Risk management
A risk register is useful only when it reflects the organisation’s actual circumstances and informs decision making. Risk management should therefore be an ongoing process rather than a document reviewed solely as a governance formality.
Why it matters
Every organisation operates with risk. Effective governance does not mean eliminating all risk. It means understanding significant risks, deciding how they should be managed and ensuring the organisation can respond when circumstances change.
A current and actively used risk register can help the board maintain oversight and focus attention where it is most needed.
What effective practice looks like
Risks are clearly identified and described in terms relevant to the organisation.
The risk register is reviewed regularly and when significant circumstances change.
Appropriate responsibility is assigned for monitoring and managing individual risks.
Risk ratings and mitigation measures are updated as circumstances evolve.
New and emerging risks can be added outside the normal review cycle.
Risk considerations form part of strategic and financial decision making.
Common weaknesses
The risk register is updated infrequently and no longer reflects current circumstances.
Risks are described too broadly to support meaningful action.
Responsibility for managing individual risks is unclear.
Mitigation measures are recorded but not followed up.
Risk management is treated separately from strategic and financial planning.
Questions your board should be asking
When was our risk register last reviewed?
Do the risks identified still reflect our organisation’s circumstances?
Is responsibility for managing each significant risk clear?
Have new risks emerged since our last review?
How does risk inform our strategic and financial decisions?
A good risk register is a working governance tool. Its value comes from the conversations, decisions and actions it supports rather than simply from its existence.