Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Enterprise Risk Register guide with columns, ratings, and reporting tips.

Enterprise Risk Register: The Definitive 2026 Guide with Example

An enterprise risk register is the single list of the risks that could stop an organization achieving its objectives, with an owner, a rating and a decision for each one. It is the document a board reviews, a risk committee works from and internal audit plans against, and it is usually the first thing a new non-executive director asks to see. Yet many registers are either a long spreadsheet nobody reads or a short list of vague headings like “cyber” and “people” that cannot be acted on.

Enterprise risk register example and guide

This guide explains what an enterprise risk register should contain, how it relates to ISO 31000 and COSO ERM, and what a good one looks like, with a worked example you can compare with your own.

What an Enterprise Risk Register Is (and Is Not)

It records the risks to the organization as a whole: strategic, financial, operational, legal and compliance, reputational, and health and safety. It sits above the operational registers kept by individual functions, such as the information security risk register or the business continuity register, and pulls the most significant risks from them into one view.

It is not a list of every risk in the business. A useful enterprise register usually holds between 15 and 40 risks, each written at the level a board can own and act on. Detail stays in the operational registers underneath.

Enterprise risk registerOperational risk register
AudienceBoard, executive team, risk committeeFunction heads and process owners
Risk levelThreats to objectives and strategyThreats to a process, system or site
Typical size15 to 40 risksCan run to hundreds
OwnersExecutivesManagers and specialists
ReviewQuarterly at executive level, at least yearly by the boardMonthly or as things change

What ISO 31000 and COSO Say About the Enterprise Risk Register

ISO 31000:2018 is a set of guidelines, not a certifiable standard, and it does not prescribe a register by name. What it does describe is a process: establish the scope, context and criteria; assess risks through identification, analysis and evaluation; treat them; monitor and review; and record and report the process and its outcomes (clause 6.7). An enterprise risk register is the most common way organizations meet that recording and reporting expectation. Our ISO 31000 risk management guide covers the full process.

COSO’s 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, organizes 20 principles into five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. The register sits mainly in the performance component, where risks are identified, assessed, prioritized and responded to, and it feeds the reporting component. If you use COSO, our summary of the COSO ERM principles shows where each one lands.

The Columns Every Enterprise Risk Register Needs

ColumnWhat goes in it
ReferenceA stable ID such as R-07 that never changes, so minutes and reports keep pointing at the same risk
RiskA scenario: the event or change, the weakness that exposes you, and the effect on objectives
CategoryStrategic, financial, operational, legal and compliance, reputational, or health and safety
Objective affectedThe strategic objective, business unit or project the risk threatens
Risk ownerAn executive, by role, with the authority to act
Existing controlsWhat is already in place, stated plainly
Likelihood, impact, levelRatings against your agreed criteria, and the resulting level (for example likelihood times impact on 1 to 5 scales)
RationaleOne sentence explaining the rating, so it can be challenged
DecisionModify, avoid, share or retain
Actions, owner, due dateWhat will be done, by whom and by when
Target levelWhere the risk should sit once the actions are complete
AcceptanceWho accepted the residual risk, and when

The two columns most often missing are the rationale and the acceptance. Without a rationale, ratings cannot be challenged or compared year to year. Without an acceptance, nobody has formally taken ownership of the risk that remains. Our article on inherent vs residual risk explains why the distinction matters.

Enterprise Risk Register Example

Aldgate Engineering Group (a fictional company) makes fabricated steel components for three divisions and is midway through an ERP replacement and an acquisition. Its appetite line is level 9 on a 1 to 25 scale: anything above it needs a decision. An extract from its enterprise risk register:

RefRiskCategoryOwnerLILevelDecision and action
R-01Two customers provide 41% of revenue; losing one would miss the growth targetStrategic, financialCommercial Director4416Modify: diversification targets and multi-year agreements
R-02Steel costs rise faster than prices; contracts have no indexation clauseFinancialChief Operating Officer4416Modify: indexation in new contracts, partial hedging
R-03ERP replacement runs over budget and lateOperational, financialProject Director4312Modify: independent assurance review, stage-gated funding
R-04Acquisition fails to deliver planned synergiesStrategicChief Executive3412No decision yet
R-05Loss of specialist welding skills held by a small teamOperationalHR Director339Retain, within appetite
R-06Workplace injury in the fabrication shopHealth and safetyHealth and Safety Lead248Modify: machine guarding upgrade
R-07New carbon reporting rules raise costsLegal and complianceHead of Compliance236Within appetite; monitor

Read as a board would, this register tells a clear story: three of the four highest risks bear directly on the operating margin, and one of them, the acquisition, has no treatment decision at all. That gap is the first thing a risk committee should close. Health and safety sits within appetite but is still being treated, which is a reasonable choice for a risk where the impact falls on people.

Common Mistakes in an Enterprise Risk Register

  • Headings instead of risks. “Cyber” is a category, not a risk. “A ransomware attack stops the legacy ERP, which is out of vendor support, for more than a week” is a risk someone can own and treat.
  • No agreed criteria. If “high” means different things to different executives, the ratings cannot be compared. Define the scales and the appetite line before anything is rated. Our guide to risk appetite covers how to set the line.
  • Owners who cannot act. A risk owned by “the business” or by a committee is owned by nobody.
  • Actions with no dates. An action without a due date is an intention.
  • A register that never changes. If the same risks sit at the same levels for three years, the register is not being used to manage anything.
  • Unrated risks. A risk without a likelihood and impact cannot appear on the heat map or in the priority order, so it tends to be forgotten.

How to Report the Enterprise Risk Register to the Board

Boards do not need the whole spreadsheet. A one-page pack works better: a heat map of current risk levels against the appetite line, a second heat map showing where risks will sit once the planned actions are done, the risks above appetite with their owners and dates, and a short list of what changed since the last meeting. The register itself stays available for anyone who wants the detail.

Review the register quarterly at executive level and at least once a year with the board, and whenever there is a major change such as an acquisition, a new market or a significant incident.

Build Your Enterprise Risk Register

You can build one in a spreadsheet, but the structure above is easy to get wrong without a method. Our free enterprise risk assessment tool walks you through criteria and appetite, your objectives and units, 36 strategic, financial, operational, legal and reputational risk scenarios, ratings and treatment, and gives you a heat map and the findings a reviewer would raise. The optional report adds the full register as a live Excel workbook and a statement written for the board.

Frequently Asked Questions

Is an enterprise risk register required by ISO 31000?

Not by name. ISO 31000 is a set of guidelines and cannot be certified against. It expects the risk management process and its outcomes to be recorded and reported, and a register is the usual way to do that.

Who owns the register?

The register as a whole is usually maintained by a risk manager or chief risk officer and owned by the executive team. Each individual risk has its own executive owner.

How does it differ from a cybersecurity risk register?

A cybersecurity register covers information security risks in detail. The enterprise register covers every kind of risk to the organization’s objectives and typically carries only the most significant cyber risks, summarized. Our cybersecurity risk register guide covers the detailed version.

How often should the register be updated?

Continuously in practice, with a formal review at least quarterly by the executive team and at least once a year by the board, plus an update after any major change or incident.

For the risk management policy, framework, register and reporting templates around this work, see the ISO 31000 Risk Management Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *