Risk management questions, answered
The questions that come up when a team starts keeping a register, each answered in a paragraph. Where a question deserves more than that, the link leads to the piece that takes it apart.
What is a risk register?
A risk register is the list an organization keeps of what could go wrong, what it would cost, and who is doing something about it. Each entry separates the cause from the consequence, carries a score before and after controls, names one owner, and has a date for its next review. It is the artifact an auditor asks for, and the reason a risk conversation survives the meeting it started in.
How to build one, field by fieldIs this a risk or an issue?
A risk is uncertain and lies ahead; an issue has already happened and is being worked on. If the sentence needs “could”, it belongs in the register; if it needs “has”, it belongs in a task list or an incident record. The distinction is practical rather than academic: a register full of issues cannot be scored, because the likelihood of all of them is 5, and a matrix that cannot sort stops being a tool.
What risk means, and what it does notHow detailed should a single risk be?
Detailed enough that one owner can act on it, broad enough that you are not writing forty variants of the same thing. “Server outage” is too vague to treat; “checkout unavailable because the payment provider has no failover, costing revenue and SLA credits” names a cause, a consequence and a place to intervene. A useful test: if two entries would always be treated by the same measure, they are one entry.
Finding risks without a workshopWhat does ISO 31000 actually require?
ISO 31000:2018 asks for three things: principles that keep the effort proportionate, a framework that says who is responsible and with what resources, and a process — establish the scope and the risk criteria, then identify, analyze, evaluate, treat, monitor, record and report. It prescribes no scale, no matrix size and no tool. The thresholds are yours to write down, and the standard expects you to be able to show that you followed your own.
The full implementation guideWhat is the difference between inherent and residual risk?
Inherent risk is the level before your controls are counted; residual risk is what remains after them. Recording both is what makes treatment visible: the distance between the two scores is the claim your controls make, and a register that carries only one number cannot show whether anything is working.
Which one to report, and to whomDo our existing controls count in the inherent score?
No. Inherent is deliberately the level without them: score what the risk would cost if the controls were switched off, record the controls as the treatment, then score the residual with them in place. Folding what you already have into the first number is the most common scoring mistake, and it costs you the comparison — both ratings come out the same, and nothing in the register shows what your controls are worth.
Scoring both levels, in orderHow does a 5x5 risk matrix work?
Likelihood and impact are each scored from 1 to 5, and the product places the risk in a band — 1 to 5 low, 6 to 9 medium, 10 to 15 high, 16 to 25 extreme. The matrix computes nothing about the world; it makes two judgements comparable across categories so that a register can be sorted and a decision can be argued. Its usefulness stands or falls with written anchors for each level.
Scales that mean somethingWhat if we cannot judge the likelihood?
Judge the conditions rather than your own history. How often does the situation arise, how exposed are you when it does, and what has happened to comparable organizations? A register that waits for certainty stays empty: score it roughly, write the reasoning into the description, and correct it at the first review. The scale exists to make entries comparable, not to be exact.
Turning judgment into a numberWhat is risk appetite, and how does it differ from tolerance?
Appetite is how much risk an organization is willing to take in pursuit of its objectives — a statement made once, at the top. Tolerance is the deviation it can live with on a single entry. A register only becomes decidable once somebody writes the line down: above it a risk needs treatment, below it monitoring is enough.
Writing an appetite statementWho owns a risk?
One named person, never a department. The owner decides what happens to the entry, answers for its review date, and is the address a reminder goes to. A risk without an owner is a note: it survives the workshop but nobody is accountable for it afterwards.
Ownership, and what it commits you toHow often should risks be reviewed?
Per risk, not per register. What moves quickly — a vendor dependency, a cyber exposure — is worth a quarterly look; a stable operational risk can be annual. The interval matters less than storing the date on the entry and reminding the owner when it arrives, because a review nobody is prompted to do is a review that does not happen.
Review cadence and early indicatorsWhat are the four risk treatment strategies?
Avoid, mitigate, transfer, accept. Avoid drops the activity that carries the risk; mitigate reduces likelihood or impact with a control; transfer moves the financial consequence to someone else through insurance or a contract clause; accept records a deliberate decision to carry it. Accepting is a decision that belongs in the register with a reason, not the absence of one.
Choosing between the fourWhen does a spreadsheet stop being enough?
When more than one person maintains it, when somebody asks who changed a score and when, or when review dates start slipping past unnoticed. A spreadsheet keeps no history and sends no reminders, and those two gaps are what most audit findings are actually about.
The failure modes, in orderWhich regulations expect a risk register?
NIS2 and DORA require documented risk management from the organizations in their scope, and the GDPR expects the risk to data subjects to be assessed and recorded. None of them prescribes a tool or a template. What they share is the demand that a decision can be reconstructed afterwards — which is a register with a history, whatever it is kept in.
NIS2, DORA and the GDPR, side by sideWhat does risk management software cost?
Anywhere from nothing to five figures a year, depending on how much of a GRC suite comes with it. EasyRisk.io charges per editor and leaves readers free: the Free plan carries one editor and one board, Team is €14 per editor and month billed yearly, Business €29. Every plan includes unlimited risks, and viewers never use a seat.
The full price listKeep the answers in one place
EasyRisk.io is the register behind these answers: inherent and residual scoring, one owner per risk, review dates that remind themselves, and a history nobody can rewrite. Free for a single editor, with no card.
Start free