Chapter 06 · Governance & regulationGovernance, Ethics & Risk
Risk register
Definition
A risk register is a structured record of identified risks, assessments, controls, owners and actions.
References
This reference provides supporting context for how “Risk register” is defined and used.
Overview
What it means in practice
Risk register should be read as a governance, ethics and risk term. Its meaning depends on the role, authority, control, legal context and decision being assessed.
In practice, users should state the boundary, actor, evidence and decision context. That keeps risk register specific enough for review without turning it into a generic assurance claim.
Why it matters
Risk register matters because governance language determines who is accountable, what is controlled and how risks are escalated. Clear definitions reduce the chance that responsibility is implied but not operational.
Common misconception
A common error is to treat Risk register as proof that governance is effective. The stronger approach is to state the owner, mandate, control, evidence and limits of authority.
Review questions
Who is responsible, and who is affected? What evidence supports the term? What limitation, authority or remedy would change how a reader interprets it?
How it is used
In professional practice, “Risk register” helps policymakers, regulators, legal teams, boards and organisations describe or assess a structured record of identified risks, assessments, controls, owners and actions. It is commonly encountered in legislation, policies, governance systems, contracts, oversight and compliance decisions.
A credible application identifies the applicable jurisdiction, legal or policy text, effective date, scope and responsible actor.