
Download or copy the risk register template
Copy the table below into Excel, Google Sheets, Word, or your preferred document format, it is a simple risk register for recording risks, scoring them, assigning ownership, tracking treatment actions, and scheduling reviews.
A practical risk register can capture fields such as an ID, description, category, likelihood, impact, rating, planned response, owner, and status, with additional detail added where useful for your organisation’s process (NIST IR 8286 Rev. 1 risk register schema).
| Risk ID | Risk description | Category | Likelihood | Impact / consequence | Risk rating | Existing controls | Treatment action | Risk owner | Due date | Status | Residual risk (optional) | Review date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| R-001 | Open / In progress / Treated / Accepted / Closed | |||||||||||
| R-002 | ||||||||||||
| R-003 |
Use residual risk if you want to record the level of risk remaining after existing controls or planned treatment. Detailed risk records may include likelihood, impact, and exposure after controls, plus ownership and follow-up dates (NIST IR 8286 Rev. 1 risk detail record schema).
What is a risk register template?
A risk register template is a structured document or spreadsheet used to record identified risks, planned responses, owners, status, and follow-up actions. The purpose is to keep risk information in one place—or at least in one agreed place—so it can be assessed, assigned, treated, and reviewed rather than left as a static list (Association for Project Management glossary).
You can use the same basic format for business, project, operational, security, supplier, or compliance risks. The template does not replace a full risk management framework; it gives teams a consistent way to capture and act on risk information.
Risk register fields explained
| Field | What to enter | Example |
|---|---|---|
| Risk ID | A unique reference number so the risk can be tracked and discussed without confusion. | R-001 |
| Risk description | A clear statement of what could happen and why it matters. Write it as a risk, not just a topic. | “Key supplier outage delays customer onboarding.” |
| Category | A grouping that helps filter and report risks. | Supplier, operational, compliance, security, financial, project |
| Likelihood | How probable the risk is before the next review or within the period you are assessing. | 3 — Possible |
| Impact / consequence | How serious the outcome would be if the risk occurred. | 4 — Major |
| Risk rating | A priority score or label based on likelihood and impact. | 12 — High |
| Existing controls | Measures already in place that reduce the likelihood or impact of the risk. | Contract SLA, backup supplier list, monthly service review |
| Treatment action | What will be done next: reduce, accept, transfer, or avoid the risk. Make the action specific. | “Complete supplier contingency plan and test alternate ordering process.” |
| Risk owner | The named person accountable for monitoring the risk and following up actions. | Operations Manager |
| Due date | Target date for the treatment action, decision, or review. | 2026-04-30 |
| Status | Current state of the risk or action. | Open, in progress, treated, accepted, closed |
| Residual risk | Optional field for the remaining risk after controls or treatment. | 6 — Medium |
| Review date | The date the risk should be reassessed. | 2026-06-30 |
Keep each entry concise. If the risk needs detailed analysis, supporting evidence, or a full treatment plan, link to that material rather than putting all of it in the register.
How to score likelihood, impact, and risk rating
Use defined likelihood and consequence criteria so different teams interpret scores consistently and can prioritise risks in a comparable way. Those criteria should be reviewed as circumstances change (The Orange Book: Management of Risk).
One simple approach is to score likelihood from 1 to 5 and score impact from 1 to 5.
Likelihood scale
| Score | Label | Plain-language meaning |
|---|---|---|
| 1 | Rare | Unlikely to happen |
| 2 | Unlikely | Could happen, but not expected |
| 3 | Possible | Might happen under normal conditions |
| 4 | Likely | Expected to happen in some cases |
| 5 | Almost certain | Expected to happen frequently or soon |
Impact scale
| Score | Label | Plain-language meaning |
|---|---|---|
| 1 | Insignificant | Minimal disruption or loss |
| 2 | Minor | Limited impact, manageable locally |
| 3 | Moderate | Noticeable business, compliance, or operational impact |
| 4 | Major | Serious disruption, financial, customer, regulatory, or security impact |
| 5 | Severe | Critical business, safety, regulatory, financial, or reputational impact |
Risk rating calculation
A simple scoring method is:
Risk rating = likelihood × impact
You can then classify the result using rating bands agreed by your organisation. For example:
| Score | Rating |
|---|---|
| 1–4 | Low |
| 5–9 | Medium |
| 10–16 | High |
| 17–25 | Critical |
These bands are a practical starting point, not a universal requirement. Adjust them if your organisation uses different thresholds, risk appetite, or governance rules.
Completed risk register example
The examples below show how the fields work together. They’re kept fairly general so you can adapt them to your business context.
| Risk ID | Risk description | Category | Likelihood | Impact | Risk rating | Existing controls | Treatment action | Risk owner | Due date | Status | Residual risk | Review date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| R-001 | Key supplier outage delays customer onboarding and creates service backlog. | Supplier | 3 | 4 | 12 — High | Supplier SLA; monthly service review; backup supplier identified | Confirm backup supplier process and run a tabletop test. | Operations Manager | 2026-04-30 | In progress | 6 — Medium | 2026-06-30 |
| R-002 | Former staff retain access to shared business applications after leaving the company. | Security | 3 | 5 | 15 — High | HR offboarding checklist; quarterly user access review | Add access removal confirmation to offboarding sign-off. | IT Manager | 2026-03-31 | Open | 8 — Medium | 2026-05-15 |
| R-003 | Compliance reporting deadline is missed because source data is not ready in time. | Compliance | 2 | 4 | 8 — Medium | Compliance calendar; named report preparer | Add interim data cut-off date and reviewer checkpoint. | Compliance Lead | 2026-04-15 | In progress | 4 — Low | 2026-05-01 |
| R-004 | Manual invoice approval process leads to duplicate payment or delayed correction. | Operational | 3 | 3 | 9 — Medium | Finance approval policy; monthly reconciliation | Introduce duplicate invoice check before payment approval. | Finance Manager | 2026-05-10 | Open | 6 — Medium | 2026-07-01 |
Here’s the difference between the fields:
- Risk description explains what could go wrong.
- Existing controls show what is already reducing the risk.
- Treatment action states what will be done next.
- Risk owner names who is accountable for follow-up.
- Residual risk shows the expected remaining exposure after controls or treatment.
How to use and maintain the risk register
Use the register as a working control document. Not a one-off spreadsheet.
- Identify and describe the risk. Write a clear risk statement that explains the event and consequence.
- Categorise it. Use categories that help your team filter, report, and assign risks.
- Score likelihood and impact. Apply the same scoring criteria across the register.
- Record existing controls. Capture what is already in place before adding new actions.
- Decide the treatment action. Make actions specific and verifiable.
- Assign an owner and due date. Assign a named owner to risks requiring active management.
- Track status. Update whether the action is open, in progress, treated, accepted, or closed.
- Reassess residual risk. If you use this field, update it after controls or treatment actions change the exposure.
- Set the next review date. Match the review timing to the severity and context of the risk.
Risk management actions should have assigned responsibility, and review frequency should reflect the nature of the risk rather than a fixed universal cadence (The Orange Book: Management of Risk).
Escalate risks that exceed your organisation’s agreed thresholds or the owner’s authority. For example, a high supplier risk may need senior operational review, while an accepted low risk may only need periodic monitoring.
Update the register when conditions change. Examples include a control failure, incident, audit finding, supplier change, process change, new system, or new business activity.
Risk register template FAQs
Can I use this risk register template in Excel or Google Sheets?
Yes. Copy the table into Excel or Google Sheets and use filters for category, owner, status, rating, and review date. Spreadsheet formulas can calculate the rating if likelihood and impact are entered as numbers.
Can I use a Word or PDF version?
Yes, if you only need a simple document for discussion or reporting. A spreadsheet is usually easier to sort, filter, update, and maintain over time.
What is the difference between a risk register and a risk assessment?
A risk assessment estimates likelihood and impact. A risk register records the identified risks, responses, owners, status, and follow-up actions so they can be tracked over time (Association for Project Management glossary).
What is the difference between a risk register and a risk treatment plan?
A risk register summarises the risk and the agreed response. A risk treatment plan usually provides more implementation detail, such as tasks, evidence, dependencies, budget, and milestones for reducing or managing a specific risk.
How often should a risk register be reviewed?
Set review dates according to the nature and severity of the risk. High-priority risks may need more frequent review than stable, low-priority risks, but the cadence should match your organisation’s governance process.
Who should own the risk register?
One person or function should maintain the register’s structure and review process, but individual risks should have named owners who are accountable for follow-up. In smaller organisations, this may be an operations, compliance, finance, project, or security lead.
A template is only handy if it stays current. Start with the copyable table, agree your scoring criteria, assign owners, and review the register whenever the risk picture changes.
