How to Build a Risk Register Auditors and Boards Actually Respect
A useful risk register is current, owned, action-focused and connected to board decisions. Here is how to build one that holds up to scrutiny.
Most organisations have a risk register. Very few have one that anyone actually uses.
The familiar scenario: a spreadsheet was created before the last audit or ahead of a board meeting, scored in a heat map, filed away and opened again twelve months later with minimal changes. Auditors see it, note it exists, and move on. The board receives it as an appendix. No one is sure who owns it.
A risk register built this way satisfies the form of governance without the substance. For PE-backed and growth-stage businesses — where boards and investors are actively engaged and auditors are often asked to assess the control environment — this is a credibility problem as much as a governance one.
This article explains what separates a register auditors and boards actually respect from one that simply exists.
Why Most Risk Registers Fail
The root cause is usually one of three things.
It was built for an audience, not for management. The register was created to show auditors or investors that the organisation takes risk seriously, rather than to actually support decision-making. Once the audience is satisfied, the register becomes dormant.
Ownership is nominal. The register may list a risk owner against each item, but if that person did not agree to it, does not review it regularly and has no mandate to act on it, ownership is fiction.
It is disconnected from how the business actually operates. If the risks on the register do not reflect what keeps the leadership team up at night, the register is not tracking the business — it is tracking an idealised version of it.
The Four Characteristics of a Respected Risk Register
1. It is current.
A register that was last updated eight months ago is not a risk register. It is a historical document. Useful risk registers are reviewed on a regular cycle — typically quarterly at operating level, with a formal annual review — and updated when significant events occur. New risks are added. Closed risks are removed or archived. Risk ratings change when circumstances change.
If your register looks the same as it did a year ago, that is a finding waiting to happen.
2. Every risk has a genuine owner.
Not a department. Not "management." A named individual who has accepted responsibility for monitoring that risk, implementing mitigating actions and escalating when the risk profile changes.
Genuine ownership means the owner was consulted before being named, understands what the risk entails, and has their name attached to the action log. When auditors or board members ask who owns a particular risk, the answer should be immediate and specific.
3. It is action-focused.
A risk rating on its own is information. What matters is what you are doing about it. Each entry should include the control or mitigating action currently in place, a description of the residual risk after that control, and — where the residual risk remains above appetite — a named action with a deadline and a responsible owner.
A register without actions is a list of things you are worried about. A register with actions is a management tool.
4. It is connected to board and investor decisions.
The register should influence what the board discusses, where resource is allocated and what gets prioritised in the business plan. If the board has not received, reviewed and challenged the risk register in the last quarter, the connection is broken.
Auditors and investors look for evidence that the board is actively engaged with risk — not that a document exists, but that it shapes decisions. Board minutes that reference the risk register, papers that tie investment proposals to the risk appetite statement, and directors who can speak fluently to the top risks are all signals that governance is real.
What a Good Entry Looks Like
A common mistake is treating each row in the register as a single line. A useful entry needs more structure than that.
For each risk, capture:
- Risk description: A clear, specific description of what could go wrong and why. Avoid vague labels like "regulatory risk" or "operational risk." Be specific about the scenario.
- Category: Financial, operational, strategic, regulatory, reputational, etc.
- Likelihood and impact scores: With a brief rationale, not just a number.
- Inherent risk rating: Before controls are applied.
- Controls in place: Specific controls, not general statements. Name the control, how often it operates and who performs it.
- Residual risk rating: After controls are applied.
- Risk owner: Named individual.
- Actions required: Where residual risk exceeds appetite — specific, time-bound, owned.
- Last reviewed date: By the named owner.
- Trend: Is this risk increasing, stable or decreasing?
This level of detail takes more effort to build and maintain. It also makes the register genuinely useful.
Connecting the Register to the Audit
Auditors use the risk register in two ways. First, they assess whether the entity-level risk management process is adequate — which affects their overall view of the control environment. Second, they use the risks identified to inform their audit approach, particularly around areas of significant judgement or where management has identified elevated risk.
A register that is current, specific and well-owned supports both. It tells auditors that management understands its own risks and has a functioning process for managing them. A register that is generic, stale or undifferentiated does the opposite.
Specific things auditors look for:
- Evidence of board review and challenge (typically in board minutes)
- Named owners who can be interviewed
- Changes to the register over time, showing it is actively maintained
- Linkage between the register and the internal audit plan or external audit risk assessment
- Actions that have been completed, evidencing the register drives outcomes
Getting Started
If your register needs rebuilding, resist the temptation to start with a template. Start with a conversation — with the leadership team, with functional heads, with the board.
Ask: what are the five things most likely to stop this business achieving its plan in the next 12 months? What happened last year that we were not expecting? Where are we most reliant on a single person, system or customer?
The answers to those questions are your risks. Document them honestly, assign real owners and build the actions from there. Then review it — together, regularly, with the board in the room.
That is a risk register auditors and boards actually respect.
