An enterprise risk register is the single list of the risks that could stop an organization achieving its objectives, with an owner, a rating and a decision for each one. It is the document a board reviews, a risk committee works from and internal audit plans against, and it is usually the first thing a new non-executive director asks to see. Yet many registers are either a long spreadsheet nobody reads or a short list of vague headings like “cyber” and “people” that cannot be acted on.

This guide explains what an enterprise risk register should contain, how it relates to ISO 31000 and COSO ERM, and what a good one looks like, with a worked example you can compare with your own.
What an Enterprise Risk Register Is (and Is Not)
It records the risks to the organization as a whole: strategic, financial, operational, legal and compliance, reputational, and health and safety. It sits above the operational registers kept by individual functions, such as the information security risk register or the business continuity register, and pulls the most significant risks from them into one view.
It is not a list of every risk in the business. A useful enterprise register usually holds between 15 and 40 risks, each written at the level a board can own and act on. Detail stays in the operational registers underneath.
| Enterprise risk register | Operational risk register | |
|---|---|---|
| Audience | Board, executive team, risk committee | Function heads and process owners |
| Risk level | Threats to objectives and strategy | Threats to a process, system or site |
| Typical size | 15 to 40 risks | Can run to hundreds |
| Owners | Executives | Managers and specialists |
| Review | Quarterly at executive level, at least yearly by the board | Monthly or as things change |
What ISO 31000 and COSO Say About the Enterprise Risk Register
ISO 31000:2018 is a set of guidelines, not a certifiable standard, and it does not prescribe a register by name. What it does describe is a process: establish the scope, context and criteria; assess risks through identification, analysis and evaluation; treat them; monitor and review; and record and report the process and its outcomes (clause 6.7). An enterprise risk register is the most common way organizations meet that recording and reporting expectation. Our ISO 31000 risk management guide covers the full process.
COSO’s 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, organizes 20 principles into five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. The register sits mainly in the performance component, where risks are identified, assessed, prioritized and responded to, and it feeds the reporting component. If you use COSO, our summary of the COSO ERM principles shows where each one lands.
The Columns Every Enterprise Risk Register Needs
| Column | What goes in it |
|---|---|
| Reference | A stable ID such as R-07 that never changes, so minutes and reports keep pointing at the same risk |
| Risk | A scenario: the event or change, the weakness that exposes you, and the effect on objectives |
| Category | Strategic, financial, operational, legal and compliance, reputational, or health and safety |
| Objective affected | The strategic objective, business unit or project the risk threatens |
| Risk owner | An executive, by role, with the authority to act |
| Existing controls | What is already in place, stated plainly |
| Likelihood, impact, level | Ratings against your agreed criteria, and the resulting level (for example likelihood times impact on 1 to 5 scales) |
| Rationale | One sentence explaining the rating, so it can be challenged |
| Decision | Modify, avoid, share or retain |
| Actions, owner, due date | What will be done, by whom and by when |
| Target level | Where the risk should sit once the actions are complete |
| Acceptance | Who accepted the residual risk, and when |
The two columns most often missing are the rationale and the acceptance. Without a rationale, ratings cannot be challenged or compared year to year. Without an acceptance, nobody has formally taken ownership of the risk that remains. Our article on inherent vs residual risk explains why the distinction matters.
Enterprise Risk Register Example
Aldgate Engineering Group (a fictional company) makes fabricated steel components for three divisions and is midway through an ERP replacement and an acquisition. Its appetite line is level 9 on a 1 to 25 scale: anything above it needs a decision. An extract from its enterprise risk register:
| Ref | Risk | Category | Owner | L | I | Level | Decision and action |
|---|---|---|---|---|---|---|---|
| R-01 | Two customers provide 41% of revenue; losing one would miss the growth target | Strategic, financial | Commercial Director | 4 | 4 | 16 | Modify: diversification targets and multi-year agreements |
| R-02 | Steel costs rise faster than prices; contracts have no indexation clause | Financial | Chief Operating Officer | 4 | 4 | 16 | Modify: indexation in new contracts, partial hedging |
| R-03 | ERP replacement runs over budget and late | Operational, financial | Project Director | 4 | 3 | 12 | Modify: independent assurance review, stage-gated funding |
| R-04 | Acquisition fails to deliver planned synergies | Strategic | Chief Executive | 3 | 4 | 12 | No decision yet |
| R-05 | Loss of specialist welding skills held by a small team | Operational | HR Director | 3 | 3 | 9 | Retain, within appetite |
| R-06 | Workplace injury in the fabrication shop | Health and safety | Health and Safety Lead | 2 | 4 | 8 | Modify: machine guarding upgrade |
| R-07 | New carbon reporting rules raise costs | Legal and compliance | Head of Compliance | 2 | 3 | 6 | Within appetite; monitor |
Read as a board would, this register tells a clear story: three of the four highest risks bear directly on the operating margin, and one of them, the acquisition, has no treatment decision at all. That gap is the first thing a risk committee should close. Health and safety sits within appetite but is still being treated, which is a reasonable choice for a risk where the impact falls on people.
Common Mistakes in an Enterprise Risk Register
- Headings instead of risks. “Cyber” is a category, not a risk. “A ransomware attack stops the legacy ERP, which is out of vendor support, for more than a week” is a risk someone can own and treat.
- No agreed criteria. If “high” means different things to different executives, the ratings cannot be compared. Define the scales and the appetite line before anything is rated. Our guide to risk appetite covers how to set the line.
- Owners who cannot act. A risk owned by “the business” or by a committee is owned by nobody.
- Actions with no dates. An action without a due date is an intention.
- A register that never changes. If the same risks sit at the same levels for three years, the register is not being used to manage anything.
- Unrated risks. A risk without a likelihood and impact cannot appear on the heat map or in the priority order, so it tends to be forgotten.
How to Report the Enterprise Risk Register to the Board
Boards do not need the whole spreadsheet. A one-page pack works better: a heat map of current risk levels against the appetite line, a second heat map showing where risks will sit once the planned actions are done, the risks above appetite with their owners and dates, and a short list of what changed since the last meeting. The register itself stays available for anyone who wants the detail.
Review the register quarterly at executive level and at least once a year with the board, and whenever there is a major change such as an acquisition, a new market or a significant incident.
Build Your Enterprise Risk Register
You can build one in a spreadsheet, but the structure above is easy to get wrong without a method. Our free enterprise risk assessment tool walks you through criteria and appetite, your objectives and units, 36 strategic, financial, operational, legal and reputational risk scenarios, ratings and treatment, and gives you a heat map and the findings a reviewer would raise. The optional report adds the full register as a live Excel workbook and a statement written for the board.
Frequently Asked Questions
Is an enterprise risk register required by ISO 31000?
Not by name. ISO 31000 is a set of guidelines and cannot be certified against. It expects the risk management process and its outcomes to be recorded and reported, and a register is the usual way to do that.
Who owns the register?
The register as a whole is usually maintained by a risk manager or chief risk officer and owned by the executive team. Each individual risk has its own executive owner.
How does it differ from a cybersecurity risk register?
A cybersecurity register covers information security risks in detail. The enterprise register covers every kind of risk to the organization’s objectives and typically carries only the most significant cyber risks, summarized. Our cybersecurity risk register guide covers the detailed version.
How often should the register be updated?
Continuously in practice, with a formal review at least quarterly by the executive team and at least once a year by the board, plus an update after any major change or incident.
For the risk management policy, framework, register and reporting templates around this work, see the ISO 31000 Risk Management Toolkit.