Risk Register
The risk register is where residual risk lives in the open: identified, owned, and treated, instead of scattered across review comments and hallway conversations. Approval reads it directly: an untriaged risk blocks the gate, and a deliberately treated one does not.
Where Risks Come From
Risks land on the register from the surfaces that discover them: the security analysis, the design review, and exception workflows. Each carries a title, a severity, and a status. You can also record risks directly; anything a human knows about the design belongs here, whether or not a machine found it.
Treat, Do Not Hoard
An open risk is an unanswered question, and unanswered questions block approval. The treatments are the classic four:
| Treatment | Meaning |
|---|---|
| Mitigating | Work is underway to reduce it |
| Accepted | The organization consciously carries it |
| Transferred | Someone else carries it (contract, insurance, provider) |
| Avoided / Closed | The risky element was removed, or the risk is resolved |
Treating a risk is a decision, so it is recorded as one: who, when, and what treatment. That record is what an assessor actually wants to see: not a clean register, but an honest one with every entry deliberately dispositioned.
Severity Is for Sorting, Treatment Is for Gating
High-severity risks deserve attention first, but the approval gate does not care about severity; it cares that nothing is still open. A low-severity open risk blocks; a high-severity accepted one does not.
Downstream
The business case lists the top open risks in its funding recommendation, and the approval evidence carries the register's state at sign-off, so "what did we knowingly accept?" stays answerable later.