Skip to content

Risk Register

Definition

A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score, and review date. The authoritative record of an organisation's risk posture.

Records per risk
Description, inherent score, owner, treatment decision, controls, residual score, review date
Role
Authoritative record of organisational risk posture
Feeds into
Risk treatment plan and Statement of Applicability
Maintained by
Risk owner or ISMS/risk management function

Common questions

How is a risk register different from a risk treatment plan?+

The register is the full inventory of identified risks with their scores and status. The treatment plan is the action-oriented document that details which controls address each risk and by when, drawing its content directly from the register.

Why does the register need a review date for every entry?+

Risk levels change as the business, the threat environment, and the controls in place change. A stale entry with no review date can hide a risk that has grown since it was last assessed, so review dates keep the register current.

What is the difference between inherent and residual risk in the register?+

Inherent risk is the exposure before any controls are applied. Residual risk is what remains after the selected controls are implemented, and it is the figure used to judge whether further treatment is needed.

Related terms

Residual Risk
The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...
Risk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Risk Treatment
The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer...
Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.