Strategy and Direction

Risk management: building the risk register

What risk management is and how to build a risk register: where to look for risks, how to assess them without false precision, and the four possible responses.

Redazione Prodability · October 3, 2026 · 17 min read

Both, and the difference lies between those who had written them down somewhere and those who discover them on Monday morning.

Risk management is the set of coordinated activities through which an organization directs and controls itself with regard to risk, where risk is the effect of uncertainty on objectives [1].

It concerns a professional with two team members, a fifteen-person family business and a hundred-person organization: the number of rows changes, not the way they are written.

Almost 90% of Italian companies say they are aware they could suffer a cyberattack, and the Bank of Italy observes that this awareness is not always matched by an adequate financial commitment [5].

A risk register is not there to predict what will happen: it is there to make visible what today depends on a single person, a single supplier or a single deadline, and to decide in advance who does what when it happens.

What follows: the scope of the subject, the five areas where risks are concentrated, how to assess them without false precision, the four possible responses and what keeps the register alive.

Telling a risk from a problem: the scope of risk management

A customer who hasn't paid for ninety days and a customer who might not pay in ninety days: do they end up on the same sheet?

No, and keeping them separate is the first decision of method.

The first is a problem: it has happened, it has a date, and you work on its causes.

The second is a risk, that is, the effect of uncertainty on objectives, where the effect is a deviation from what is expected [1]: they are two different sheets, and the boundary between them comes back later among the mistakes.

An unexpected event is also a risk, under a different name because it had not been written down: the work of reducing how often they happen is in the article on how to reduce unexpected events.

The reference standard is ISO 31000:2018, Risk management — Guidelines, second edition of February 2018, reconfirmed in 2023 [1].

They are guidelines, not requirements: the guidance can be adapted to any organization and is not industry-specific [1].

It follows that there is no such thing as an ISO 31000 company certification, and that whoever offers one is selling something else.

Business risk assessment is part of risk management, not a synonym for it: it includes identification, analysis and evaluation, and stops before the choice of response [2].

The terms of this vocabulary come from ISO Guide 73:2009, which has been withdrawn: the current text that has taken over its function, ISO 31073:2022, does not make them freely available for consultation [2].

The risk register is the medium on which that part leaves a trace, that is, the record of information about the risks identified [2].

Two subjects remain outside these pages.

The assessment of risks to workers' health and safety follows the applicable occupational safety legislation — in Italy, Legislative Decree 81/2008 [6] — produces its own mandatory risk assessment document and has its own obligations: an internal register does not replace it.

Financial risk in the strict sense — interest rate, exchange rate, credit — also remains outside, as it is measured with dedicated tools.

Where to look for risks: the five areas to check in a company

The register doesn't predict the future: it makes visible what today depends on a single person, a single supplier or a single deadline.

Do twenty minutes of meeting with the question "what risks are we running?" and a tour of the five areas where damage is concentrated produce the same list?

The first produces categories, the second produces rows.

Identification, in the ISO definition, is the process of finding, recognizing and describing risks [2].

Looking for risks is not looking for problems: the latter looks at what is already happening without anyone having written it down, and it is the job of problem finding.

The five areas below are the ones to look at first.

People. The question is which activity would stop if a single person were away for a month.

In Italy, 80.9% of companies with at least three employees are controlled by a single person or a family, and management is in most cases in the hands of the business owner or a family member [3].

It is the ordinary condition, not the exception.

When the person everything converges on is the business owner, the row has a proper name: business succession, which 7.9% of Italian companies controlled by an individual or a family expected to face in the 2023-2025 period [3].

Suppliers and customers. About 80% of Italian production units take part in a single supply chain, and micro-businesses report being able to influence prices with suppliers in about 11% of cases [3].

The questions are how many weeks you would be at a standstill if your main supplier closed, and how much revenue depends on your largest customer.

Deadlines. Contracts that renew automatically, certifications, permits, insurance policies: every date remembered from memory is a row.

Cash. In Italy, 43.1% of companies with at least three employees that turn to external financing do so for liquidity needs [3].

The question is how many days the company can hold out if the largest payment of the quarter arrives sixty days late.

Equipment and data. In 2024, 15.8% of Italian companies with at least ten employees reported having suffered at least one IT security problem in the previous year [4].

Alongside attacks, the ordinary things need to be counted: the spare part that takes six weeks to arrive, the management software for which only one person has the credentials.

In a thirty-person family business in an engineering district, the same person may program the machines and handle the main customer: two areas intersect on a single name.

The row is born here, with three fields: the area, the event written as a sentence — who or what, what happens, with what consequence — and the date.

Diagram of the five areas in which to look for risks in a company: people, suppliers and customers, deadlines, cash, equipment and data, with the question to ask for each

How business risk assessment works without false precision

Do a risk rated 7.4 out of 10 and a risk rated "high" say different things?

They say the same thing, but the first says it with a figure the procedure cannot support.

The standard is explicit: likelihood is the chance of something happening, whether determined objectively or subjectively, qualitatively or quantitatively [1].

A rough scale is therefore allowed, on one condition: that the criterion used to assign the levels is stated.

Risk criteria, in the ISO definition, are the terms of reference against which the significance of a risk is evaluated [2].

In practice, at the top of the sheet you write what the words used in the columns mean.

  • likelihood — rare: it has not happened in the last five years; possible: once every two or three years; recurring: at least once a year;
  • impact — low: recovered within the week with the people on hand; medium: stops an order or costs more than a stated threshold; high: a delivery to a customer is missed or a contract is called into question.

The thresholds are chosen based on the size of the company, written down once and not renegotiated at every meeting.

The product of the two levels is for ranking the rows, not measuring them: two items in the same cell do not, for that reason, have the same expected value.

The robustness test is simple: two people who know the company, with the same sheet and the same criterion, must place the same row in the same cell.

When this doesn't happen, the number is an opinion dressed up as a measurement, and the criterion must be rewritten before adding more rows.

When, on the other hand, two rows legitimately end up in the same position, the criterion that separates them is how fast the event unfolds: you work first on the one that leaves less time to react.

The register thus gains two columns, likelihood and impact, plus a header row with the definitions actually used.

The four responses to a risk: avoid, reduce, transfer, accept

Faced with a row that has already been assessed, how many moves really exist?

The ISO risk management vocabulary lists seven — avoiding the risk, taking or increasing it to pursue an opportunity, removing its source, changing its likelihood, changing its consequences, sharing it with other parties, retaining it by informed decision — which in a company fall into four families [2].

Avoid. This is the informed decision not to start an activity, or to withdraw from it, so as not to be exposed to that risk [2].

Turning down an order that requires a process the company doesn't control is an avoidance, and should be written down as such: otherwise it remains an opportunity lost for no reason.

Reduce. This is where the moves that remove the source, lower the likelihood or contain the consequences belong [2].

A second person trained to program the machines, the critical spare part in stock, the written procedure for the activity only one person knows how to do: they cost time before they cost money.

Transfer. Transfer is a form of sharing risk with other parties, carried out through insurance or other forms of contract [2].

An insurance policy shifts the financial consequence, not the operational one: the customer still waits.

Accept knowingly. Acceptance is the informed decision to take a particular risk, and accepted risks remain subject to monitoring and review [2].

Accepting means writing on the row who decided, when, and which signal you watch for to notice that the situation has changed.

What remains after treatment is called residual risk [2], and it is worth noting down: it is the part the company has chosen to keep.

The four families are not mutually exclusive: the same row can be partly reduced and accepted for the rest, as long as each decision has a date.

Each row thus gains three columns: the chosen response, the action with a deadline and the name of the risk owner, that is, the person with the accountability and authority to manage it [2].

A row without a name next to it is not a response, it is an intention.

Diagram of the four responses to a risk: avoid, reduce, transfer, accept knowingly, with residual risk as the common outcome

Keeping the risk register alive: rhythm, owner, review

Is a register filled in well once worth the same as one reread every quarter?

The numbers say the first case is the common one.

Between 2022 and 2024, the share of Italian companies with at least ten employees that have documents on IT security measures and procedures fell from 48.3% to 35.9%, close to the 2019 figure [4].

In the same year, IT risk assessment practices stopped at 36.9% of those companies [4].

The document is written in a moment of attention and ages during the months in which whoever wrote it no longer opens it.

Three elements keep it alive.

A stated rhythm. Thirty minutes per quarter, inside a meeting that already exists, with the sheet on screen and a single question per row: has anything changed?

A register owner. A person who calls the review, updates the rows and closes them — a role distinct from the owners of the individual rows.

Events that trigger an off-schedule review. A customer who exceeds a revenue threshold, new equipment, the departure of a person who handled an activity alone, a supplier who changes payment terms.

In the review, you close the rows that are no longer relevant, noting the date and reason, move those whose likelihood has changed, and add those that emerged during the quarter.

Closing matters as much as opening: a register that grows without closing rows becomes unreadable within a year, and an unreadable sheet gets abandoned.

The final format comes down to seven columns — area, event, likelihood, impact, response, action with deadline, owner — plus the date of the last review at the top of the sheet.

If you already keep a dashboard of indicators, you can tie the review to the same appointment as management control, instead of setting up a new meeting.

The mistakes that turn the risk register into a dead document

A sheet with twelve generic rows and one with five rows that name people and dates: which one leads to a decision on Monday?

The four mistakes below can be recognized by reading the rows, not by debating the method.

Writing categories instead of risks. "Market crisis," "problems with suppliers," "cyber" are chapter titles: a row like that can be neither assessed nor assigned.

The description of a risk, in the vocabulary of the field, contains four elements — source, event, causes and consequences [2].

The practice is to rewrite the row as a complete sentence: who or what, what happens, with what consequence for the company.

Keeping what may happen and what has already happened on the same sheet. The two lists run at different rhythms, and mixing them means losing both.

What has happened is handled through nonconformity management when it concerns products or services that fail to meet requirements, and through root cause analysis when it is worth understanding why it happened.

The risk register looks ahead and stays short; the other looks back and grows.

Assessing with numbers finer than the criterion. Ten-level scales and decimals give the impression of a measurement and cost meetings spent arguing over whether a row is worth 6 or 7.

The practice is to go back to three levels with the definitions written at the top of the sheet.

Accepting by omission. Rows without a chosen response are acceptances that someone should have decided on, and they come to light at the worst moment.

The practice is the rule that closes the review: every row leaves with one of the four responses and a name next to it, or it is closed.

The final check is about stability: if, when the person filling in the sheet changes, the top five rows stay the same, the register describes the company; if they change, it describes whoever is writing it.

Limitations and conditions of applicability

The full text of ISO 31000:2018 is paid: the definitions cited come from the informative sections published on the official ISO platform — scope, introduction and terms — and not from the normative clauses [1].

The definitions of treatment, criteria and register come from ISO Guide 73:2009, the ISO risk management vocabulary: it is a withdrawn standard, whose function has been taken over by ISO 31073:2022, and it is cited only because the current text does not make those terms freely available for consultation [2].

The ISTAT and Bank of Italy data describe populations of Italian companies [3] [4] [5]: they show how widespread certain dependencies are, they do not demonstrate causal links or how risks are distributed within a single company.

Three-level scales rank the rows, they don't measure them: the matrix is not an estimation tool.

The engineering district scenario was constructed for this article and does not represent a documented case.

The assessment of risks to workers' health and safety follows the applicable occupational safety legislation — in Italy, Legislative Decree 81/2008 [6] — and produces its own risk assessment document, with its own obligations: the register described here neither replaces nor supplements it.

Financial risk in the strict sense — interest rate, exchange rate, credit — requires skills and measures different from organizational ones.

A rare event with serious consequences for people's safety or for legal obligations falls outside the logic of relative weighting and is dealt with immediately.

FAQ

What is risk management in simple terms?

It is the set of coordinated activities through which an organization directs and controls itself with regard to risk, where risk is the effect of uncertainty on objectives [1].

In practice it means writing down what can go wrong, how much it weighs and who does what when it happens.

What is the difference between risk management and business risk assessment?

Risk assessment is part of risk management: it includes the identification, analysis and evaluation of risks [2].

Risk management also includes choosing the response, implementing it, monitoring and recording.

Is ISO 31000 mandatory, and is certification required?

ISO 31000:2018 is a guidelines document, adaptable to any organization and not industry-specific [1].

It contains no certifiable requirements, so there is no such thing as an ISO 31000 company certification.

What does a risk register contain?

In the ISO definition, it is the record of information about the risks identified [2].

In the practice of a small company, it comes down to seven columns: area, event, likelihood, impact, chosen response, action with deadline, row owner.

Does the risk register replace the occupational risk assessment document?

No: the occupational risk assessment document concerns workers' health and safety, follows the applicable legislation — in Italy, Legislative Decree 81/2008 [6] — and has its own obligations.

The register described here is an internal organizational tool and lives alongside that document, not in its place.

Key takeaways

The starting point is a distinction: what has already happened goes on one sheet, what may happen goes on another.

Rows are sought in five areas — people, suppliers and customers, deadlines, cash, equipment and data — with a concrete question for each.

Every row starts as a complete sentence: who or what, what happens, with what consequence for the company.

The weight is assigned on three levels of likelihood and three of impact, with the definitions written at the top of the sheet and the test of two people placing the same row in the same cell.

Faced with an assessed row, there are four responses: avoid, reduce, transfer, accept knowingly — and they can coexist on the same row, as long as each decision has a date.

Every row leaves the meeting with a response, an action with a deadline and the name of whoever manages it: without a name it is an intention.

The sheet is reread for thirty minutes each quarter inside a meeting that already exists, and off schedule when something big changes: a customer above the threshold, new equipment, the departure of a key person.

In the review, outdated rows are closed, changed ones are moved and those that emerged during the quarter are added: closing matters as much as opening.

Conclusion

Risk management is not predicting what will happen: it is the work of making visible what today depends on a single person, a single supplier or a single deadline, and of deciding in advance who does what when it happens.

The register is the place where that visibility takes a readable form: five areas in which to look, two columns to assess with a stated criterion, four possible responses, a name and a date next to each.

The definitions that support the method are few and public — risk, criteria, treatment, residual risk — and ISO 31000 lines them up without requiring any certification [1] [2].

If you're looking for the framework in which this work sits, you'll find it in strategic planning; if instead you're starting from what is already going wrong without anyone having written it down, begin with problem finding.

After three or four quarterly reviews, the tone of the meetings changes.

Surprises don't end, but they stop being complete surprises: when the person who handled an activity alone leaves, there is already the name of someone who has been working alongside them for months, and when the main supplier changes terms there is already a second quote on file.

It is the difference between a company that reacts to whatever happens and one that has decided beforehand, with the sheet in front of it, what was worth avoiding, reducing, transferring or keeping.

Sources and references

[1] ISO, "ISO 31000:2018 — Risk management — Guidelines", International Organization for Standardization, technical committee ISO/TC 262, second edition, February 2018, 16 pages (reviewed and confirmed in 2023). Informative sections — Introduction, Scope, Terms and definitions — consulted on the official ISO Online Browsing Platform. Available at: https://www.iso.org/standard/65694.html — informative text: https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en

[2] ISO, "ISO Guide 73:2009 — Risk management — Vocabulary", International Organization for Standardization, ISO Technical Management Board Working Group on risk management, first edition, 2009 (withdrawn standard; vocabulary function taken over by ISO 31073:2022). Terms consulted on the official ISO Online Browsing Platform. Available at: https://www.iso.org/obp/ui/en/#iso:std:iso:guide:73:ed-1:v1:en

[3] ISTAT, "Censimento permanente delle imprese 2023: primi risultati", press release and report, November 14, 2023 (reference year 2022; about 280,000 responding companies, representative of 1,021,618 companies with at least 3 employees). Available at: https://www.istat.it/comunicato-stampa/censimento-permanente-delle-imprese-2023-primi-risultati/ — PDF: https://www.istat.it/it/files/2023/11/REPORTCensimprese.pdf

[4] ISTAT, "Imprese e ICT — Anno 2024", statistical report, January 17, 2025 (survey on ICT use in companies with at least 10 employees). Available at: https://www.istat.it/comunicato-stampa/imprese-e-ict-anno-2024/ — PDF: https://www.istat.it/wp-content/uploads/2025/01/Statreport_ICT2024-1.pdf

[5] Bencivelli, L., Mongardini, M., "La sicurezza cibernetica delle imprese italiane: percezione dei rischi e pratiche di mitigazione", Questioni di Economia e Finanza (Occasional Papers) no. 852, Banca d'Italia, June 2024, DOI 10.32057/0.QEF.2024.0852 (evidence from the 2016 and 2022 editions of the Survey of Industrial and Service Firms). Available at: https://www.bancaditalia.it/pubblicazioni/qef/2024-0852/index.html — PDF: https://www.bancaditalia.it/pubblicazioni/qef/2024-0852/QEF_852_24.pdf

[6] Italy, "Decreto legislativo 9 aprile 2008, n. 81 — Attuazione dell'articolo 1 della legge 3 agosto 2007, n. 123, in materia di tutela della salute e della sicurezza nei luoghi di lavoro", Gazzetta Ufficiale, Serie Generale no. 101 of April 30, 2008, Supplemento Ordinario no. 108. Cited as the regulatory boundary, without attributing any content to it: current text on Normattiva — https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2008-04-09;81 — record of the published act: https://www.gazzettaufficiale.it/eli/id/2008/04/30/008G0104/sg