The Cyber Academy take
The risk register is the canonical, living list of identified risks with their analysis, evaluation, treatment and ownership. Not a one-time spreadsheet. Auditors expect dated entries, named owners, traceable changes and review cycles tied to management review. The board version is shorter; the operational version has everything.
What the register really is
The risk register is the single place where the organisation keeps track of what it is worried about and what it is doing about it. People picture a spreadsheet, and it often starts as one, but the artifact that matters is the discipline behind it: every risk identified, analysed, evaluated against the appetite, assigned an owner, given a treatment decision, and revisited on a cycle. A register that was filled in once for a certification and never touched again is not a risk register, it is a museum piece. The test is whether you can look at any line and see when it was last reviewed, who owns it, and what changed since.
Each entry typically carries a description of the risk, the asset or objective it threatens, the analysis (likelihood and impact, however you score them), the evaluation against your criteria, the chosen treatment, the named owner, the residual risk after treatment, and a review date. The detail level is deliberate: when an auditor or an incident pulls on one thread, the entry has to hold up. Vague entries with no owner and no date are the first thing a competent auditor finds, and they undermine the credibility of the whole programme.
How it connects to everything else
The register is not a standalone document, it is the hub the rest of the risk programme plugs into. Identification and analysis follow a methodology such as ISO 27005 or EBIOS RM, and their output lands here. The treatment column is where each risk meets the avoid, reduce, transfer or accept decision, and in an ISO 27001 context that decision traces onward to the Statement of Applicability and the controls that implement it. The evaluation column only means something if there is a written risk appetite to evaluate against, otherwise every rating is one analyst's opinion. So the register sits downstream of the methodology and the appetite, and upstream of treatment and the control evidence.
This is also why the register is a living document tied to management review rather than a one-off deliverable. New risks appear, treated risks change their residual rating, owners move on, and the appetite itself can shift. A mature programme reviews the register on a defined cadence and feeds the significant movements into the management review, so leadership is making decisions on a current picture rather than last year's.
What practitioners actually maintain
In practice the register is where good intentions meet maintenance. The hard part is not the first pass, it is keeping it honest over years. Dated entries matter because an auditor expects to see traceable change: when a risk was raised, when its rating moved, when treatment completed. Named owners matter because a risk with no owner is a risk nobody is actually managing. Review cycles matter because tolerances and dependencies drift, and a register that is two reorganisations old will prioritise the wrong things. The fields are easy to list and hard to sustain, which is exactly why the register, not the policy, is where you can see whether a risk programme is alive.
A frequent confusion is between the register and the treatment plan. The register is the inventory of risks and their current state. The treatment plan is the set of actions you have committed to, with deadlines and accountability, to move risks toward acceptable levels. They reference each other but they are not the same document, and when they drift apart the audit notices. Keep the register as the source of truth for state, and let the treatment plan be the source of truth for the work in flight.
Frequently asked questions
01Is a risk register the same as a risk assessment?
No. The risk assessment is the activity of identifying, analysing and evaluating risks. The register is the living record that holds the output of that activity and tracks it over time, including ownership, treatment and review dates.
02Does ISO 27001 require a risk register?
ISO 27001 does not mandate a document called a "risk register" by name, but it requires documented results of the information security risk assessment and risk treatment. In practice the register is how organisations satisfy that requirement and demonstrate it to auditors.
03What should every entry contain?
At minimum: a clear risk description, the analysis (likelihood and impact), the evaluation against your criteria, a named owner, the treatment decision, the residual risk after treatment, and a review date. Dated, traceable entries are what auditors look for first.
04How often should the register be reviewed?
On a defined cycle and after any significant change, with the material movements feeding into management review. Risks, ratings, owners and the appetite itself all drift, so an unreviewed register quickly stops reflecting reality.
05Why keep a separate board version?
The operational register carries every detail the risk team needs to do its job. The board needs a focused summary of the risks that matter at their level so they can make decisions. Reconcile the two, but do not force one document to serve both audiences.