Glossary · ERM
Risk Register
Centralized repository documenting identified risks, their assessments, ownership, controls, and mitigation actions across an organization.
Full definition
A Risk Register serves as the operational database for enterprise risk management, capturing each risk's description, likelihood, impact, current controls, residual exposure, assigned owner, and treatment plans. It enables consistent risk documentation, facilitates reporting to governance bodies, and tracks mitigation progress over time. Modern risk registers integrate with GRC platforms to automate updates, trigger alerts when thresholds are breached, and provide dashboards for executives. For instance, a manufacturing company's risk register might track supplier concentration, equipment failure modes, regulatory changes, and commodity price volatility in a single structured format.
documentationtrackingGRC-platformrisk-identification