Framework library · Risk management and assessment
Risk register
A risk register records each risk as a cause and an effect, scores it for likelihood and impact, and names the response and the owner. It is a management tool rather than a compliance one: its value is in the review, when the scores move and the actions are checked.
Use it when
- A project, programme or business area needs a single place where its risks, responses and owners are recorded.
- You need to show a board or lender that risks are known and being managed.
- Several teams are working on one outcome and need a shared view of what could stop it.
Avoid it when
- The real question is uncertainty in a number, such as cost or schedule. Use a Monte Carlo simulation alongside the register.
- Nobody will review it. An unreviewed register gives false comfort. Agree the review rhythm before you start.
- You are recording things that have already happened. Those are issues, and belong in an issue log with actions and dates.
How to run it
Write each risk as cause and effect
"Because the wholesale contract ends in March, we may lose access to the network and stop serving 40,000 customers." A risk with no cause cannot be managed.
Agree the scales before scoring
Define what 1 to 5 means for likelihood (a chance over the period) and impact (money, customers, safety, reputation). Write the definitions down and keep them with the register.
Score as things stand today
Likelihood times impact gives a score from 1 to 25. Score the risk with the controls that exist now, not the ones planned.
Choose a response
Avoid, reduce, transfer or accept. Every response except accept needs an action, an owner and a date.
Name one owner per risk
One person who will notice if it moves and has the authority to act.
Review on a rhythm
Re-score, close what has passed, add what is new. The heat map of scores shows whether the portfolio is moving.
Work through it
Answer the questions below, or load the worked example to see a finished one. The drawing updates as you type. Export the result as a PowerPoint deck, a Word document, an Excel workbook, a PDF or plain text.
What you type stays in this browser, so you can close the page and come back to it. It is not sent to Blue Prysm or anyone else, and the exports are made here, on your device. Privacy policy.
Mistakes to avoid
- Writing vague risks ("cyber", "resourcing") that nobody can act on, so they sit on the register unchanged from one review to the next.
- Scoring everything 3. If the scores do not separate the risks, the scales are not defined well enough.
- Naming a committee as owner. When a group owns a risk, nobody acts on it between meetings.
- Treating the register as the goal. A complete register with no actions under way reduces no risk.
Where it comes from
No single originator. The register is the record kept by the risk management process described in ISO 31000:2018, Risk management: Guidelines, and in COSO's Enterprise Risk Management framework (2017). Source.
Use it with
Further reading
Work through it with us
The frameworks here are free to use as they stand. If you would rather work through the question behind this one with us, these are the ways an engagement starts.