Learn It. Grow It. Own It.

How effective and complete is your risk register?

risk Aug 13, 2026

The Risk Register Is Not Risk Management

I have a risk register. Therefore, I manage risk.

If only it were that easy.

Somewhere on a shared drive, perhaps in a beautifully formatted spreadsheet with enough red, amber and green to resemble a traffic light convention, sits the organization’s risk register.

Risks identified? Check.
Owners assigned? Check.
Ratings completed? Check.

So we’re managing risk, right?

Not necessarily.

A risk register is an important tool. But confusing the tool with risk management is a little like owning a treadmill and assuming you’re now physically fit.

Eventually, you have to get on the thing.

The Risk Register Is the Map, Not the Journey

Let’s give the risk register the credit it deserves.

A good risk register can help an organization identify what could go wrong, assess likelihood and impact, assign responsibility, document planned responses and track changes over time.

That’s valuable.

But the register itself doesn’t manage a single risk.

People do.

A spreadsheet can’t challenge an assumption. It can’t notice that a mitigation action hasn’t happened. It can’t walk into a meeting and say, “Something has changed here, and I think we need to talk about it.”

It certainly can’t make a difficult decision.

The risk register records the conversation.

It should never replace it.

When Risk Management Becomes an Administrative Exercise

This is where organizations can get into trouble.

The risk register begins life with enthusiasm. Workshops are held. Risks are identified. People debate likelihood and impact. Owners are assigned. Mitigation plans are created.

Then everyone goes back to work.

Three months later, someone remembers that the risk committee is meeting next Tuesday.

Suddenly, the register receives a burst of attention.

Emails fly.

“Can everyone please update their risks by Friday?”

Ratings change. Comments are refreshed. A few dates move. Perhaps one risk goes from amber to green.

The committee meets.

The spreadsheet is presented.

Everyone nods.

Meeting adjourned.

See you next quarter.

Technically, the organization has a risk management process.

But is it actually managing risk?

That’s a very different question.

Risk Doesn’t Wait for the Next Meeting

Risk has an inconvenient habit of refusing to follow our calendars.

A supplier can begin struggling financially on Wednesday.

A key employee can resign on Thursday.

A cyber vulnerability can emerge overnight.

A project can start slipping today.

A competitor can introduce something that changes your market before the next quarterly risk meeting ever arrives.

That means risk management has to be alive.

The risks identified six months ago may not be the risks that matter most today. Their likelihood may have changed. Their potential impact may have changed. Controls may have weakened. Mitigation activities may have stalled.

And entirely new risks may have walked through the front door while everyone was busy monitoring the old ones.

A risk register should therefore be a living document, not an organizational time capsule.

“We Have an Owner”

Excellent.

What does the owner actually own?

Assigning someone’s name to a risk doesn’t automatically create accountability.

A genuine risk owner should understand the risk, monitor changes, know what controls or responses are in place, recognize when something is deteriorating and have enough authority to do something about it, or know exactly where to escalate it.

Otherwise, “risk owner” can become little more than someone’s name occupying a cell in Excel.

There is another question worth asking:

Does the person named as the risk owner know they are the risk owner?

Don’t laugh.

It’s worth checking.

The Seduction of Red, Amber and Green

We love colors.

Green feels safe.

Amber gets our attention.

Red makes people sit up a little straighter.

But risk management isn’t a coloring exercise.

A risk rated green can still deserve attention. A red risk may be entirely acceptable if leadership understands it and has consciously decided to accept the exposure.

The color isn’t the decision.

It is information that should help us make the decision.

That’s why one of the most useful questions we can ask about any significant risk isn’t simply:

“What color is it?”

It’s:

“What has changed since the last time we looked at this?”

Now we’re having a risk conversation.

Mitigation Plans Need Verbs

Consider these two mitigation statements:

“Continue to monitor supplier performance.”

and

“Finance will review the supplier’s financial stability monthly through December, with any deterioration escalated to the project steering committee within five business days.”

One sounds reassuring.

The other tells us who is doing what, how often, for how long and what happens if something changes.

Effective mitigation needs action.

Someone has to do something.

There should be ownership, timing and, where appropriate, evidence that the action actually happened.

“Monitor closely” may sound impressive in a risk register.

But unless someone can explain who is monitoring what and what they will do when they see trouble, it isn’t much of a mitigation strategy.

Ask Better Questions

One of the simplest ways to move from documenting risk to managing it is to change the conversation.

Instead of spending the entire risk meeting asking people to explain what is already written in the register, ask questions that make them think.

What has changed?

Which risk worries you more today than it did three months ago?

What are we assuming is true?

Which mitigation action is behind schedule?

What would cause this risk to escalate quickly?

Are there risks people are discussing privately that haven’t made it onto this register?

That last question can be particularly interesting.

Because sometimes the most important risks in an organization aren’t the ones sitting neatly in rows on a spreadsheet.

They’re the ones people are talking about in hallways, after meetings and over coffee.  It may be the ones people are afraid to mention.

Risk Management Should Occasionally Make Us Uncomfortable

A healthy risk conversation isn’t designed to reassure everyone that everything is fine.

It is designed to help us see what might not be fine while we still have time to do something about it.

That requires honesty.

It requires people who are willing to raise concerns.

It requires leaders who don’t shoot the messenger when someone brings them bad news.

And it requires enough curiosity to look beyond the comforting green box on the dashboard and ask whether the underlying reality tells the same story.

Sometimes good risk management means saying:

“I know the report says we’re okay, but something doesn’t feel right. Let’s look again.”

That isn’t negativity.

That’s awareness.

So, Do We Need the Risk Register?

Absolutely.

This isn’t an argument for throwing away the spreadsheet.

A well-designed risk register is an incredibly useful part of a strong risk management process. It creates structure, helps maintain visibility and gives organizations a way to document and track important information.

But it is only one part.

The real work happens in the conversations, decisions, actions and follow-up that surround it.

So the next time someone proudly announces:

“Don’t worry. It’s on the risk register.”

There is one more question worth asking.

“Great. What are we doing about it?”

Because identifying a risk is important.

Documenting it is useful.

Color-coding it may even make the spreadsheet look rather impressive.

But none of those things actually manages the risk.

People do.

Stay connected with news and updates!

Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.

We hate SPAM. We will never sell your information, for any reason.