Risk management

A risk register people actually maintain.

You almost certainly have one already. The question is whether it knows the control it depends on lost its evidence in February, whether anybody’s name is against the third entry, and whether it has been opened since the last board meeting. Sentinel keeps risk in the same place as the controls, the evidence and the work.

Self-service signup opens shortly — we will set you up in the meantime

Risk registerSentinel interface, reproduced
7
Open
1
Critical
2
High
4
Medium
0
Low
5
Mitigated
  • Ransomware via phishing on plant-floor engineering workstations
    Category
    Cyber
    Rating
    Critical4×5
    Status
    Open
    Owner
    Priya Raman
    Treatment
    Mitigate
    Target
    30 Nov 2026
  • Privileged accounts without PAM / shared local admin credentials
    Category
    Cyber
    Rating
    High3×4
    Status
    Open
    Owner
    Priya Raman
    Treatment
    Mitigate
    Target
    31 Oct 2026
  • Unpatched OT/SCADA vendor appliance (vendor-managed)
    Category
    Third-party
    Rating
    High3×4
    Status
    Open
    Owner
    Marc Lévesque
    Treatment
    Transfer
    Target
    15 Dec 2026
  • + 2 more in the workspace

7 open, 5 mitigated. Figures are from the example workspace used across this site — Northstar Manufacturing Ltd. is fictional.

7
Fields on every risk row: Title, Category, Rating, Status, Owner, Treatment, Target
5
Action horizons, from Critical Now to Strategic Projects
L×S
Rating recorded as likelihood times severity, not a single word
Essentials
Risk register and action tracking included from the entry plan

The problem

Nobody sets out to abandon a risk register.

It dies of four specific causes, and they are all consequences of keeping risk in a document with no connection to the controls it talks about. That is a structural problem, not a diligence problem.

Four specific causes, and most registers have three

  1. 01

    The workshop deck

    Two hours of genuinely good thinking, facilitated by somebody competent, exported to slides in March. Nobody has opened it since March, and three of the risks in it were resolved in April.

  2. 02

    An owner column that says “IT”

    A department cannot make a treatment decision, cannot accept a risk, and cannot be overdue. A register with a team name in the owner column has, in practice, no owners at all.

  3. 03

    A rating nobody can reconstruct

    A risk scored 12, from a 3 and a 4 agreed in a room, with no record of what a 3 meant or who argued for it. Next year somebody scores it 9, and there is no way to tell whether anything improved.

  4. 04

    Reviewed once a year, the week before the board meeting

    Which makes the review a formatting exercise. Ratings get adjusted to match the story the pack is telling, instead of the pack reporting what the register found.

The one worth fixing first is the third-order version of all four: an entry reads “mitigated by multi-factor authentication and quarterly access reviews”, and both halves were true when they were typed. The access review has not run since, and the register has no way of knowing. Everything below follows from closing that gap.

A gap nobody owns is a note, not a finding.

Every register contains entries that describe a problem accurately and commit nobody to anything. They are not risks being managed — they are observations being stored, and they are the reason a register stops being opened.

The record

Seven fields, and one of them decides whether the register survives.

A risk record is not complicated. What matters is that none of these tolerates a blank, because a register that accepts blanks fills up with them — and the owner field is the one that empties first.

The seven columns on a Sentinel risk record, what each holds, and why each is required
ColumnWhat it holdsWhy it is not optional
TitleA description somebody who was not in the room can read.“Ransomware” is a category. “Production database encrypted and no restore tested in twelve months” is a risk you can do something about.
CategoryThird party, resilience, technical, operational — the grouping the register sorts and reports by.Categories keep a register readable at forty rows, and make it obvious when every entry you have is a technical one.
RatingCritical, High, Medium, Low — with the L×S arithmetic recorded on the same row.A rating only compares with another rating when the workings are beside it. 4×5 is defensible a year later. “Critical” on its own is not.
StatusOpen, Mitigated, Formally Accepted.Three states, and the third is the one most registers lack — which is exactly why acceptance ends up undocumented.
OwnerOne named person, not a function.The owner authorises the treatment or escalates it. This is the field that quietly empties first, and the one that decides whether the register survives.
TreatmentThe route chosen, and who chose it. The example register shows Mitigate and Reduce; transfer and formal acceptance are the other two.A risk sitting in a register with no decision against it is not being managed. It is being stored.
TargetThe date it is expected to be resolved by — or, for a closed risk, the date it closed.A treatment with no date is a sentiment. The register sorts on this field and reports what has gone past it.

Blank is not a passing state

A risk with no owner reports as an exception rather than sorting quietly to the bottom of a list. So does a risk past its review date, and one whose treatment actions are overdue. Nobody has to audit the register for completeness, because incompleteness is on the same screen as everything else.

No ownerReview overdueNot assessed

One rating scale, written down once

The register records the L×S arithmetic alongside the Critical / High / Medium / Low label, so a rating can be defended a year later by somebody who was not in the room. That is the whole reason a second review can be a measurement rather than another argument about what a 3 means.

The chain

Risk, control, evidence, decision, work, review.

You cannot check the evidence behind a control you never linked, and a treatment nobody decided cannot become work. This is the only part of a register that makes it self-correcting, which is why it is the part a spreadsheet cannot reproduce.

  1. 01

    The risk

    Recorded in plain terms with a named owner and a rating. Raised from wherever it came from — an assessment finding, an incident, a customer question, a control with no evidence behind it, or somebody noticing something on a Tuesday.

  2. 02

    The controls

    The risk points at the controls meant to reduce it, in the same register the rest of the programme uses — not a separate list of mitigations typed into a risk document, which is how a business ends up with two descriptions of one control.

  3. 03

    The evidence

    Each linked control carries its evidence, with a status and an expiry date. A risk resting on a control whose proof lapsed eight months ago is visibly exposed rather than nominally mitigated — the failure mode every spreadsheet register has.

  4. 04

    The decision

    Reduce, transfer, avoid or accept, recorded against the risk with the person who decided and the date. Where it is acceptance, it carries a rationale and a date it comes back.

  5. 05

    The work

    A treatment becomes tracked actions with owners and due dates, in the same backlog as evidence gaps and assessment findings. One list of security work, and one answer to whether any of it moved this month.

  6. 06

    The review

    On its review date the risk returns with what changed since the last one: rating, linked controls, evidence that expired, actions closed or overdue. A review becomes a decision rather than an archaeology exercise.

The practical effect is that the register maintains part of itself. Evidence expiring changes what the linked risks look like. An assessment finding raises a risk instead of sitting in a separate report. What is left for a person is judgement — the rating, the decision, the escalation — which is the only part that needed a person in the first place.

Treatment

Four routes, and acceptance is a real one.

A business accepts risk constantly and correctly. What separates a defensible acceptance from an unmanaged one is whose name is on it and when it comes back.

Reduce
Strengthen or add the controls that hold it down, as dated work with owners. The register shows the rating you expect to reach and the actions the reduction depends on, so “we are working on it” has a date attached.
Transfer
Move some of the consequence elsewhere — most often an insurance policy, sometimes a contractual term with a supplier. The register holds the decision and what it relies on, including the representations you made to get it.
Avoid
Stop doing the thing: retire the legacy system, drop the data you did not need to hold, end the integration nobody uses. Recorded with an owner, because avoidance nobody schedules is an intention.
Accept
Decide to live with it, on the record. Acceptance is a legitimate answer and a common one. What makes it defensible is a named person, a stated reason, and a date it gets looked at again.

What an acceptance has to carry

  • Somebody with the authority to accept it

    A risk accepted by the person who would otherwise have had to fix it is not an acceptance, it is a deferral. The record names who decided — the first question an auditor or an incident review asks.

  • A reason, written at the time

    Cost, timing, a compensating control, a decision to take the exposure. Written while the decision was fresh, not reconstructed afterwards from memory.

  • A date it comes back

    An acceptance with no review date is not a decision, it is a shrug that got filed. Circumstances change: the system grows, the customer base changes, the compensating control lapses.

  • Visibility above the person accepting

    Accepted risks appear in the executive and board view as a set, with ratings and review dates. Acceptance is a management position, so it is reported rather than absorbed.

Transfer, in practice

Insurance is the transfer route most businesses use, and the register is where the decision belongs: which exposures the policy is expected to answer for, which controls the insurer was told about, and what the renewal will ask you to re-confirm. Sentinel organises that so the risk position and the submission tell the same story.

Action centre

Gaps become work, bucketed the way an owner actually thinks.

Not a flat backlog sorted by creation date. Five horizons, and the same list holds evidence gaps, assessment findings and risk treatments — so there is one answer to whether any of it moved this month.

Critical Now2
Work that cannot wait for a planning cycle. The example workspace holds two.
Next 30 Days3
Committed for this month, with an owner and a date already against each item.
Next Quarter3
Real work, planned rather than reacted to. This is the bucket that should be the biggest.
Quick Wins3
An hour of somebody’s afternoon that closes a gap — assign the unowned supplier control, publish a document that already exists.
Strategic Projects
Budget and a quarter, not an afternoon. Carried here so it stops competing with this week for attention.

Counts are from the example workspace. Strategic Projects deliberately carries no figure here — the example dataset does not publish one, and filling the slot would be an invention.

Action centreSentinel interface, reproduced
Critical Now2Next 30 Days3Next Quarter3Quick Wins3Strategic Projects2
  • Run and document the Q3 backup restore test
    Module
    Audit
    Owner
    Jordan Blake
    Priority
    Critical
    Due
    30 Sep 2026
    Status
    Not started
  • Deploy privileged access management for shared admin accounts
    Module
    Risk
    Owner
    Priya Raman
    Priority
    Critical
    Due
    15 Oct 2026
    Status
    In progress
  • Obtain SOC 2 report from Great Lakes Logistics
    Module
    Vendors
    Owner
    Elena Kowalski
    Priority
    High
    Due
    05 Oct 2026
    Status
    In progress
  • + 2 more in the workspace

Reporting

What a board needs from a register, and what it does not.

A board does not want forty rows. It wants the biggest exposures, what moved, what somebody has decided to live with, and which two things need a decision from them this quarter.

What a board is usually handed
  • Forty rows, exported the week before the meeting
  • A heat map with no owners on it
  • Ratings adjusted to match the story the pack is telling
  • Accepted risks absorbed rather than reported
  • Treatment work counted, not aged
  • No way to answer a follow-up question in the room
What a board can act on
  • The top risks by rating, each with one name against it
  • Movement since the last review, and the record that caused it
  • Accepted risks, and the dates they come back
  • Treatment work that is past its date, and whose it is
  • Escalations — the decisions the owner cannot make alone
  • Every figure openable back to the risk behind it

Questions

What buyers ask about the risk register.

Ownership, size, and how the register stays connected to the compliance work — the three that decide whether a register is still alive in twelve months.

Risk register and action tracking are included from Essentials upwards, at $99 per month. Executive and board reporting is part of Full Platform.

Compare plans
Who should own a risk — the person who found it, or the person who can fix it?
Neither, necessarily. The owner is whoever is accountable for the decision: they authorise the treatment or escalate it to somebody who can. That is often a manager rather than the engineer doing the work, and the actions underneath a risk can be owned by different people. What does not work is a team name, because a team cannot decide anything and cannot be overdue.
How many risks should a register have?
Fewer than most templates give you. Twenty risks that each have an owner, a rating somebody can defend and a review date will get reviewed. Two hundred imported from a generic library get skimmed once and abandoned. Start with the risks your business would actually recognise, and add what assessments and incidents surface.
Is the register separate from our compliance work?
No, and keeping them separate is what makes both go stale. A risk links to the same controls your framework requirements map to, and those controls carry the same evidence with the same expiry dates. When a policy lapses, the requirement, the control and every risk depending on it are affected at once, in one place, rather than in three documents that disagree.
How is a rating recorded?
As a rating with the arithmetic beside it — the register shows L×S, likelihood times severity, on the same row as the Critical / High / Medium / Low label. That is what makes a rating comparable with itself a year later, and what lets somebody who was not in the room see how it was reached.
Can AI write our risk register for us?
It can help you analyse a risk. AI assistance works from the entry and what is already in your own workspace — evidence, policies, open critical risks — and can describe the business impact, outline a treatment plan, and list the evidence and framework controls that apply. You set the rating and make the treatment decision. Nothing is rated, accepted or approved by AI.
What does the board actually get out of this?
Movement, and the decisions that need them: top risks by rating, what changed since the last review, which accepted risks are due back, and what treatment work is overdue — generated from the register rather than rebuilt by hand. Executive and board reporting sits in Full Platform; the register itself, with owners, ratings, treatments and action tracking, starts at Essentials.
What happens to our register if a trial ends?
When the trial ends, carrying on means choosing a paid subscription; nothing converts or is charged on its own. Your data is not deleted because a trial ended.

Start with the ten risks you would name in a meeting.

Not a library of two hundred generic entries. Ten real ones, each with an owner, a rating you can defend and a target date — linked to the controls they depend on, so you can see what each one rests on when you review it.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required