Templates / ISO 31000 risk register example
ISO 31000 risk register example
ISO 31000 is the general risk-management standard: identify risks, analyse likelihood and consequence, evaluate, treat, and review. The worked example below follows that structure across common organisational risks and is free to download or open live in Urna, which uses ISO 31000 as its default framework.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: iso 31000 risk register example
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust. | legal | medium | high | Encrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it. | |
| Denial of service and loss of availabilityA distributed denial-of-service attack, traffic spike or infrastructure failure knocks a public-facing or business-critical service offline. | operational | medium | medium | Route public-facing traffic through a DDoS-mitigation or filtering layer, and line up upstream scrubbing in advance. | |
| Ransomware and extortionMalware encrypts systems or an attacker steals data and threatens to leak it, halting operations and demanding payment. | operational | medium | high | Keep tested, offline or immutable backups of critical data and rehearse restoring from them. | |
| Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection. | security | medium | high | Keep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding. | |
| Shadow or unsanctioned AI useStaff paste confidential documents, customer data or code into public AI tools to get work done faster, sending that data to a third party outside any agreement or oversight. | legal | high | high | Publish a short AI-use policy: which tools are approved, and the data categories that must never be pasted into a public service. | |
| Deployer duties under AI regulationAs an organisation deploying AI, you fall under obligations — the EU AI Act's deployer and transparency duties, and comparable regimes elsewhere — that go unmet because no one has mapped which apply. | legal | medium | high | Inventory your AI uses and determine which obligations apply — for the EU AI Act, the deployer duties of Art. 26 and the transparency duties of Art. 50, plus any local regime. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is ISO 31000?
ISO 31000 is the international standard for risk management — a general framework (identify, analyse, evaluate, treat, monitor) that applies to any kind of risk, not just security. It's Urna's default register framework.
How do you build an ISO 31000 risk register?
Set the scope and criteria, identify risks, rate likelihood and consequence, evaluate against your appetite, decide treatments, assign owners, and review on a cadence. The example below is structured this way.
Is it free?
Yes — download the CSV free or open it live in Urna. No card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.