Risk Register
What is Risk Register?
A documented inventory of identified risks, their assessments, treatment plans, and current status. A key tool in enterprise risk management.
Related terms
Frameworks that govern risk register
What the standards actually require on risk register
Requirements naming risk register across 6 standards, quoted from the control text.
Risk Reporting + KRIs + Performance + Horizon Scanning translate the risk management process into actionable management information.
IRM-Reporting-KRIs-Performance-HorizonScanning-Dashboard-Heatmap-RiskRegister-EmergingRisk · IRM Risk Reporting + Key Risk Indicators (KRIs) + Performance Measurement + Horizon Scanning + Dashboard + Heat Map + Risk Register + Emerging Risk Identification →Communicate risk per NIST SP 800-30 Rev 1 Section 3.3 Step 7 (Communicating and Sharing Risk Assessment Information). Communication must address (a) decision makers (system owner, mission owner, authorising official, Risk Executive Function, board) with approp...
NISTSP30-7 · Risk Communication and Sharing →Implement Technology Risk Governance + Technology Risk Management Framework + Information Asset Management per MAS TRM Chapters 2 + 3 + 5.
MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management · MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management →Identify, analyse, and treat project risks throughout the lifecycle with documented risk register and mitigation tracking.
MAN.5 · Risk Management →HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;
HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment →UR E26 Goal 1 (Identify) also requires a Ship Cyber Resilience Plan (SCRP) covering scope + assumptions + roles + responsibilities + risk assessment methodology + control measures + maintenance procedures + incident response + recovery + training.
IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation · IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation →Questions people ask about risk register
What is Risk Register?
Why is Risk Register important for compliance?
What concepts are related to Risk Register?
Which compliance frameworks address Risk Register?
Where can I learn more about Risk Register?
See how Risk Register applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.