The core fields

At minimum, each entry needs: a clear risk description (specific enough to act on, not "cybersecurity risk" as a single line item), likelihood and impact ratings, the controls currently in place, a named individual owner, a treatment plan with a target date, and a status field showing whether it's open, in progress, or closed.

Who should own it

The register itself should have an overall owner — typically someone at a governance or risk-management level, not IT alone — even though individual risk entries are owned by whoever is best placed to act on each one. A register with no single accountable owner tends to go stale within a few months.

Review cadence

A risk register that's updated once, after an assessment, and never touched again isn't really a risk register — it's a historical document. A working register gets reviewed on a set schedule (commonly quarterly) and updated whenever a new risk is identified or an existing one changes status.

A practical checklist

  • Does every entry have a named individual owner, not a department?
  • Are likelihood and impact rated using a consistent scale across all entries?
  • Is there a documented review cadence, and is it actually being followed?
  • Does the register feed into board or leadership reporting, or does it sit unread?

Frequently asked questions