Register template

Risk register template with 5×5 scoring.

The columns, the scoring, the bands and the spreadsheet formulas, with two worked risks from start to residual. Paste it into a sheet and replace the examples with your own.

01

What is a risk register?

A risk register is the list of risks an organisation has identified, each with an owner, a score for likelihood and impact before controls (inherent) and after them (residual), a treatment decision and a review date. It is the working record behind ISO 27001 risk treatment, SOC 2 risk assessment and the security duties in the DPDP Act.

One number per risk records an opinion. Two numbers, inherent and residual, record an argument: what this would cost with nothing in place, and what it costs given the controls you actually operate. The template holds both.

02

How to score a risk on a 5×5 matrix

Score likelihood from 1 (rare) to 5 (almost certain) and impact from 1 (negligible) to 5 (severe), then multiply. The score, from 1 to 25, falls into one of five bands, and the band decides what happens next. These are the same bands the TryTrustable risk register uses.

ScoreBandWhat it should trigger
1–4LowAccept and review annually
5–9ModerateNamed owner, treatment plan, review every six months
10–14HighActive treatment, quarterly review, visible to leadership
15–19SevereEscalation, dated remediation plan, monthly review
20–25CriticalBoard-level, immediate treatment or a documented decision to accept

Likelihood × impact, each 1 to 5. The bands matter less than applying them consistently.

ScoreLikelihoodImpact
1Rare: not expected in the next three yearsNegligible: no data exposed, minutes of disruption
2Unlikely: could happen once in three yearsMinor: internal data, hours of disruption
3Possible: could happen once a yearModerate: limited personal data, a day of disruption, customer complaints
4Likely: expected more than once a yearMajor: significant personal data, regulator notification, contract loss
5Almost certain: expected within monthsSevere: large-scale breach, prolonged outage, material penalty exposure

An example scale. Rewrite the descriptions in your own terms and keep them fixed, so two assessors give the same score.

03

The template

Tab-separated, 21 columns, two worked examples. Paste into cell A1 of a blank sheet. The examples show a risk moving from Critical to Moderate and from Severe to Moderate once treatment is in place.

risk-register.tsv
ID	Risk title	Description (cause, event, consequence)	Category	Asset or process	Owner	Likelihood (1-5)	Impact (1-5)	Inherent score	Inherent band	Existing controls	Treatment	Planned controls and due date	Residual likelihood (1-5)	Residual impact (1-5)	Residual score	Residual band	Within appetite?	Review date	Status	Linked requirements
R-001	Unencrypted vendor backup	Backup vendor stores customer database copies without encryption; a compromise at the vendor exposes customer personal data; breach notification, penalty exposure and customer loss	Vendor	Customer database	[Head of Infrastructure]	4	5	20	Critical	Vendor contract with security clause	Mitigate	Encrypt backups with our keys before transfer [date]; vendor review [date]	2	4	8	Moderate	Yes	[date]	In treatment	ISO 27001 A.8.13, A.8.24; DPDP Rule 6(1)(a)
R-002	Shared admin credentials	Cloud admin account shared by three engineers; misuse or phishing of one person grants full control without attribution; outage or data loss with no audit trail	Access	Cloud production account	[CTO]	4	4	16	Severe	Password manager	Mitigate	Individual accounts with MFA and just-in-time elevation [date]	2	3	6	Moderate	Yes	[date]	In treatment	ISO 27001 A.5.16, A.8.2, A.8.5

Formulas for Google Sheets or Excel, assuming the column order above:

risk-register-formulas.txt
Inherent score (column I, row 2):   =G2*H2
Residual score (column P, row 2):   =N2*O2
Band (column J, from I2; copy the same formula to Q, pointing at P2):
=IF(I2>=20,"Critical",IF(I2>=15,"Severe",IF(I2>=10,"High",IF(I2>=5,"Moderate","Low"))))
Within appetite? (column R), with your appetite threshold in cell X1:
=IF(P2<=$X$1,"Yes","No")
04

How to use this template

  • Write risks as cause, event, consequence. “Ransomware” is a category; “unpatched VPN appliance lets an attacker encrypt file servers, stopping operations for a week” is a risk you can treat.
  • Score inherent risk honestly. Imagine the control is absent, not merely weak. Low inherent scores hide the value of the controls you run.
  • Pick one of four treatments. Mitigate, transfer, avoid or accept. An accepted risk needs a named person and a date, or it is not accepted, only ignored.
  • Link each risk to requirements. ISO 27001 Annex A controls, SOC 2 criteria or DPDP duties. It is how the register feeds the Statement of Applicability.
  • Set an appetite threshold. A residual score above it goes to leadership.
05

Why does residual risk need to move on its own?

Residual risk should move on its own because the controls it depends on change state without anyone updating the register. When encryption is switched off or MFA lapses, the residual score should rise that day, not at the next quarterly review. A spreadsheet can only approximate this with a frequent review cycle.

The TryTrustable risk register attaches the treating controls to each risk and recalculates the residual score whenever those controls pass or fail, with appetite thresholds that raise their own alerts. Data protection impact assessments and vendor reviews feed the same register, so privacy and security risk are ranked on one scale. For how risk ties into the rest of a programme, see the compliance programme page.

More free templates: the full template library, including a 5×5 risk register, a record of processing activities, a vendor security questionnaire and a DPDP consent notice.

Questions

The things people ask us

What columns should a risk register have?

At minimum: an ID, the risk described as cause, event and consequence, an owner, likelihood and impact scores, an inherent score, existing controls, a treatment decision, residual likelihood and impact, a residual score, a review date and a status. Linking each risk to the requirements it affects makes the register usable in an audit.

How do you calculate inherent and residual risk?

Inherent risk is likelihood multiplied by impact before any controls, each scored 1 to 5, so scores run from 1 to 25. Residual risk is the same calculation after the controls you actually operate are taken into account. The difference between the two is the value of your controls.

What are the risk bands for a 5x5 matrix?

This template uses the same bands as our risk register: 1 to 4 Low, 5 to 9 Moderate, 10 to 14 High, 15 to 19 Severe and 20 to 25 Critical. Each band triggers a different response, from annual review for Low to board-level attention for Critical. The exact thresholds matter less than applying them consistently.

What are the four risk treatment options?

Mitigate, by adding controls that reduce likelihood or impact; transfer, by moving the financial consequence to an insurer or counterparty; avoid, by stopping the activity; and accept, as a named, dated decision. Transfer does not move regulatory liability under the DPDP Act or the GDPR, which stays with you.

Does ISO 27001 require a risk register?

ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3 require a documented risk assessment and treatment process, with risk owners, and retained results. The standard does not require a register by name, but a register is how almost every organisation holds those results, and the controls chosen for treatment feed the Statement of Applicability.

Why does residual risk go stale in a spreadsheet?

Because the controls change and the spreadsheet does not. A residual score entered in March still reads Moderate in October after the control it relied on has stopped working. The only fix in a spreadsheet is a review cycle; the alternative is to derive the residual score from the live state of the controls.

Book a walkthrough

Bring three real risks to the call.

We score them live, attach the controls, and show you what the residual number does when a control fails.