The email arrives three weeks out: the audit is scheduled, please have the risk register available. What follows is usually a scramble — someone opens two hundred entries, fixes whatever catches the eye, and runs out of afternoon somewhere in the middle of the Cs.
There is a better use of the same time. Auditors do not read a register the way its owner does. They sample, they look for internal consistency, and they follow one thread until it either holds or breaks. You can walk that path yourself, in four passes, in about half an hour.
This is the working version of the register health check — the same seventeen checks, arranged by the order in which they cost you.
Before you start: decide what "fixing" means
Two rules make the difference between a useful half hour and a cosmetic one.
Do not invent history. If a review was due in March and never happened, recording one today with March's date is not a correction — it is the one finding that turns a conversation about hygiene into a conversation about integrity. Leave the gap, note it, and be ready to say what changed since.
Fix facts, note judgments. A missing owner is a fact you can correct in ten seconds. A residual rating you now consider too optimistic is a judgment, and re-scoring it the week before an audit looks exactly like what it is. Put it on the agenda for the next review instead.
Pass 1 — Accountability (5 minutes)
Filter for risks with no owner. This is the fastest pass and the one an auditor is most likely to open with, because it needs no domain knowledge at all.
Every risk gets a named person — not a department, not "IT". If you cannot name one in ten seconds, that is not an administrative gap; it is the finding. A risk nobody will claim is either somebody else's risk or not a risk you are actually managing.
While you are here: check that the owners still work here and still hold the role. Ownership that quietly outlived a reorganisation is common and reads badly.
Pass 2 — The cycle (10 minutes)
Filter for overdue reviews, and for risks marked Monitored where no review was ever recorded.
Overdue is survivable and normal. A register with no overdue items at all can mean the discipline is genuinely good — or that the cadence is set too loosely to reveal anything; check which of the two you are looking at before you take comfort from it. What is not survivable is the pattern: a whole category overdue by a year says the review cadence exists on paper only.
Sort what you find into three piles. Reviews you can genuinely do this week — do them, with today's date. Risks that need the owner in the room — book the slot, and let the register show the date. Risks nobody has looked at in a year because they no longer matter — close them, with a reason. A closed risk with a stated reason is a sign of an active register. An untouched one is the opposite.
Pass 3 — Internal contradictions (10 minutes)
This is the pass that finds what an auditor finds, and it is entirely mechanical. Four questions, in this order:
- Is anything closed with actions still running? Either the actions are done and nobody ticked them, or the risk was closed early. Both take a minute to settle, and both look careless when discovered by someone else.
- Does any strategy carry no action? Mitigate, Avoid and Transfer each promise activity. If the promise is three months old and no action exists, the honest fix is often to change the strategy, not to invent an action.
- Does any Accept carry open actions, or an unexplained lower residual rating? Open actions contradict the decision outright. A lower residual is only a finding when nothing on the entry names the control that earned it — write that sentence, or change the strategy.
- Is any residual rating far below the inherent one with no justification written down? This is the one to spend real time on — see the next section.
Pass 4 — The reduction you cannot explain (5 minutes, and worth more)
Take the entries where the residual rating drops two bands or more, and read the justification. If there is none, write it now, in one sentence, while you still remember the reasoning:
Access to the payment system requires two approvers since March; the change is enforced in the system, not by instruction.
That sentence is the difference between a control and a hope. It names what was implemented, when, and how it is enforced — and it is exactly what an auditor will ask about the moment they see a large drop. Written today it takes sixty seconds. Reconstructed in the audit meeting it takes twenty minutes and sounds improvised, however true it is.
If you cannot write the sentence, that is the actual finding, and it is better to meet it now: the number is wrong, or the control lives in somebody's habits rather than in a system.
What to say about what you did not fix
Bring a short list. Three overdue reviews with dates booked, two risks awaiting an owner decision at the next management meeting, one rating you intend to revisit. A register with named, dated open items reads as managed. A register that looks flawless a week before an audit invites the question of when it was last honest.
This is also the moment the change history earns its keep: it shows the work was continuous rather than a week of tidying. If your register cannot show who changed what and when, that gap will outrank every finding in this article.
The checklist, in one block
Copy this into the agenda of whoever runs the register.
Pass 1 - Accountability (5 min)
[ ] Every risk has a named person, not a department
[ ] Every named owner still holds the role
Pass 2 - The cycle (10 min)
[ ] Overdue reviews listed and sorted: do now / book / close
[ ] Monitored risks with no review ever recorded
[ ] Closures carry a reason
Pass 3 - Contradictions (10 min)
[ ] Nothing closed while its actions are still running
[ ] Every strategy carries at least one action
[ ] No Accept with open actions or an unexplained lower residual
[ ] No residual rating above the inherent one
Pass 4 - The unexplained drop (5 min)
[ ] Every reduction of two bands or more has one sentence naming the control
[ ] That sentence says what was implemented, when, and how it is enforced
Bring to the meeting
[ ] The list of items you did NOT fix, with dates
Making the half hour unnecessary
Every pass above is a filter over fields you already have. That is precisely the work worth automating: in EasyRisk.io the same checks run continuously across the register, so the pre-audit half hour turns into a look at a list that has been current all along — and the reviews, the owners and the reasoning are recorded as they happen rather than reconstructed under time pressure.
Frequently asked questions
How long before the audit should you run this? Two to three weeks. Far enough out that a booked review can actually happen; close enough that what you fix is still true on the day.
Should you fix everything you find? No. Fix facts — owners, ticked actions, missing sentences you can write truthfully today. Note judgments and schedule them. The list of noted items is an asset in the meeting, not an admission.
What do auditors actually ask for? Usually four things: how risks are identified, how they are rated and by whom, what was decided and by when, and evidence that reviews happen. See reporting risk to leadership — the same material answers both audiences, in different lengths.
Does this replace an internal audit of the risk process? No. This checks the record. An internal audit checks whether the process behind the record is working, including whether the right risks are in the register at all.
Half an hour will not make a neglected register defensible. What it will do is remove every finding that costs nothing to prevent — and leave the meeting free for the risks themselves, which is what everyone in the room would rather be discussing.