If your risk register records concerns but does not change decisions, take one stale entry to the next review meeting. Rewrite the scenario, test the controls and leave with a decision, an accountable owner and a date. Updating the colour of a cell is not the decision.
Start with the row that nobody can act on
“Cyberattack — High — IT to monitor” could sit unchanged for years. It does not identify what could happen, which objective is exposed, what currently stops it or what the owner needs approval to do. Pick a real entry with that problem and work it through before redesigning the whole register.
Move from an entry to a decision
- Find the stale row. Identify the unresolved decision and the objective at risk.
- Rewrite the risk statement. Describe a credible cause, event and consequence.
- Separate causes and consequences. Record the pathways and what each outcome would mean.
- Use a bow-tie where it helps. Put the central loss-of-control event between causes and consequences. A simple risk may only need a short paragraph.
- Identify and test current controls. Name the operator and inspect evidence that each relevant control works.
- Identify gaps. Distinguish a missing control, a failed control and missing evidence.
- Decide. Treat, retain, escalate or investigate further, using agreed criteria and authority.
- Assign owners and dates. Record actions, resources, the completion test and the next review.
Worked example: an invoice-fraud entry before and after
In this fictional example, Eastbank Advisory is a professional services firm. Its finance director needs to decide whether supplier bank-detail changes are controlled well enough for the next payment run. The dates below illustrate an agreed action plan.
| Field | Before | After |
|---|---|---|
| Risk statement | Cyberattack | A fraudulent supplier bank-detail request could be accepted without independent verification, diverting an approved payment and causing financial loss and delayed supplier payment. |
| Current controls | Staff trained; two approvals | A callback procedure exists, but four of ten sampled changes lack evidence of a call to a previously verified number. Both payment approvers relied on the same altered invoice. |
| Assessment | High, copied from last quarter | The old rating is unsupported. Assess the current scenario and observed control failures against the agreed criteria; record uncertainty while the sample is extended. |
| Decision | IT to monitor | Treat the verification gap now; investigate how often it occurs. Escalate any exposure outside the finance director’s delegation. |
| Owner and action | IT; ongoing | Finance manager: verify unresolved bank changes using independently held contact details before the next payment run, by 30 September 2026. |
| Completion and review | None | By 7 October 2026, a reviewer independent of processing checks the next ten changes for callback records and separate approval. Finance director reviews results on 9 October. |
Use the bow-tie to test the proposed fix
The central event is an unauthorised bank-detail change being accepted. Causes include a spoofed request, a compromised supplier mailbox and staff bypassing a callback under time pressure. Consequences include a diverted payment, recovery costs and an unpaid legitimate supplier.
An independent callback before changing the bank record is a preventive control. A second approver helps only if that person checks different, reliable evidence. After a diverted payment, prompt detection, bank contact and an exercised recovery process may limit loss. They do not undo the failed preventive check, and recovery is not guaranteed.
Test that distinction. Inspect completed callbacks, exception records and the approval trail. Rehearse the escalation route without making a real payment. If the proposed “fix” is another reminder to be careful, ask which failure it changes and how you would know.
Choose an outcome, rather than another status update
- Treat: change a control or activity, with resources and a test of effectiveness.
- Retain: accept the current risk with a documented reason, authorised owner and review trigger.
- Escalate: take the decision to someone with the necessary authority; state what you need them to decide.
- Investigate further: name the missing evidence, who will obtain it and when. Record any interim controls while uncertainty remains.
These outcomes can be combined. Eastbank treats an observed gap while investigating its extent. It does not lower the risk rating merely because an action has been approved. Reassess after the control is operating and the evidence supports the change.
Keep the reasoning with the row
Record the evidence date, assumptions, decision authority and why the chosen action is proportionate. Keep the register concise, linking to the detailed evidence where necessary. At the next review, ask what changed in the exposure, controls or evidence before copying the previous rating forward.
This is where Risk Management Body of Knowledge (RMBOK) thinking is useful: the objective, scenario, causes, consequences and controls form an argument for a decision. The free 24-page RMBOK PDF guide explains that reasoning in more depth. Once actions are agreed, use a risk treatment schedule to track delivery and evidence of completion.
Free working resource
Put the decision into a working record
The free Risk Register Starter Pack contains a simple register, treatment plan and summary in editable Word and PDF formats. Use it if your existing record cannot capture the decision clearly. Keep one approved record rather than creating a parallel register.
Download the free Word and PDF Starter Pack
Opens the SRMBOK product page. Add the free item to your cart and complete the $0 order to receive the download. Check the newsletter choice at checkout.
