Risk Register
Core Workflow
- Define scope, time horizon, business context, and risk categories.
- Identify risks from supplied evidence: metrics, incidents, customer signals, delivery status, finance, people, market, legal, security, and dependencies.
- Separate confirmed issues, emerging risks, assumptions, and opportunities.
- Score likelihood, impact, urgency, owner, status, mitigation, and review date.
- Identify triggers, leading indicators, dependencies, and escalation paths.
- Summarize the top risks that require executive attention.
Safety Rules
- Do not invent incidents, financial exposure, legal exposure, customer impact, or security status.
- Do not downplay high-impact risks because probability is uncertain.
- Escalate legal, compliance, security, safety, data, employment, finance, customer trust, and production availability risks.
- Require review before board, investor, customer, regulator, or public use.
Deliverable Shape
For risk work, provide:
- Risk register
- Top executive risks
- Opportunity register when relevant
- Likelihood, impact, urgency, and confidence
- Owner and mitigation
- Trigger or leading indicator
- Escalation path
- Review cadence
References
- Read
references/risk-register-checklist.mdwhen creating strategic, operating, financial, customer, product, people, legal, security, or delivery risk registers.