The Cadence Kit

Articles

How to build a risk register people actually use

Most risk registers are written once and never read. The difference is in four things.

Most risk registers are written for an audit, read by nobody, and updated the week before the next audit.

You can spot one instantly. Every risk is worded as a general anxiety ("resourcing"), every mitigation is a verb with no owner ("monitor closely"), and nothing has changed since the workshop where they were written.

The difference between that and a register people use is not sophistication. It is four things.

1. A risk is an event, not a topic

"Resourcing" is not a risk. It is a subject heading. Nobody can tell whether it has happened, so nobody can tell whether the mitigation worked.

Write risks as a sentence with a cause, an event and a consequence:

If the two senior engineers on the migration are pulled onto the platform incident, then the cutover slips past the March freeze, resulting in a three-month delay and £180k of extended dual-running.

That is longer, and it is the point. It is specific enough to argue with, specific enough to mitigate, and specific enough to close when it stops being true.

The test: could two people independently agree on whether this has happened? "Resourcing" fails. The sentence above passes.

2. Score impact and likelihood separately, and define the scale

A five-by-five matrix is standard. What is usually missing is the definition of what a 4 means.

Without definitions, scoring is vibes, and vibes drift: the same risk scores 3 in March and 5 in September because the mood changed. Write the scale down, in the register, with money and time in it:

Then two people scoring the same risk independently land in the same place, which is the only way a heat map means anything.

3. Mitigation is an action with a name and a date

"Monitor" is not a mitigation. Neither is "escalate if required", which means nothing will happen until it is too late to help.

A mitigation is a thing somebody does by a date that changes the score. Record what it changes: does it reduce the likelihood, the impact, or both? A register that shows a pre-mitigation and post-mitigation score is doing management information. One that shows a single score is doing paperwork.

And record the residual — where the risk sits after the mitigation has worked. That is the number the board is actually accepting. Reporting only the gross score overstates exposure and trains people to ignore the top of the register.

4. Somebody owns it, and it is not a committee

A risk owned by "the programme" is unowned. Risk ownership is a single named person who is accountable for the mitigation happening, and it should be the person who can actually do something — which is frequently not the person who raised it.

Review dates matter as much as owners. A risk with no next review date drops out of the register's working set immediately, and the register slowly becomes an archive.

What to report upwards

Not the whole register. A board that receives 60 risks reads none.

Report:

The trend column does most of the work. A risk at 12 and falling is a mitigation working. A risk at 9 and rising is the thing that will be at 16 next quarter, and it is invisible in a register sorted by current score.

The register is a living document or it is nothing

The honest test of a risk register is whether anyone has opened it between reviews. If the only edits happen the day before the governance meeting, it is an artefact produced for that meeting rather than a tool for running anything.

The usual fix is not more discipline. It is a shorter register. Forty risks nobody maintains is worse than twelve that are current — and the forty are usually forty because closing a risk feels like an admission that it should never have been opened.

Close them. A register where things close is a register people believe.


The [Risk Register & Heat Map](/products/risk-register-and-heat-map.html) has defined scoring scales, pre- and post-mitigation scores, owners, review dates, a real heat map and a movement view — with a worked example carrying a register mid-life rather than freshly written. £26.