Creating risks
How to write, classify, and structure register entries so they stay useful.
A register entry is only as useful as the statement behind it. This guide covers how to create risks and how to write them so they survive review cycles.
Creating an entry
From the register, create a new risk and complete the core fields: title, type, category, owner, accountable department, and inherent ratings. Set a next-review date at creation time, not later. Entries without a review date are the ones that go stale.
Writing the risk statement
Write the risk as a cause-and-effect statement, not a topic. Compare:
- Topic: "Cybersecurity."
- Statement: "Aging systems increase exposure to a service-disrupting cyber incident."
The topic tells you nothing about exposure. The statement names a condition and a consequence, which is what an owner can act on and a rating can describe.
Classifying consistently
Use the same type and category vocabulary across departments. Consistent classification is what makes trend reporting and AI-suggested classification useful. If two departments call the same exposure by different names, the register undercounts it.
Assigning ownership
Every risk gets one owner and one accountable department. One owner, not a committee. Shared ownership diffuses accountability, and diffuse accountability is how risks go unreviewed.
Duplicates and merges
Before creating a new risk, search the register. If a similar entry exists, merge or update it instead of adding a near-copy. A smaller, accurate register is easier to review and easier to report from.
After creation
Link the risk to its existing controls, plan treatments for what is missing, and set the next review. Then let the register carry the work forward.