Risk register template with 5×5 scoring.
The columns, the scoring, the bands and the spreadsheet formulas, with two worked risks from start to residual. Paste it into a sheet and replace the examples with your own.
What is a risk register?
A risk register is the list of risks an organisation has identified, each with an owner, a score for likelihood and impact before controls (inherent) and after them (residual), a treatment decision and a review date. It is the working record behind ISO 27001 risk treatment, SOC 2 risk assessment and the security duties in the DPDP Act.
One number per risk records an opinion. Two numbers, inherent and residual, record an argument: what this would cost with nothing in place, and what it costs given the controls you actually operate. The template holds both.
How to score a risk on a 5×5 matrix
Score likelihood from 1 (rare) to 5 (almost certain) and impact from 1 (negligible) to 5 (severe), then multiply. The score, from 1 to 25, falls into one of five bands, and the band decides what happens next. These are the same bands the TryTrustable risk register uses.
| Score | Band | What it should trigger |
|---|---|---|
| 1–4 | Low | Accept and review annually |
| 5–9 | Moderate | Named owner, treatment plan, review every six months |
| 10–14 | High | Active treatment, quarterly review, visible to leadership |
| 15–19 | Severe | Escalation, dated remediation plan, monthly review |
| 20–25 | Critical | Board-level, immediate treatment or a documented decision to accept |
Likelihood × impact, each 1 to 5. The bands matter less than applying them consistently.
| Score | Likelihood | Impact |
|---|---|---|
| 1 | Rare: not expected in the next three years | Negligible: no data exposed, minutes of disruption |
| 2 | Unlikely: could happen once in three years | Minor: internal data, hours of disruption |
| 3 | Possible: could happen once a year | Moderate: limited personal data, a day of disruption, customer complaints |
| 4 | Likely: expected more than once a year | Major: significant personal data, regulator notification, contract loss |
| 5 | Almost certain: expected within months | Severe: large-scale breach, prolonged outage, material penalty exposure |
An example scale. Rewrite the descriptions in your own terms and keep them fixed, so two assessors give the same score.
The template
Tab-separated, 21 columns, two worked examples. Paste into cell A1 of a blank sheet. The examples show a risk moving from Critical to Moderate and from Severe to Moderate once treatment is in place.
ID Risk title Description (cause, event, consequence) Category Asset or process Owner Likelihood (1-5) Impact (1-5) Inherent score Inherent band Existing controls Treatment Planned controls and due date Residual likelihood (1-5) Residual impact (1-5) Residual score Residual band Within appetite? Review date Status Linked requirements R-001 Unencrypted vendor backup Backup vendor stores customer database copies without encryption; a compromise at the vendor exposes customer personal data; breach notification, penalty exposure and customer loss Vendor Customer database [Head of Infrastructure] 4 5 20 Critical Vendor contract with security clause Mitigate Encrypt backups with our keys before transfer [date]; vendor review [date] 2 4 8 Moderate Yes [date] In treatment ISO 27001 A.8.13, A.8.24; DPDP Rule 6(1)(a) R-002 Shared admin credentials Cloud admin account shared by three engineers; misuse or phishing of one person grants full control without attribution; outage or data loss with no audit trail Access Cloud production account [CTO] 4 4 16 Severe Password manager Mitigate Individual accounts with MFA and just-in-time elevation [date] 2 3 6 Moderate Yes [date] In treatment ISO 27001 A.5.16, A.8.2, A.8.5
Formulas for Google Sheets or Excel, assuming the column order above:
Inherent score (column I, row 2): =G2*H2 Residual score (column P, row 2): =N2*O2 Band (column J, from I2; copy the same formula to Q, pointing at P2): =IF(I2>=20,"Critical",IF(I2>=15,"Severe",IF(I2>=10,"High",IF(I2>=5,"Moderate","Low")))) Within appetite? (column R), with your appetite threshold in cell X1: =IF(P2<=$X$1,"Yes","No")
How to use this template
- Write risks as cause, event, consequence. “Ransomware” is a category; “unpatched VPN appliance lets an attacker encrypt file servers, stopping operations for a week” is a risk you can treat.
- Score inherent risk honestly. Imagine the control is absent, not merely weak. Low inherent scores hide the value of the controls you run.
- Pick one of four treatments. Mitigate, transfer, avoid or accept. An accepted risk needs a named person and a date, or it is not accepted, only ignored.
- Link each risk to requirements. ISO 27001 Annex A controls, SOC 2 criteria or DPDP duties. It is how the register feeds the Statement of Applicability.
- Set an appetite threshold. A residual score above it goes to leadership.
Why does residual risk need to move on its own?
Residual risk should move on its own because the controls it depends on change state without anyone updating the register. When encryption is switched off or MFA lapses, the residual score should rise that day, not at the next quarterly review. A spreadsheet can only approximate this with a frequent review cycle.
The TryTrustable risk register attaches the treating controls to each risk and recalculates the residual score whenever those controls pass or fail, with appetite thresholds that raise their own alerts. Data protection impact assessments and vendor reviews feed the same register, so privacy and security risk are ranked on one scale. For how risk ties into the rest of a programme, see the compliance programme page.
More free templates: the full template library, including a 5×5 risk register, a record of processing activities, a vendor security questionnaire and a DPDP consent notice.
The things people ask us
What columns should a risk register have?
At minimum: an ID, the risk described as cause, event and consequence, an owner, likelihood and impact scores, an inherent score, existing controls, a treatment decision, residual likelihood and impact, a residual score, a review date and a status. Linking each risk to the requirements it affects makes the register usable in an audit.
How do you calculate inherent and residual risk?
Inherent risk is likelihood multiplied by impact before any controls, each scored 1 to 5, so scores run from 1 to 25. Residual risk is the same calculation after the controls you actually operate are taken into account. The difference between the two is the value of your controls.
What are the risk bands for a 5x5 matrix?
This template uses the same bands as our risk register: 1 to 4 Low, 5 to 9 Moderate, 10 to 14 High, 15 to 19 Severe and 20 to 25 Critical. Each band triggers a different response, from annual review for Low to board-level attention for Critical. The exact thresholds matter less than applying them consistently.
What are the four risk treatment options?
Mitigate, by adding controls that reduce likelihood or impact; transfer, by moving the financial consequence to an insurer or counterparty; avoid, by stopping the activity; and accept, as a named, dated decision. Transfer does not move regulatory liability under the DPDP Act or the GDPR, which stays with you.
Does ISO 27001 require a risk register?
ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3 require a documented risk assessment and treatment process, with risk owners, and retained results. The standard does not require a register by name, but a register is how almost every organisation holds those results, and the controls chosen for treatment feed the Statement of Applicability.
Why does residual risk go stale in a spreadsheet?
Because the controls change and the spreadsheet does not. A residual score entered in March still reads Moderate in October after the control it relied on has stopped working. The only fix in a spreadsheet is a review cycle; the alternative is to derive the residual score from the live state of the controls.
Bring three real risks to the call.
We score them live, attach the controls, and show you what the residual number does when a control fails.