Skip to content

Risk Register

The risk register is where residual risk lives in the open: identified, owned, and treated, instead of scattered across review comments and hallway conversations. Approval reads it directly: an untriaged risk blocks the gate, and a deliberately treated one does not.

Where Risks Come From

Risks land on the register from the surfaces that discover them: the security analysis, the design review, and exception workflows. Each carries a title, a severity, and a status. You can also record risks directly; anything a human knows about the design belongs here, whether or not a machine found it.

Treat, Do Not Hoard

An open risk is an unanswered question, and unanswered questions block approval. The treatments are the classic four:

Treatment Meaning
Mitigating Work is underway to reduce it
Accepted The organization consciously carries it
Transferred Someone else carries it (contract, insurance, provider)
Avoided / Closed The risky element was removed, or the risk is resolved

Treating a risk is a decision, so it is recorded as one: who, when, and what treatment. That record is what an assessor actually wants to see: not a clean register, but an honest one with every entry deliberately dispositioned.

Severity Is for Sorting, Treatment Is for Gating

High-severity risks deserve attention first, but the approval gate does not care about severity; it cares that nothing is still open. A low-severity open risk blocks; a high-severity accepted one does not.

Downstream

The business case lists the top open risks in its funding recommendation, and the approval evidence carries the register's state at sign-off, so "what did we knowingly accept?" stays answerable later.