Risk Management
Building a Risk Register that Passes Cyber Assurance
Published 13 May 2026
The minimum fields
- Risk ID
- Description (what could go wrong, why it matters)
- Asset / process affected
- Threat source
- Inherent likelihood (1–5) and impact (1–5)
- Current controls in place
- Residual likelihood and impact
- Risk owner (named person)
- Treatment decision (accept / reduce / transfer / avoid)
- Action(s), owner, due date
- Date raised, date last reviewed, next review date
Scoring that auditors accept
Use a 5×5 matrix with documented definitions for each likelihood and impact level. The scoring scale itself doesn't matter – the consistency does. If two people score the same risk, they should land within one band of each other.
Risks every UK SME register should include
- Phishing leading to credential compromise
- Ransomware affecting endpoints or cloud storage
- Loss or theft of mobile device
- Unauthorised access via shared/orphaned account
- Supplier breach exposing customer data
- Misconfigured cloud storage / shared link leakage
- Insider data exfiltration (joiner/leaver process gap)
- Loss of key person / single point of knowledge
- Backup failure or untested restore
- Regulatory breach (UK GDPR, sector-specific)
Treatments that pass
For every "reduce" treatment, link to a control or project. "We have MFA enabled" beats "we plan to enable MFA". For "accept" treatments, the named owner must be senior enough to accept the risk.
Review cadence
Quarterly review at minimum, with full annual reassessment. Auditors will check the dates – a register that hasn't been touched in 8 months is a finding.
Where it fits
The risk register is your core evidence for the Risk Assessment and Management theme. See all 14 themes.
