risk after treatment and review dates.
Is a spreadsheet good enough?
For many mid-market companies, yes, at first. A spreadsheet works if someone owns it and reviews it regularly. GRC platforms help when many people contribute, when you need workflows and approvals, or when you want to link risks to controls and audit evidence.
How often should a risk register be reviewed?
Common practice is a regular review, often quarterly for key risks, plus updates whenever something material changes, such as a new system, vendor, incident or regulation. The right cadence depends on how quickly your risks change.
Who owns the risk register?
Usually a risk, security or compliance lead maintains it, but each risk is owned by the business or technology leader who can act on it. Leadership or the board reviews the top risks and approves risk acceptance above agreed limits.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.