Templates / Risk register template

Risk register template

A risk register is the single list your organisation keeps of what could go wrong, how serious each risk is, who owns it, and what you're doing about it. Below is a complete, worked example you can download as a spreadsheet or open live — pre-filled with common risks, scored, and with a recommended treatment for each.

Open live in Urna — free Download the CSV

No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.

Worked example: risk register template

RiskCategoryLikelihoodImpactRatingSuggested remediation
Phishing and credential theftAn attacker tricks a staff member into revealing a password or approving a login, or steals a session, and gains access to email, files or business systems.securityhighhighhighEnforce phishing-resistant multi-factor authentication (passkeys or hardware security keys) on email and any account that reaches sensitive data.
Ransomware and extortionMalware encrypts systems or an attacker steals data and threatens to leak it, halting operations and demanding payment.operationalmediumhighhighKeep tested, offline or immutable backups of critical data and rehearse restoring from them.
Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust.legalmediumhighhighEncrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it.
Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection.securitymediumhighhighKeep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding.
Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work.securitymediumhighhighGrant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves.
Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in.securityhighhighhighBuild systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it.
Unpatched or end-of-life systemsA known vulnerability in software, a device or a dependency is left unpatched — or the product is past end of support — and an attacker exploits it.securityhighhighhighKeep a live inventory of software and versions and scan for known vulnerabilities, prioritising internet-facing and critical systems.
Denial of service and loss of availabilityA distributed denial-of-service attack, traffic spike or infrastructure failure knocks a public-facing or business-critical service offline.operationalmediummediummediumRoute public-facing traffic through a DDoS-mitigation or filtering layer, and line up upstream scrubbing in advance.
Shadow or unsanctioned AI useStaff paste confidential documents, customer data or code into public AI tools to get work done faster, sending that data to a third party outside any agreement or oversight.legalhighhighhighPublish a short AI-use policy: which tools are approved, and the data categories that must never be pasted into a public service.
Sensitive data sent to an external AI modelPrompts, documents or records sent to a hosted model for inference leave your security boundary — retained in logs, exposed to the provider, or transferred across borders — even when the AI use is sanctioned.legalhighmediumhighClassify what may and may not be sent to an external model, and minimise or redact personal and confidential data in prompts.

Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.

Questions

What is a risk register?

A risk register is a living record of an organisation's risks — each with a description, a likelihood and impact rating, an owner, and the controls or treatments in place. It's the artefact auditors, boards, and clients ask for as evidence that risk is being managed.

What should a risk register include?

At minimum: the risk and its scenario, a likelihood and impact (and often vulnerability) rating, an overall severity, the treatment decision, the controls applied, an owner, and a review date. The example below has all of these.

Is this risk register template free?

Yes. Download the CSV with no sign-up, or open the same register live in Urna — a free risk register tool — to edit it, score your own risks, and get suggested remediations. No card required.

Build your own in Urna — free

Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.

Start free See how it works