In short: A useful risk register records a small number of meaningful risks with clear causes, consequences, owners, ratings and treatment actions, and is reviewed regularly as part of management decisions.
What should a risk register include?
- Risk description (cause, event, consequence)
- Risk owner
- Likelihood and impact ratings
- Existing controls and their effectiveness
- Treatment actions, due dates and residual risk
How do you keep it alive?
Review it in management meetings, link it to objectives and audits, and update ratings when controls or conditions change.
Key takeaways
- Describe risks with cause and consequence.
- Assign real owners.
- Review risks as part of decision-making.
Frequently asked questions
Does ISO 9001 require a risk register?
No, but many organizations use one to manage risks and opportunities.
How many risks should it contain?
Enough to cover significant risks; avoid long lists of trivial items.
What is residual risk?
The risk remaining after controls and treatments.