By Robert Sturgeon · Founder and Lead Consultant · 6-minute read · Published 13 August 2026

Most risk registers fail for one of two reasons: they're never built properly in the first place, or they're built once, filed away, and never looked at again. Neither helps you. Done well, a risk register is one of the simplest tools a growing business has for staying ahead of problems instead of reacting to them after the fact.

Here's a practical way to build one that people will actually use.

Start with the risks that matter, not every risk imaginable

It's tempting to list everything that could conceivably go wrong. Resist it. A register with 200 entries gets ignored. For many growing businesses, a focused register of roughly 20 to 30 material risks is more useful than an exhaustive list of every conceivable concern. Focus on what could meaningfully disrupt revenue, operations, compliance or reputation — the risks that would actually change how someone runs the business if they went wrong.

The minimum fields your register should contain

Beyond the risk description itself, a register that's actually useful in a management meeting needs a handful of specific fields:

  • Cause and consequence — what triggers the risk, and what happens if it materialises
  • Likelihood and impact — rated consistently across the register
  • Inherent risk versus residual risk — the exposure before controls, and what's left after them
  • Key controls and their effectiveness — what's actually mitigating this today
  • Owner — one accountable person, not a team or department
  • Agreed actions, action owners and due dates — what's being done, by whom, and by when
  • Early-warning indicators, where relevant — a metric that signals the risk is increasing before it materialises

You don't need every field to be complex. A short, consistent structure beats a detailed one nobody keeps updated.

A simple example

Risk Owner Likelihood Impact Key controls Further action Due date
Customer data breach CTO Medium High Access controls; monitoring Complete access review 30 Sept

Rate each risk on likelihood and impact

For each risk, ask two questions. How likely is this to happen? And if it does, how bad would it be? A simple high, medium or low scale on both is enough to get started for most businesses. As the register matures, distinguishing inherent exposure (before controls) from residual exposure (after controls) gives experienced risk owners a clearer picture of whether existing controls are actually doing enough.

Give every risk an owner

A risk with no owner doesn't get managed, it gets forgotten. Each entry needs one person accountable for watching it and acting if it starts to move in the wrong direction. This is often the single biggest gap in registers we see: risks were identified correctly, but nobody was ever clearly responsible for them.

Review it on a schedule, not when something goes wrong

A register that's only updated after an incident isn't managing risk, it's documenting failure after the fact. Set a cadence — quarterly works for most growing businesses — and treat it like any other recurring business review. Risks change as the business grows, and the register should change with it.

Keep it proportional to your size

This is the part people get wrong most often. A 40-person business doesn't need the same risk framework as a listed multinational, and forcing one onto the other creates a document nobody has time to maintain. The right register is the one that's actually kept up to date, not the most sophisticated one on paper.

If your current risk register is too long, out of date, unclear on ownership or disconnected from management decisions, we can help you rebuild it into a practical management tool.