The core fields
At minimum, each entry needs: a clear risk description (specific enough to act on, not "cybersecurity risk" as a single line item), likelihood and impact ratings, the controls currently in place, a named individual owner, a treatment plan with a target date, and a status field showing whether it's open, in progress, or closed.
Who should own it
The register itself should have an overall owner — typically someone at a governance or risk-management level, not IT alone — even though individual risk entries are owned by whoever is best placed to act on each one. A register with no single accountable owner tends to go stale within a few months.
Review cadence
A risk register that's updated once, after an assessment, and never touched again isn't really a risk register — it's a historical document. A working register gets reviewed on a set schedule (commonly quarterly) and updated whenever a new risk is identified or an existing one changes status.
A practical checklist
- Does every entry have a named individual owner, not a department?
- Are likelihood and impact rated using a consistent scale across all entries?
- Is there a documented review cadence, and is it actually being followed?
- Does the register feed into board or leadership reporting, or does it sit unread?
