Documenting, Tracking, and Managing Organizational Risks
A risk register (or risk log) is a centralized document that tracks all identified risks facing an organization. It serves as the single source of truth for risk management, enabling consistent tracking from identification through resolution.
| ID | Risk Description | Category | Severity | Owner | Status | Due Date |
|---|---|---|---|---|---|---|
| R-001 | Unpatched Exchange servers vulnerable to ProxyLogon | Vulnerability | Critical | J. Smith | Mitigating | 2026-01-10 |
| R-002 | Third-party vendor lacks SOC 2 certification | Compliance | High | M. Johnson | Open | 2026-02-15 |
| R-003 | Phishing success rate above threshold (15%) | Human | Medium | A. Williams | Mitigating | 2026-01-31 |
| R-004 | Legacy system EOL with no migration plan | Operational | High | T. Brown | Open | 2026-03-01 |
| R-005 | Weak password policy on admin accounts | Access Control | Low | J. Smith | Closed | 2025-12-15 |
While organizations customize their registers, these fields are commonly included:
Unique identifier for tracking (e.g., R-001, RISK-2026-042)
Clear, concise statement of what the risk is
Classification (Technical, Compliance, Operational, Human, Financial)
Probability the risk will materialize (1-5 scale)
Severity if risk occurs (1-5 scale)
Calculated: Likelihood × Impact
Person accountable for managing this risk
Actions to reduce likelihood or impact
Current state (Open, Mitigating, Closed, Accepted)
Risk remaining after controls are applied
Deadline for mitigation completion
When risk was last assessed/updated
Practice creating a risk register entry. Fill in the fields to see your entry formatted:
Test your understanding. You need 80% (4/5) to pass.