# A risk register template only gets you so far. Excel breaks the moment more than one person owns it.

Most organisations start their risk register in a spreadsheet. It works until a second risk owner edits it, a rating changes with no record of why, or the board asks for a rollup that takes three days to compile. This checklist sets out the fields and structure a risk register actually needs — the same structure XGRC® ERM runs live, with an audit trail built in.

**Frameworks:** ISO 31000, COSO ERM, King V, Risk Register

## A spreadsheet risk register works right up until it does not.

A risk register in Excel is fine for one person, once. It stops working the moment a second risk owner needs to edit it, a rating needs to change with a record of why, or leadership needs a current view instead of last quarter's export.

- One risk register file per business unit, no single source of truth
- Version conflicts the moment more than one risk owner edits it
- No record of when a rating changed, who changed it, or why
- Risk register disconnected from the controls and actions meant to treat it

## The fields and structure a risk register actually needs.

- Define one field set for every risk: description, category, owner, likelihood, impact, existing controls, treatment plan, status, and next review date
- Agree a single consistent scoring scale before the first risk is logged, not after inconsistent ratings pile up
- Assign a named individual as owner for every risk — never a department
- Link each risk to the controls already in place and to any treatment action still open
- Set a review cadence per risk and enforce it structurally, not with a reminder email
- Give leadership a live rollup they can check any time, not a document someone compiles before the meeting

## How it works

- A central risk register with a consistent field set and categorisation across the whole organisation
- Configurable likelihood/impact scoring and risk appetite thresholds, applied the same way everywhere
- Every risk linked to its controls, its treatment plan, and any related audit finding
- Automatic escalation when a risk breaches its appetite threshold, instead of waiting for the next review
- A live board dashboard instead of a spreadsheet export

## On the platform

**The register, without the version conflicts** — XGRC® ERM holds one risk register with a full audit trail — every rating change, every treatment update, every review is recorded against who made it and when. Risk owners work in the same live register instead of merging spreadsheet versions, and leadership sees current status without asking anyone to compile it.

## The same fields you would put in a spreadsheet. None of the version conflicts.

| Manual approach | With XGRC® |
| --- | --- |
| One spreadsheet file, emailed around for edits | One live register, no file versions to reconcile |
| No record of who changed a rating or when | A full audit trail on every change |
| Risks tracked with no link to controls or actions | Every risk linked to its controls and treatment actions |
| A rollup someone compiles manually before the board meeting | A board dashboard that is already current |

## One register, however many business units you have.

- Risk identification and categorisation
- Consistent likelihood/impact scoring
- Treatment planning and ownership
- Monitoring, review and board reporting

## Frequently asked questions

### Is there a free risk register template I can just download?

This checklist sets out exactly which fields a working risk register needs — description, category, owner, likelihood, impact, controls, treatment and review date — so you can build one in a spreadsheet if that is genuinely all you need. Most organisations that reach for a template are already past the point where a spreadsheet holds up, which is the gap XGRC® ERM is built for.

### What is wrong with keeping a risk register in Excel?

Nothing, for one person, for a while. It breaks down once a second risk owner needs to edit it at the same time, a rating changes with no record of why, or leadership needs a current view rather than an export from three weeks ago.

### What fields does a proper risk register need?

At minimum: a description, category, named owner, likelihood and impact score, existing controls, treatment plan and status, and a scheduled review date. Every risk should also link to the controls and actions meant to treat it — a register without that link cannot show whether treatment is actually working.

### How is this different from the ISO 31000 checklist?

The ISO 31000 checklist covers the risk management process end to end — context, assessment, treatment, review. This one is narrower and more practical: the specific fields and structure a risk register itself needs to capture, whatever process sits around it.

## Related solution

- [Enterprise Risk Management](https://xgrcsoftware.com/erm)

---

Source: https://xgrcsoftware.com/use-cases/risk-register-template
