A risk register is the backbone of any compliance programme. Here is what it is, what belongs in it, and how to actually keep one useful — plus a free template to get started.

Almost every security framework — ISO 27001, NIST CSF, SOC 2, Cyber Essentials and more — expects you to identify and manage risk in a structured way. The tool that does this is the risk register. Yet many teams either don't have one, or keep a stale spreadsheet that gets dusted off only when an auditor asks. This guide explains what a risk register really is and how to keep one that's genuinely useful.

What a risk register is

A risk register is a single, living record of the risks facing your organisation, together with how significant each one is and what you're doing about it. It turns vague worries into a documented list you can prioritise, act on and review. Done well, it's not a compliance chore — it's a management tool that tells you where to spend your limited security effort.

What belongs in a risk register

A practical risk register captures, for each risk, a clear description of what could go wrong, the asset or process affected, the likelihood of it happening, the impact if it does, and a resulting risk score that lets you rank one risk against another. It should also record the owner responsible for the risk, the treatment decision — whether you're reducing, accepting, transferring or avoiding it — and the current status. The scoring doesn't need to be scientific; consistency matters far more than precision.

How to actually use it

The value of a risk register comes from what you do after you write it down. Start by identifying risks from real sources: past incidents, near misses, supplier dependencies, staff feedback and threat trends. Score each one, then focus your attention on the high-scoring risks rather than trying to fix everything at once. Assign a genuine owner to each — a risk with no owner never gets treated. Finally, review the register on a regular cadence so it reflects reality rather than a snapshot from a year ago.

The most common mistakes

The biggest failure mode is treating the register as a one-off document created for an audit and then forgotten. The second is scoring everything as high, which defeats the purpose of prioritisation. The third is a register with no owners, so nothing ever moves. A short, honest, regularly reviewed register beats a long, impressive-looking one that nobody maintains.

Get started with SnapGRC's free risk register

SnapGRC offers a free risk register designed to make all of this easy: capture risks, score them consistently, assign owners and track treatment over time in one place — without the version-control headaches of a spreadsheet. It's a simple, cost-aware way to start managing risk properly, and it grows with you as your compliance programme matures. If you're building toward ISO 27001 or any other framework, a solid risk register is the foundation everything else sits on.