Category: Risk management frameworks · Reviewed by Simon Temme, Account Executive · Last reviewed
A risk register is the central record of identified risks, their assessment, ownership and treatment. It is the most basic operational artefact of any risk management system and is referenced in ISO 31000, COSO ERM and the PRA’s Insurance Rulebook.
A practical register contains, at minimum:
| Field | Purpose |
|---|---|
| Risk ID | Unique reference for traceability |
| Risk description | Specific, observable event (not a generic category) |
| Cause(s) | The drivers that could give rise to the event |
| Consequence(s) | What happens if the event occurs |
| Inherent likelihood / impact | Pre-control assessment |
| Current controls | What is in place today |
| Residual likelihood / impact | Post-control assessment |
| Risk owner | A named individual (not a committee) |
| Treatment / action | Tolerate, transfer, treat or terminate, with action owner and due date |
| Last reviewed | Date of last formal review |
In small firms a spreadsheet is sufficient. As complexity grows, registers should integrate with:
Maintained by Apex Insurance Brokers. FCA FRN 724952. Companies House 07014570.
Apex Insurance Brokers serves UK professional services firms and commercial businesses. Call 0117 325 0027, email info@apexinsurancebrokers.co.uk, or request a quotation.
Get a quoteOffices: QCS, 53 Queen Charlotte Street, Bristol BS1 4HQ · Unit 24, Basepoint Centre, Jubilee Close, Weymouth DT4 7BS