Somewhere in your shared drive there is a spreadsheet called Risk_Register_FINAL_v3. It was last opened the week before an audit, half the review dates have passed, and nobody is completely sure which tab is the current one.
That spreadsheet is what this guide will help you replace. A risk register is a live record of what could hurt your business and who is doing something about it. Done well, it becomes the most useful register in your risk workflow, and it takes less effort to build than most guides make out.
Below you will find a free risk register template and a worked example to copy from. Just as important, we will cover the small habits that keep a register alive after week one.
Want the template first?
It is free, prefilled with example risks, and works in Excel or Google Sheets. Pop your email in and we will send it over.
What is a risk register?
A risk register is a structured record of the risks facing your business. Each entry captures a specific risk, how likely it is, how much damage it would do, who owns it, and what is being done about it. You will sometimes hear it called a risk log or a risk inventory, and they all mean the same thing.
ISO 31000, the international risk management standard, treats recording and reporting as a core part of managing risk. The register is where that recording lives, and the structure scales from a two-person consultancy up to a manufacturer with three sites.
What should a risk register include?
Ten fields cover what a working SME register needs:
- Risk ID, so entries can be referenced without ambiguity.
- Risk description, specific enough that a new hire would understand it.
- Category, such as operational, financial, compliance or cyber.
- The asset affected, whether that is a building, a production line, a fleet vehicle or a customer database.
- Likelihood rating.
- Impact rating.
- Overall risk rating, usually the two ratings combined.
- Owner, one named person per risk.
- Controls and treatment plan, covering what limits the risk today and what is planned.
- Status and next review date.
The asset column is the one most free templates skip, and it is the one worth keeping. When every risk points at a real thing your business owns, the register turns into something your team can act on.
What is inside the free template
The download gives you all ten fields set up and ready, with:
- Dropdown menus for likelihood, impact and status, so scoring stays consistent.
- A rating column that calculates itself from likelihood and impact.
- Six example risks already filled in, drawn from property, manufacturing, logistics and energy businesses.
- A second tab explaining each field in plain language.
It works in Excel and Google Sheets, and there is nothing to install. Delete our example rows, add your own, and you have a working register this afternoon.
How to fill in your risk register
A blank register can feel intimidating, so take it in five small steps.
Start with your assets
List the things your business depends on before you list any risks. Buildings, equipment, vehicles, key suppliers, systems, data. Risks get much easier to spot when you are looking at a concrete list, because for each asset you can simply ask what would hurt if it failed.
Describe each risk specifically
"Cyber risk" tells you nothing at three months' distance. "Customer data exposed through a phishing attack on the finance inbox" tells you exactly what you were worried about and where to look. Write every description so that someone who was not in the room could act on it.
Score likelihood and impact
Rate each risk on a consistent scale, from rare to almost certain for likelihood and minor to severe for impact. A 5x5 risk matrix is the standard tool for the job. Whatever scale you choose, write down what each level means, because the ratings only work if everyone scores the same way.
Give every risk an owner
Every entry needs one named person attached, ideally whoever sits closest to the asset. A production line risk belongs to the site engineer who hears the motor every day, and the register coordinator simply keeps track of the whole.
Set a review date
Every entry gets a next-review date before you close the file. It is a small habit, and it is the one that keeps a register current after the initial enthusiasm wears off.
Risk register example
Three entries from a typical SME register, using the template's fields:
Risk register example rows
| Risk | Likelihood | Impact | Rating | Owner |
|---|---|---|---|---|
| Key supplier fails, delaying customer deliveries | Possible | Major | High | Operations manager |
| Ageing conveyor motor fails, halting the production line | Likely | Moderate | High | Site engineer |
| Customer data exposed through phishing attack | Possible | Severe | Critical | IT lead |
Each description names a specific failure, and the ratings make the priority order obvious at a glance. That is the whole job of the register.
How often should you review a risk register?
Quarterly is the sensible baseline for most SMEs, with your highest-rated risks checked monthly and any entry updated straight away when something changes, such as a new supplier coming on board or a near miss on site.
The easiest way to make reviews happen is to attach them to a meeting that already exists. Ten minutes in your monthly ops meeting beats a standalone review that keeps getting postponed. The Australian government's business.gov.au guidance makes the same point: risk management works best folded into normal business planning.
Common risk register mistakes
The template protects you from formatting problems, so the mistakes left are habits. The ones we see most:
- Descriptions too vague to act on, which turn reviews into guesswork.
- Risks without a named owner, so nobody notices when one deteriorates.
- Scoring that means different things depending on who filled in the row.
- Registers that only get opened in the fortnight before an audit.
- A register only one person understands, which becomes a real problem the week they go on leave.
All five are fixable with the habits above, applied consistently.
When a spreadsheet stops being enough
A spreadsheet register is a great place to start, and for some small businesses it stays sufficient for years. The strain shows when the register needs to connect to things: controls that need evidence behind them, treatment plans with tasks and deadlines, approvals that need sign-off history, reports the board wants monthly.
At that point the register has become a risk workflow spread across email, folders and tabs, and the chasing starts to eat your week.
That is the point Guardzy was built for. You can import a spreadsheet register, keep the fields that matter, and connect each record to owners, assets, controls, evidence, tasks, approvals, and reports. The free plan takes an afternoon to set up, so the work you have done in the template carries straight over into a live register workspace.
Move your risk template into a connected register
Move from a spreadsheet risk register to a connected workspace for risks, assets, controls, evidence, owners, and reports without an enterprise rollout.
- Import spreadsheet registers into a live workspace.
- Link each risk to the asset, controls, evidence, and treatment work behind it.
- Give owners clear follow-up without chasing every review manually.
About the author
Hamish Lister writes practical register, security, compliance, and workflow guides for SMEs that need audit-ready structure without an enterprise rollout.
Frequently asked questions
What is the difference between a risk register and a risk assessment?
A risk assessment is the activity and the risk register is where the results live. You assess a risk when you work out how likely it is and how much damage it would do, then you record that thinking in the register so the risk can be owned, tracked and reviewed over time.
What else is a risk register called?
The same document goes by risk log, risk inventory and sometimes RAID log, which stands for risks, actions, issues and decisions. They all describe a single structured record of your risks, so do not let the vocabulary put you off.
Who should maintain the risk register?
One person should coordinate the register, usually an operations lead, a risk manager, or the owner in a smaller business, while each individual risk belongs to its own named owner. That split keeps the document consistent without making one person a bottleneck for every update.
Can I use Excel for a risk register?
Excel works well for a starting register, and our free risk register template is built for it. The limits appear as you grow, when risks, controls, evidence and approvals need to stay linked together, and that is usually the point where SMEs move to purpose-built register software.