Risk Register
A risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
A risk register is the system of record for risk management. Each entry typically describes the risk, its likelihood and potential impact, the resulting risk rating, the owner responsible for it, and the treatment plan — whether to mitigate, transfer, accept, or avoid.
Maintaining a risk register is a requirement or expectation across most compliance frameworks, including ISO 27001 and the NIST AI RMF. It provides the evidence trail showing that risks are identified, evaluated consistently, and actively managed.
A living risk register feeds directly into control selection and prioritization: the highest-rated risks justify the controls and remediation work that follow. Linking risks to controls and evidence keeps the register connected to day-to-day operations rather than becoming a static document.
Related terms
- GRCGRC stands for Governance, Risk, and Compliance — an integrated approach to aligning an organization's strategy, risk management, and adherence to regulations and standards.
- ISO 27001ISO/IEC 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, operating, and continually improving information security.
- NIST AI RMFThe NIST AI Risk Management Framework is a voluntary US framework that helps organizations identify, assess, and manage risks associated with AI systems.
- Vendor Risk ManagementVendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.