The tale of a risk register...
I was handed a risk register once. Two hundred and thirty-seven risks. The title of one of them was four sentences long. Its description took up an entire paragraph.
My first thought was: who is going to manage this?
Not in theory. In practice. Who owns this? Who updates it when the business changes? Who looks at it and actually does something? The honest answer: nobody. Which means the register was dead on arrival.
“A risk register that no one maintains is not a risk management tool. It is a document that makes an organisation feel like something is being done.”
Risk Layered
This is not an unusual story. After fifteen years in assurance and risk management, I have seen this pattern repeat in organisations of every size. The register gets built, populated with risks, rated by some committee — and then filed. Not because the organisation doesn’t care about risk. But because the register itself was never designed to be useful. It was designed to demonstrate effort.
The three ways registers fail
Every failing register I have reviewed shares one of three problems. These are not technical failures. They are cultural ones and that is why they are so hard to fix.
Failure 1: The Vague Description
Risks with descriptions so broad they could mean anything. I once saw a risk titled simply: ‘Weapons.’ Its description: ‘Reckless or careless use of a weapon.’
Now, is that a farmer with a rifle? A security guard? A child finding a kitchen knife? The description tells you nothing. Which means you cannot mitigate it, assign it, or rate it. It is a placeholder that looks like risk management but does nothing.
Here is another: ‘Critical event.’ Description: ‘If a critical event occurs after hours, it may go unnoticed, resulting in temporary loss of services.’ What is a critical event? Server failure? A break-in? A medical emergency? The word ‘critical’ is doing no work here at all.
“A risk without a cause is a worry. A risk without a consequence is a platitude. A risk without either is a placeholder.”
Risk Layered
Failure 2: The Flat List
A list of fifty risks. Every single one rated ‘medium.’ If everything is medium, nothing is medium. What you actually have is a list with no prioritisation. And that means when a real problem lands on your desk, you have no way to know which fifteen of those fifty you should focus on right now.
This happens when the Risk Assessment Matrix (RAM) has not been calibrated properly. Without calibration, the ratings become meaningless. You end up with a register that looks complete but has no signal.
I have seen registers where everything is red. I have seen registers where everything is green. Neither tells you anything useful.
Failure 3: The Spreadsheet That Lies
The third failure is specific to Excel-based registers. Here is what I see happen. A risk management review concludes annual, perhaps. And the controls documented are things that were planned. Ideas. Things in a project proposal. They were never actually implemented.
So the register says: ‘Control in place: quarterly audit of supplier contracts.’ The reality: no one has run that audit in eighteen months. The register is a projection. A hope. Not a record of what actually exists.
Spreadsheets lie because they are easy to fill in and hard to maintain. When someone marks a control as ‘complete’ without checking whether it actually exists in practice the register stops reflecting reality.
The impact: the organisation makes decisions based on controls that are not there. Projects overrun because risks were systematically underestimated.
“A register that is not kept current is not a risk register. It is a record of what someone once thought might be true.”
Risk Layered
The culture connection
Here is what the research confirms and the practitioner pattern suggests: these three failures are symptoms of the same underlying problem.
A recent Optro report on regulatory compliance found that the financial sector spends $181 billion annually maintaining compliance. Non-compliance costs, on average, are 2.7 times the cost of compliance. Yet 87% of employees across industries report encountering situations where they are unsure how to comply with the regulations that govern their own work.
That is not a systems problem. That is a culture problem.
When risk management lives in a spreadsheet that no one owns, it becomes theatre. When the compliance team is the only team thinking about risk, it becomes bureaucracy. When the register is updated once a year to satisfy an auditor and then ignored, it becomes a historical document not a working tool.
The Optro research identifies three characteristics of organisations that fail at compliance: isolated teams, a lack of enterprise-wide culture, and legacy systems that no longer reflect what is actually happening. These same characteristics destroy risk registers.
The isolated team: risk is owned by the risk manager, not by the people who create the risks. The absent culture: nobody questions whether the controls documented actually exist. The legacy system: the register was built in 2019 and no one has redesigned it since.
Source: Optro, ‘From Reactive to Resilient: Mastering Regulatory Compliance with AI’, 2026. Data: $181B annual compliance spend, 2.7x non-compliance cost multiplier, 87% employee uncertainty rate (Gartner/Globalscape research cited in Optro report).
What a useful risk register looks like
The risk register is not inherently useless. The problems are fixable if you are willing to change what the register is for.
The Tripod Formula: Event, Cause, Consequence
Every risk description should answer three questions: What might happen? Why would it happen? What would happen if it did?
This is the tripod. It is not a formula for its own sake. It is a forcing function. When you cannot answer all three parts, the risk is not well understood. When you can, the mitigation becomes obvious.
Take the ‘Weapons’ risk rewritten properly: ‘A firearms incident may occur because licensed farmers and hunters lack good firearms handling habits, which could lead to fatalities or serious injury.’ Now you can design training, enforce licensing checks, write an operating procedure. The risk has become manageable.
Once risks are written correctly using the tripod, something unexpected happens: the register shrinks. Duplicates collapse. Vague items clarify. The duplicates ‘risk of bad press,’ ‘risk of social media comments,’ ‘risk of customer information leakage’ turns out to be the same risk expressed differently.
It works at any scale
The register is not a large-organisation luxury. Any team has a risk landscape. The question is whether they have named it.
Ask the team: what is the one thing this team is here to prevent? Whatever that answer is that is the top of the register. Everything else is elaboration.
The same principle works in reverse at scale. When a register exceeds fifty risks, before adding more: ask yourself, am I describing the same risk in multiple ways? Is anyone else in management dealing with more than ten active risks at any one time? If the answer is yes, chances are the register is bloated and bloat is a warning sign that the register has become a list rather than a tool.
Quality risk descriptions, three questions to make
Take any risk description on your register. Ask three questions:
Does this risk have an Event?
Does it have a Cause?
Does it have a Consequence?
If any of those three elements are missing the risk is incomplete. In my experience, the missing element is almost always the Cause. People can describe consequences like a fatality, or a financial loss easily but struggle to name what actually triggers a risk. That is the gap. And it is where most risk registers quietly fail.
In summary
Your risk register is not a compliance document. It is not a template you found online and will never look at again. It is a confession of what your organisation values and what it has decided not to look at.
The register you have is telling you something. Whether it is useful depends entirely on whether anyone is willing to read it honestly and do something about what they find.
If your register has risks with no cause, ratings that are all the same, and controls no one has verified that is not a risk management problem. That is a culture problem wearing a spreadsheet costume. Fix the culture, and the register will follow.
