Risk & policies

How do I build a risk register?

Build a risk register by identifying risks from real sources, describing each clearly, scoring inherent likelihood and impact on a consistent scale, assigning an owner and a treatment, linking the controls that reduce each risk and scoring residual likelihood and impact, and reviewing it on a cadence so it stays current.

Step by step

  1. Identify risks. Draw from real sources: assets, threats, past incidents, audit findings, and vendor assessments.
  2. Describe each risk. State clearly what could happen and to what, so the risk is comparable and actionable.
  3. Score inherent likelihood and impact. Use a consistent scale (often 5×5) so risks can be compared and plotted on a heat map.
  4. Assign an owner and a treatment. Choose accept, mitigate, transfer, or avoid, and give each risk an accountable owner.
  5. Link controls and score residual risk. Attach the controls that reduce the risk, then score residual likelihood and impact.
  6. Review on a cadence. Revisit on a schedule and after incidents or major changes so the register stays current.

Inherent vs residual is the key idea

A good register distinguishes inherent risk (before controls) from residual risk (after them). The gap shows how much your program actually reduces exposure and where more work is worthwhile.

Keep it living, not a one-off

The most common failure is building the register for an audit and never updating it. Owners, treatments, and a review cadence are what turn it from a document into a working control.

FAQ

What fields does a risk register need?

At minimum: description, likelihood, impact, owner, treatment, linked controls, and status. Distinguishing inherent from residual risk makes it far more useful.

Do SOC 2 and ISO 27001 require a risk register?

Effectively yes. Both expect a maintained risk assessment, and a living risk register is the standard way to demonstrate it.

Related

What is a risk register? → Risk register in Keel → How do I prepare for SOC 2? →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free