Risk log template (ISO 31000)
A risk register laid out the way the ISO 31000 process works: identification, inherent scoring, treatment, residual scoring, review. Twenty-six labeled columns, dropdowns where a register usually drifts, and six columns that calculate themselves. Opens in Excel, Google Sheets or Numbers.
No email required. Free to use, share and adapt.
What is inside
- How to use — the five steps, both scales, and the severity bands on one page.
- Register — 26 labeled columns, 60 rows deep, with the header frozen and a filter on every column.
- Matrix — every likelihood-by-impact combination with its score and band.
- Lists — the dropdown values and the band table; change one here and the register follows.
- Score, severity, next review date and the justification check are formulas, not typing.
- Three worked examples to delete once the layout is clear.
The 26 columns
Grouped by the stage they serve, and named the way EasyRisk.io names them, so a register started here moves across without renaming anything. A register that carries fewer than these tends to fail the same way: it records what went wrong without recording what was decided about it.
- Identification
- IDRisk titleCategoryStatusOwnerDescriptionContextCauseConsequence
- Analysis
- Inherent likelihoodInherent impactInherent scoreInherent severity
- Treatment
- Existing controlsTreatment strategyTreatment actions
- Residual assessment
- Residual likelihoodResidual impactResidual scoreResidual severity
- Guardrail
- Justification neededReduction justification
- Monitoring
- Last reviewedReview every (months)Next reviewNotes
The guardrail pair is worth a word. When the residual score falls more than eight points below the inherent one, or drops two whole bands, the register marks the row as needing a written reason. A large improvement nobody can explain is the first thing an audit will question.
How to keep a risk log
Five steps, run as a loop rather than once. They are the working shorthand for the ISO 31000 process, which groups identification, analysis and evaluation under risk assessment and runs review and reporting alongside everything else — the ISO 31000 guide sets out that structure in full.
1. Identify
One row per risk, with a stable ID, an owner and a date. Keep cause and consequence in their own columns — a row is only useful if someone who was not in the workshop can read it and understand what could go wrong.
2. Analyze
Score inherent likelihood and inherent impact from 1 to 5, before existing controls are taken into account. Score and severity appear on their own.
3. Evaluate
Compare the severity against the line your organization has set for itself. Above it, a risk needs treatment; below it, monitoring is enough. If nobody has written that line down, this is the step to stop at.
4. Treat
Choose avoid, mitigate, transfer or accept, and record the actions, their owners and their dates. A strategy without an action is a wish.
5. Monitor
Score again for residual likelihood and impact, set the date of the last review and how often it repeats. The next date follows from those two, and a large drop in severity asks for a reason.
When a spreadsheet stops working
A file like this is enough for one person and a first register. It stops being enough at three predictable points: when a second person edits it and neither version is authoritative, when someone asks who changed a score and when, and when a review date passes without anyone noticing.
EasyRisk.io uses the same fields and closes those three gaps — a change history nobody can rewrite, review dates that announce themselves, and a matrix that updates as scores change. Viewers and auditors read without using a seat.
Frequently asked questions
- What is a risk log?
- A risk log — also called a risk register — is the single record of every operational risk an organization is tracking. Each entry says what could go wrong, how likely it is, how bad the consequence would be, who owns it, and what is being done about it. It is the artifact the ISO 31000 process produces and maintains.
- What columns should a risk log contain?
- At minimum: an ID, title, category, owner and status; the cause and the consequence as separate fields; inherent likelihood and impact with the resulting severity; existing controls; a treatment strategy of avoid, mitigate, transfer or accept, with the actions that follow from it; residual likelihood, impact and severity; and a review date. The template carries all 26 of these.
- What is the difference between inherent and residual risk?
- Inherent risk is the risk before controls are taken into account. Residual risk is what remains once the controls and treatments are working. Scoring both is what makes a register defensible: it shows the risk was real and shows what the controls actually moved.
- Does the template calculate anything?
- Six columns calculate themselves: both scores, both severity bands, the next review date, and whether the drop from inherent to residual needs a written justification. Likelihood, impact, category, status, strategy and the review interval are dropdowns, so a register cannot drift into three spellings of the same word.
- When should I move from a spreadsheet to a tool?
- When more than one person maintains it, when someone asks who changed a score and when, or when review dates start passing unnoticed. A spreadsheet has no history and sends no reminders; those two gaps are what most audit findings are about.