Governance · Enterprise risk · Component
Enterprise risk register
The principal risks across the whole organisation, drawn from every function, assessed on one scale and each with a named owner.
The deliverable
What it is
The enterprise register is not the sum of every departmental register. It holds the principal risks — those that could affect the organisation’s objectives as a whole — and draws them from the places where they are managed: Compliance, technology and security, the supply chain, finance and the rest.
Its distinctive work is comparison. Placed on one scale and beside the appetite, a supplier concentration and a data-protection exposure can be weighed against each other, and risks sharing a cause become visible as a cluster.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Principal risks
Each risk described as a cause, an event and a consequence for the organisation’s objectives.
3 attributes: Risk description · Category · Objective affected
LearnSource functions
Where each risk was identified and is managed in detail — Compliance, technology, supply chain or elsewhere.
3 attributes: Detailed record · Risk owner · Source updated
LearnAssessment
Likelihood and impact before and after treatment, on the scale the whole organisation uses, compared with appetite.
4 attributes: Likelihood · Impact · Confidence · Against appetite
Learn
Point to the functional records; do not copy them. Two versions of one risk will drift apart within a quarter.
The other components in enterprise risk
Risk appetite statement
How much risk the organisation is prepared to carry in each category, with the tolerances that trigger escalation to the board.
LearnAssurance map
For each principal risk, who manages it, who oversees it and who checks it independently — and when each last did so.
Learn