Governance · Enterprise risk · Component

Enterprise risk register

The principal risks across the whole organisation, drawn from every function, assessed on one scale and each with a named owner.

The deliverable

What it is

The enterprise register is not the sum of every departmental register. It holds the principal risks — those that could affect the organisation’s objectives as a whole — and draws them from the places where they are managed: Compliance, technology and security, the supply chain, finance and the rest.

Its distinctive work is comparison. Placed on one scale and beside the appetite, a supplier concentration and a data-protection exposure can be weighed against each other, and risks sharing a cause become visible as a cluster.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Principal risks

    Each risk described as a cause, an event and a consequence for the organisation’s objectives.

    3 attributes: Risk description · Category · Objective affected

    Learn
  2. Source functions

    Where each risk was identified and is managed in detail — Compliance, technology, supply chain or elsewhere.

    3 attributes: Detailed record · Risk owner · Source updated

    Learn
  3. Assessment

    Likelihood and impact before and after treatment, on the scale the whole organisation uses, compared with appetite.

    4 attributes: Likelihood · Impact · Confidence · Against appetite

    Learn
  4. Treatment

    What is being done about each risk — accept, reduce, transfer or avoid — and by when it should take effect.

    3 attributes: Response · Actions · Due

    Learn

Point to the functional records; do not copy them. Two versions of one risk will drift apart within a quarter.