Growth Marketing Glossary

Risk Register

risk reg·is·ternoun

The list that keeps risks visible. A risk register records each risk, its odds, its impact, and its owner.

scattered worriesthe register organizestracked risks
Schematic — identified risks logged with owners and responses
Term
Risk register
Is
A log of identified risks
Records
Likelihood, impact, owner, response
Used in
Project and enterprise risk management

Parts of speech & senses

risk register · noun
  1. A risk register is a structured, living log of the risks a project or organization has identified, capturing for each one its likelihood, its impact, the person who owns it, and the planned response. "Every risk in the register has an owner and a next review date."

What a risk register is

A risk register is a structured, living document that lists the risks a project or organization has identified and records key information about each one — typically its description, its likelihood of occurring, its potential impact, the person responsible for managing it, and the planned response if it materializes. It is the central tool of risk management, turning a vague sense of what might go wrong into an explicit, organized record that can be reviewed and acted on. Rather than carrying risks around in people's heads, a risk register writes them down, so they can be ranked, assigned, tracked, and revisited. It is used both at the project level, where it logs the risks to a particular initiative, and at the enterprise level, where it captures the broader risks an organization faces. The register is the single place where the organization's known risks live.

A risk register matters because unmanaged risk is usually unrecorded risk. When risks live only in individuals' minds, they are easy to forget, hard to prioritize, and rarely owned by anyone in particular — so they go unaddressed until they hit. A risk register makes risks visible and accountable: each one has an owner, a likelihood, an impact, and a plan, so it can be watched and managed rather than ignored. It supports prioritization, because rating likelihood and impact shows which risks deserve attention and which can be accepted. And because it is a living document, it keeps risk management continuous rather than a one-time exercise — risks are added as they emerge, updated as they change, and closed when they pass. The register is what makes the difference between managing risk and merely worrying about it.

What a good risk register contains, and what it is not

A useful risk register captures a consistent set of fields for every risk. Each entry describes the risk clearly, rates its likelihood and its impact — often combined into a single score or heat-map rating to show severity at a glance — names an owner accountable for managing it, and records the planned response, whether that is to avoid, reduce, transfer, or accept the risk. Many registers add the current status, any triggers or early-warning signs, and the residual risk expected after the response. The point of this structure is comparability: because every risk is recorded the same way, they can be ranked against one another and the most severe ones prioritized. A register that records risks in inconsistent, freehand notes loses that power, because you cannot compare or prioritize what is described differently each time.

A risk register is not a plan you write once and file away, and treating it as one is the classic failure. Its value comes entirely from being kept current — reviewed regularly, updated as risks change, added to as new ones appear, and used in real decisions. A register that is created to satisfy a process requirement and then never opened is worthless, however thorough it looks. Nor is a risk register the same as risk management itself: the register is the tool that records and organizes risks, but managing them still requires acting on the responses, holding owners accountable, and revisiting the ratings as the situation shifts. The register makes risk management possible and disciplined. It does not replace the work of actually reducing, transferring, or watching the risks it lists.

Using a risk register well

Using a risk register well means keeping it alive and letting it drive action. That starts with identifying risks honestly and recording each with a consistent set of fields — description, likelihood, impact, owner, and response — so they can be compared and ranked. It means genuinely assigning ownership, because a risk without an accountable owner tends to be nobody's job until it happens. It means prioritizing by severity, focusing attention on the high-likelihood, high-impact risks rather than treating every entry as equal, and choosing a deliberate response for each — avoid, reduce, transfer, or accept. And it means reviewing the register on a regular cadence, updating ratings, adding emerging risks, and closing those that have passed, so the document reflects reality rather than the day it was written.

The failures are familiar. Teams build a risk register to tick a box and never look at it again, so it goes stale and useless. They record risks without owners, so nothing gets managed. They rate every risk the same or skip the likelihood-and-impact scoring, losing the ability to prioritize. And they mistake the register for the management, believing that logging a risk deals with it. The discipline is to treat the risk register as a living instrument of accountability — consistent fields, real owners, severity-based prioritization, deliberate responses, and regular review — so it keeps risks visible and drives the actions that actually reduce them. A register kept this way is one of the simplest, most effective tools in project and enterprise risk management. A register left to rot is just paperwork.

Worked example. A project team starts a major software rollout and builds a risk register instead of trusting memory. Each risk — a key vendor slipping, a critical hire leaving, a data-migration failure — gets a description, a likelihood and impact rating, an owner, and a response. The team ranks them by severity and focuses on the few high-likelihood, high-impact risks, assigning each to a named person with a plan. Every fortnight they review the register, update ratings, add new risks, and close ones that have passed. When the vendor does slip, the owner already has a mitigation ready. The register did not remove the risks, but it made them visible, owned, and managed rather than left to chance. (Illustrative; RGM analysis.)
Failure modes to watch. Building a register to tick a box and never reviewing it, so it goes stale; recording risks without accountable owners so nothing gets managed; rating every risk the same or skipping likelihood-and-impact scoring so nothing can be prioritized; and mistaking the register for risk management itself.

Synonyms & antonyms

Synonyms

risk logrisk inventoryrisk repository

Antonyms

unmanaged riskad-hoc risk tracking

Origin & history

Risk register combines risk, the chance of loss, with register, a formal record, naming the structured log of identified risks used in risk management.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What is a risk register?
A structured, living log of the risks a project or organization has identified. For each risk it records a description, its likelihood, its impact, the owner responsible, and the planned response, so risks can be ranked, assigned, tracked, and managed rather than forgotten.
What should a risk register include?
For each risk: a clear description, a likelihood rating, an impact rating, often a combined severity score, a named owner, and a planned response — to avoid, reduce, transfer, or accept it. Many registers also record status, early-warning triggers, and the residual risk after the response.
Why keep a risk register instead of just tracking risks informally?
Because informal risks live in people's heads, where they are forgotten, unranked, and unowned. A register makes each risk visible, rated, and accountable to a specific owner, supports prioritizing the severe ones, and keeps risk management continuous as risks emerge, change, and pass.

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where risk register is a core concern:

Sources

  1. trendsGoogle Trends — "risk register"