Risk management
A risk register people actually maintain.
You almost certainly have one already. The question is whether it knows the control it depends on lost its evidence in February, whether anybody’s name is against the third entry, and whether it has been opened since the last board meeting. Sentinel keeps risk in the same place as the controls, the evidence and the work.
Self-service signup opens shortly — we will set you up in the meantime
| Title | Category | Rating | Status | Owner | Treatment | Target |
|---|---|---|---|---|---|---|
| Ransomware via phishing on plant-floor engineering workstations | Cyber | Critical4×5 | Open | Priya Raman | Mitigate | 30 Nov 2026 |
| Privileged accounts without PAM / shared local admin credentials | Cyber | High3×4 | Open | Priya Raman | Mitigate | 31 Oct 2026 |
| Unpatched OT/SCADA vendor appliance (vendor-managed) | Third-party | High3×4 | Open | Marc Lévesque | Transfer | 15 Dec 2026 |
| Third-party logistics portal — no SOC 2 report available | Third-party | Medium3×3 | Open | Elena Kowalski | Mitigate | 05 Oct 2026 |
| MFA not enforced for all Microsoft 365 users | Cyber | Critical4×5 | Mitigated | Priya Raman | Mitigate | Closed 08 May 2026 |
- Ransomware via phishing on plant-floor engineering workstations
- Category
- Cyber
- Rating
- Critical4×5
- Status
- Open
- Owner
- Priya Raman
- Treatment
- Mitigate
- Target
- 30 Nov 2026
- Privileged accounts without PAM / shared local admin credentials
- Category
- Cyber
- Rating
- High3×4
- Status
- Open
- Owner
- Priya Raman
- Treatment
- Mitigate
- Target
- 31 Oct 2026
- Unpatched OT/SCADA vendor appliance (vendor-managed)
- Category
- Third-party
- Rating
- High3×4
- Status
- Open
- Owner
- Marc Lévesque
- Treatment
- Transfer
- Target
- 15 Dec 2026
- + 2 more in the workspace
7 open, 5 mitigated. Figures are from the example workspace used across this site — Northstar Manufacturing Ltd. is fictional.
The problem
Nobody sets out to abandon a risk register.
It dies of four specific causes, and they are all consequences of keeping risk in a document with no connection to the controls it talks about. That is a structural problem, not a diligence problem.
Four specific causes, and most registers have three
- 01
The workshop deck
Two hours of genuinely good thinking, facilitated by somebody competent, exported to slides in March. Nobody has opened it since March, and three of the risks in it were resolved in April.
- 02
An owner column that says “IT”
A department cannot make a treatment decision, cannot accept a risk, and cannot be overdue. A register with a team name in the owner column has, in practice, no owners at all.
- 03
A rating nobody can reconstruct
A risk scored 12, from a 3 and a 4 agreed in a room, with no record of what a 3 meant or who argued for it. Next year somebody scores it 9, and there is no way to tell whether anything improved.
- 04
Reviewed once a year, the week before the board meeting
Which makes the review a formatting exercise. Ratings get adjusted to match the story the pack is telling, instead of the pack reporting what the register found.
The one worth fixing first is the third-order version of all four: an entry reads “mitigated by multi-factor authentication and quarterly access reviews”, and both halves were true when they were typed. The access review has not run since, and the register has no way of knowing. Everything below follows from closing that gap.
A gap nobody owns is a note, not a finding.
Every register contains entries that describe a problem accurately and commit nobody to anything. They are not risks being managed — they are observations being stored, and they are the reason a register stops being opened.
The record
Seven fields, and one of them decides whether the register survives.
A risk record is not complicated. What matters is that none of these tolerates a blank, because a register that accepts blanks fills up with them — and the owner field is the one that empties first.
| Column | What it holds | Why it is not optional |
|---|---|---|
| Title | A description somebody who was not in the room can read. | “Ransomware” is a category. “Production database encrypted and no restore tested in twelve months” is a risk you can do something about. |
| Category | Third party, resilience, technical, operational — the grouping the register sorts and reports by. | Categories keep a register readable at forty rows, and make it obvious when every entry you have is a technical one. |
| Rating | Critical, High, Medium, Low — with the L×S arithmetic recorded on the same row. | A rating only compares with another rating when the workings are beside it. 4×5 is defensible a year later. “Critical” on its own is not. |
| Status | Open, Mitigated, Formally Accepted. | Three states, and the third is the one most registers lack — which is exactly why acceptance ends up undocumented. |
| Owner | One named person, not a function. | The owner authorises the treatment or escalates it. This is the field that quietly empties first, and the one that decides whether the register survives. |
| Treatment | The route chosen, and who chose it. The example register shows Mitigate and Reduce; transfer and formal acceptance are the other two. | A risk sitting in a register with no decision against it is not being managed. It is being stored. |
| Target | The date it is expected to be resolved by — or, for a closed risk, the date it closed. | A treatment with no date is a sentiment. The register sorts on this field and reports what has gone past it. |
Blank is not a passing state
A risk with no owner reports as an exception rather than sorting quietly to the bottom of a list. So does a risk past its review date, and one whose treatment actions are overdue. Nobody has to audit the register for completeness, because incompleteness is on the same screen as everything else.
One rating scale, written down once
The register records the L×S arithmetic alongside the Critical / High / Medium / Low label, so a rating can be defended a year later by somebody who was not in the room. That is the whole reason a second review can be a measurement rather than another argument about what a 3 means.
The chain
Risk, control, evidence, decision, work, review.
You cannot check the evidence behind a control you never linked, and a treatment nobody decided cannot become work. This is the only part of a register that makes it self-correcting, which is why it is the part a spreadsheet cannot reproduce.
- 01
The risk
Recorded in plain terms with a named owner and a rating. Raised from wherever it came from — an assessment finding, an incident, a customer question, a control with no evidence behind it, or somebody noticing something on a Tuesday.
- 02
The controls
The risk points at the controls meant to reduce it, in the same register the rest of the programme uses — not a separate list of mitigations typed into a risk document, which is how a business ends up with two descriptions of one control.
- 03
The evidence
Each linked control carries its evidence, with a status and an expiry date. A risk resting on a control whose proof lapsed eight months ago is visibly exposed rather than nominally mitigated — the failure mode every spreadsheet register has.
- 04
The decision
Reduce, transfer, avoid or accept, recorded against the risk with the person who decided and the date. Where it is acceptance, it carries a rationale and a date it comes back.
- 05
The work
A treatment becomes tracked actions with owners and due dates, in the same backlog as evidence gaps and assessment findings. One list of security work, and one answer to whether any of it moved this month.
- 06
The review
On its review date the risk returns with what changed since the last one: rating, linked controls, evidence that expired, actions closed or overdue. A review becomes a decision rather than an archaeology exercise.
The practical effect is that the register maintains part of itself. Evidence expiring changes what the linked risks look like. An assessment finding raises a risk instead of sitting in a separate report. What is left for a person is judgement — the rating, the decision, the escalation — which is the only part that needed a person in the first place.
Treatment
Four routes, and acceptance is a real one.
A business accepts risk constantly and correctly. What separates a defensible acceptance from an unmanaged one is whose name is on it and when it comes back.
- Reduce
- Strengthen or add the controls that hold it down, as dated work with owners. The register shows the rating you expect to reach and the actions the reduction depends on, so “we are working on it” has a date attached.
- Transfer
- Move some of the consequence elsewhere — most often an insurance policy, sometimes a contractual term with a supplier. The register holds the decision and what it relies on, including the representations you made to get it.
- Avoid
- Stop doing the thing: retire the legacy system, drop the data you did not need to hold, end the integration nobody uses. Recorded with an owner, because avoidance nobody schedules is an intention.
- Accept
- Decide to live with it, on the record. Acceptance is a legitimate answer and a common one. What makes it defensible is a named person, a stated reason, and a date it gets looked at again.
What an acceptance has to carry
Somebody with the authority to accept it
A risk accepted by the person who would otherwise have had to fix it is not an acceptance, it is a deferral. The record names who decided — the first question an auditor or an incident review asks.
A reason, written at the time
Cost, timing, a compensating control, a decision to take the exposure. Written while the decision was fresh, not reconstructed afterwards from memory.
A date it comes back
An acceptance with no review date is not a decision, it is a shrug that got filed. Circumstances change: the system grows, the customer base changes, the compensating control lapses.
Visibility above the person accepting
Accepted risks appear in the executive and board view as a set, with ratings and review dates. Acceptance is a management position, so it is reported rather than absorbed.
Transfer, in practice
Insurance is the transfer route most businesses use, and the register is where the decision belongs: which exposures the policy is expected to answer for, which controls the insurer was told about, and what the renewal will ask you to re-confirm. Sentinel organises that so the risk position and the submission tell the same story.
Action centre
Gaps become work, bucketed the way an owner actually thinks.
Not a flat backlog sorted by creation date. Five horizons, and the same list holds evidence gaps, assessment findings and risk treatments — so there is one answer to whether any of it moved this month.
- Critical Now2
- Work that cannot wait for a planning cycle. The example workspace holds two.
- Next 30 Days3
- Committed for this month, with an owner and a date already against each item.
- Next Quarter3
- Real work, planned rather than reacted to. This is the bucket that should be the biggest.
- Quick Wins3
- An hour of somebody’s afternoon that closes a gap — assign the unowned supplier control, publish a document that already exists.
- Strategic Projects
- Budget and a quarter, not an afternoon. Carried here so it stops competing with this week for attention.
Counts are from the example workspace. Strategic Projects deliberately carries no figure here — the example dataset does not publish one, and filling the slot would be an invention.
| Action | Module | Owner | Priority | Due | Status |
|---|---|---|---|---|---|
| Run and document the Q3 backup restore test | Audit | Jordan Blake | Critical | 30 Sep 2026 | Not started |
| Deploy privileged access management for shared admin accounts | Risk | Priya Raman | Critical | 15 Oct 2026 | In progress |
| Obtain SOC 2 report from Great Lakes Logistics | Vendors | Elena Kowalski | High | 05 Oct 2026 | In progress |
| Approve the Data Retention & Disposal Policy | Policies | Dana Whitfield | High | 10 Oct 2026 | Not started |
| Tabletop exercise with plant leadership — ransomware scenario | Risk | Dana Whitfield | Medium | 20 Nov 2026 | Not started |
- Run and document the Q3 backup restore test
- Module
- Audit
- Owner
- Jordan Blake
- Priority
- Critical
- Due
- 30 Sep 2026
- Status
- Not started
- Deploy privileged access management for shared admin accounts
- Module
- Risk
- Owner
- Priya Raman
- Priority
- Critical
- Due
- 15 Oct 2026
- Status
- In progress
- Obtain SOC 2 report from Great Lakes Logistics
- Module
- Vendors
- Owner
- Elena Kowalski
- Priority
- High
- Due
- 05 Oct 2026
- Status
- In progress
- + 2 more in the workspace
Reporting
What a board needs from a register, and what it does not.
A board does not want forty rows. It wants the biggest exposures, what moved, what somebody has decided to live with, and which two things need a decision from them this quarter.
- Forty rows, exported the week before the meeting
- A heat map with no owners on it
- Ratings adjusted to match the story the pack is telling
- Accepted risks absorbed rather than reported
- Treatment work counted, not aged
- No way to answer a follow-up question in the room
- The top risks by rating, each with one name against it
- Movement since the last review, and the record that caused it
- Accepted risks, and the dates they come back
- Treatment work that is past its date, and whose it is
- Escalations — the decisions the owner cannot make alone
- Every figure openable back to the risk behind it
Questions
What buyers ask about the risk register.
Ownership, size, and how the register stays connected to the compliance work — the three that decide whether a register is still alive in twelve months.
Risk register and action tracking are included from Essentials upwards, at $99 per month. Executive and board reporting is part of Full Platform.
Compare plansWho should own a risk — the person who found it, or the person who can fix it?
How many risks should a register have?
Is the register separate from our compliance work?
How is a rating recorded?
Can AI write our risk register for us?
What does the board actually get out of this?
What happens to our register if a trial ends?
Start with the ten risks you would name in a meeting.
Not a library of two hundred generic entries. Ten real ones, each with an owner, a rating you can defend and a target date — linked to the controls they depend on, so you can see what each one rests on when you review it.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required