Risk Register
Pronunciation: RISK REH-jih-stur
Definition
A risk register is a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information. Risk Register must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Risk Register to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.
Overview
A risk register creates a common view of material scenarios across a defined organization, product, project, or system. Typical fields include description, cause, affected objectives, inherent risk, controls, residual risk, owner, action, due date, and status.
Registers lose value when entries are vague, duplicated, outdated, or disconnected from decisions and evidence. A long list is not necessarily comprehensive, and a low rating may hide severe consequences, correlated risks, or uncertainty.
Organizations should use clear scenario language, stable identifiers, consistent methods, linked evidence, overdue-action escalation, and regular owner review. Aggregation and reporting should reveal concentration, common dependencies, accepted exposure, and changes rather than only count open items.
A risk register is a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information. A risk register is a living decision system, not an inventory exercise, and depends on specific scenarios, accountable owners, evidence, and timely updates.
For Risk Register, the assessment should evaluate a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information. The assessment record should separate observed evidence supporting a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about a maintained record of identified risks, assessments, owners, controls, treatments, decisions, and monitoring information to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
A risk register is a living decision system, not an inventory exercise, and depends on specific scenarios, accountable owners, evidence, and timely updates.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)