All posts
Continuous Compliance9 min readAug 16, 2026

Risk register template

Ashish / CEO/Co-Founder
Risk register template

Download or copy the risk register template

Copy the table below into Excel, Google Sheets, Word, or your preferred document format, it is a simple risk register for recording risks, scoring them, assigning ownership, tracking treatment actions, and scheduling reviews.

A practical risk register can capture fields such as an ID, description, category, likelihood, impact, rating, planned response, owner, and status, with additional detail added where useful for your organisation’s process (NIST IR 8286 Rev. 1 risk register schema).

Risk IDRisk descriptionCategoryLikelihoodImpact / consequenceRisk ratingExisting controlsTreatment actionRisk ownerDue dateStatusResidual risk (optional)Review date
R-001Open / In progress / Treated / Accepted / Closed
R-002
R-003

Use residual risk if you want to record the level of risk remaining after existing controls or planned treatment. Detailed risk records may include likelihood, impact, and exposure after controls, plus ownership and follow-up dates (NIST IR 8286 Rev. 1 risk detail record schema).

What is a risk register template?

A risk register template is a structured document or spreadsheet used to record identified risks, planned responses, owners, status, and follow-up actions. The purpose is to keep risk information in one place—or at least in one agreed place—so it can be assessed, assigned, treated, and reviewed rather than left as a static list (Association for Project Management glossary).

You can use the same basic format for business, project, operational, security, supplier, or compliance risks. The template does not replace a full risk management framework; it gives teams a consistent way to capture and act on risk information.

Risk register fields explained

FieldWhat to enterExample
Risk IDA unique reference number so the risk can be tracked and discussed without confusion.R-001
Risk descriptionA clear statement of what could happen and why it matters. Write it as a risk, not just a topic.“Key supplier outage delays customer onboarding.”
CategoryA grouping that helps filter and report risks.Supplier, operational, compliance, security, financial, project
LikelihoodHow probable the risk is before the next review or within the period you are assessing.3 — Possible
Impact / consequenceHow serious the outcome would be if the risk occurred.4 — Major
Risk ratingA priority score or label based on likelihood and impact.12 — High
Existing controlsMeasures already in place that reduce the likelihood or impact of the risk.Contract SLA, backup supplier list, monthly service review
Treatment actionWhat will be done next: reduce, accept, transfer, or avoid the risk. Make the action specific.“Complete supplier contingency plan and test alternate ordering process.”
Risk ownerThe named person accountable for monitoring the risk and following up actions.Operations Manager
Due dateTarget date for the treatment action, decision, or review.2026-04-30
StatusCurrent state of the risk or action.Open, in progress, treated, accepted, closed
Residual riskOptional field for the remaining risk after controls or treatment.6 — Medium
Review dateThe date the risk should be reassessed.2026-06-30

Keep each entry concise. If the risk needs detailed analysis, supporting evidence, or a full treatment plan, link to that material rather than putting all of it in the register.

How to score likelihood, impact, and risk rating

Use defined likelihood and consequence criteria so different teams interpret scores consistently and can prioritise risks in a comparable way. Those criteria should be reviewed as circumstances change (The Orange Book: Management of Risk).

One simple approach is to score likelihood from 1 to 5 and score impact from 1 to 5.

Likelihood scale

ScoreLabelPlain-language meaning
1RareUnlikely to happen
2UnlikelyCould happen, but not expected
3PossibleMight happen under normal conditions
4LikelyExpected to happen in some cases
5Almost certainExpected to happen frequently or soon

Impact scale

ScoreLabelPlain-language meaning
1InsignificantMinimal disruption or loss
2MinorLimited impact, manageable locally
3ModerateNoticeable business, compliance, or operational impact
4MajorSerious disruption, financial, customer, regulatory, or security impact
5SevereCritical business, safety, regulatory, financial, or reputational impact

Risk rating calculation

A simple scoring method is:

Risk rating = likelihood × impact

You can then classify the result using rating bands agreed by your organisation. For example:

ScoreRating
1–4Low
5–9Medium
10–16High
17–25Critical

These bands are a practical starting point, not a universal requirement. Adjust them if your organisation uses different thresholds, risk appetite, or governance rules.

Completed risk register example

The examples below show how the fields work together. They’re kept fairly general so you can adapt them to your business context.

Risk IDRisk descriptionCategoryLikelihoodImpactRisk ratingExisting controlsTreatment actionRisk ownerDue dateStatusResidual riskReview date
R-001Key supplier outage delays customer onboarding and creates service backlog.Supplier3412 — HighSupplier SLA; monthly service review; backup supplier identifiedConfirm backup supplier process and run a tabletop test.Operations Manager2026-04-30In progress6 — Medium2026-06-30
R-002Former staff retain access to shared business applications after leaving the company.Security3515 — HighHR offboarding checklist; quarterly user access reviewAdd access removal confirmation to offboarding sign-off.IT Manager2026-03-31Open8 — Medium2026-05-15
R-003Compliance reporting deadline is missed because source data is not ready in time.Compliance248 — MediumCompliance calendar; named report preparerAdd interim data cut-off date and reviewer checkpoint.Compliance Lead2026-04-15In progress4 — Low2026-05-01
R-004Manual invoice approval process leads to duplicate payment or delayed correction.Operational339 — MediumFinance approval policy; monthly reconciliationIntroduce duplicate invoice check before payment approval.Finance Manager2026-05-10Open6 — Medium2026-07-01

Here’s the difference between the fields:

  • Risk description explains what could go wrong.
  • Existing controls show what is already reducing the risk.
  • Treatment action states what will be done next.
  • Risk owner names who is accountable for follow-up.
  • Residual risk shows the expected remaining exposure after controls or treatment.

How to use and maintain the risk register

Use the register as a working control document. Not a one-off spreadsheet.

  1. Identify and describe the risk. Write a clear risk statement that explains the event and consequence.
  2. Categorise it. Use categories that help your team filter, report, and assign risks.
  3. Score likelihood and impact. Apply the same scoring criteria across the register.
  4. Record existing controls. Capture what is already in place before adding new actions.
  5. Decide the treatment action. Make actions specific and verifiable.
  6. Assign an owner and due date. Assign a named owner to risks requiring active management.
  7. Track status. Update whether the action is open, in progress, treated, accepted, or closed.
  8. Reassess residual risk. If you use this field, update it after controls or treatment actions change the exposure.
  9. Set the next review date. Match the review timing to the severity and context of the risk.

Risk management actions should have assigned responsibility, and review frequency should reflect the nature of the risk rather than a fixed universal cadence (The Orange Book: Management of Risk).

Escalate risks that exceed your organisation’s agreed thresholds or the owner’s authority. For example, a high supplier risk may need senior operational review, while an accepted low risk may only need periodic monitoring.

Update the register when conditions change. Examples include a control failure, incident, audit finding, supplier change, process change, new system, or new business activity.

Risk register template FAQs

Can I use this risk register template in Excel or Google Sheets?

Yes. Copy the table into Excel or Google Sheets and use filters for category, owner, status, rating, and review date. Spreadsheet formulas can calculate the rating if likelihood and impact are entered as numbers.

Can I use a Word or PDF version?

Yes, if you only need a simple document for discussion or reporting. A spreadsheet is usually easier to sort, filter, update, and maintain over time.

What is the difference between a risk register and a risk assessment?

A risk assessment estimates likelihood and impact. A risk register records the identified risks, responses, owners, status, and follow-up actions so they can be tracked over time (Association for Project Management glossary).

What is the difference between a risk register and a risk treatment plan?

A risk register summarises the risk and the agreed response. A risk treatment plan usually provides more implementation detail, such as tasks, evidence, dependencies, budget, and milestones for reducing or managing a specific risk.

How often should a risk register be reviewed?

Set review dates according to the nature and severity of the risk. High-priority risks may need more frequent review than stable, low-priority risks, but the cadence should match your organisation’s governance process.

Who should own the risk register?

One person or function should maintain the register’s structure and review process, but individual risks should have named owners who are accountable for follow-up. In smaller organisations, this may be an operations, compliance, finance, project, or security lead.

A template is only handy if it stays current. Start with the copyable table, agree your scoring criteria, assign owners, and review the register whenever the risk picture changes.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents