← Back to blog

72 Hour Triage, 30 Day Fixes for Risk Register Governance (Risk Teams)

October 3, 2026
72 Hour Triage, 30 Day Fixes for Risk Register Governance (Risk Teams)

Risk register governance is the set of rules that decide what gets recorded, who owns each entry and how often it gets reviewed, so the register drives decisions rather than sitting as a static file. The fastest improvement most teams can make is simple: assign a named owner and a review date to every top risk promptly. The sections below give you the field blueprint, the role map and the quick checklists to make that stick.


TL;DR:

  • Assign a clear owner and review date to every top risk within 72 hours to establish accountability and review cadence.
  • Ensure each risk entry includes a specific statement, source, likelihood, impact, existing controls, planned actions, and escalation level for auditability.
  • Distribute risk ownership across operational, oversight, and audit roles, with the register maintained by a neutral custodian responsible for data quality.
  • Regularly archive risks when trigger conditions no longer apply, and implement automation to enforce review deadlines and evidence collection.
  • Conduct frequent operational reviews and structured KPIs, such as overdue actions and risk trend analyses, to keep the register decision-relevant and actionable.

Keystoneconsulting
Strengthen Your Risk Governance
Keystone integrates with teams to improve governance, streamline reporting, and support audit-ready compliance across complex delivery environments.
Explore Keystone Consulting

Table of Contents

What good risk register governance looks like

A register earns its place in governance when it does four things: supports real decisions, triggers escalation before a risk becomes a crisis, leaves an auditable trail, and gives leadership a consolidated view of exposure across the portfolio rather than a department-by-department patchwork. Without those outcomes, a register is just a list.

The COSO Enterprise Risk Management framework frames this clearly: risk management only works when it is integrated with strategy and performance, with the board setting risk appetite and expecting reporting that feeds planning rather than sitting apart from it. BS ISO 31000 adds that risk management belongs inside governance and daily operations, with recording and reporting built into the process rather than bolted on afterwards.

In practice, this means:

  • Risk appetite set by the board decides which items reach the register and which stay managed through standard procedures.
  • Accountability for each entry sits with a named owner, never a department or a committee.
  • Continuous review replaces the annual refresh, so entries change as conditions change.
  • Tone from the top determines whether staff flag genuine risks early or quietly absorb them.

Building the register: essential fields and structure

A governance-grade register needs enough structure to be auditable without becoming bureaucratic. The following fields cover what assurance teams, boards and regulators expect to see, drawing on the field sets described in GSA's risk management strategy guidance, which links individual register entries to programme boards and defined review mechanisms.

  1. ID: a unique reference so the risk can be tracked across reports and meetings.
  2. Risk statement: a concise sentence combining the event, its consequence and its scope, for example "delayed material delivery could push the handover date past the contracted deadline for Phase 2".
  3. Owner: the named individual accountable for managing the risk, not a team or function.
  4. Source: where the risk originated, such as an audit finding, a site inspection or a stakeholder report.
  5. Likelihood and impact: scored on a consistent scale, qualitative for emerging or reputational risks, quantitative where cost or schedule data exists.
  6. Score: the combined rating that drives prioritisation and reporting order.
  7. Existing controls: what is already in place to limit the risk, stated as fact, not aspiration.
  8. Planned actions: the next concrete step, with a deadline attached.
  9. Status: open, in progress, escalated or closed.
  10. Next review date: mandatory, never left blank.
  11. Escalation level: whether the risk sits at project, programme or board level.

Writing a tight risk statement is the detail most registers get wrong. "Supplier risk" tells nobody anything; "a single-source supplier for steel fixings may delay the frame-up phase by four to six weeks if their contract is not renewed" gives an owner something to act on.

Who owns and oversees the risk register

A register only works when responsibility for it is distributed correctly, not concentrated in one overworked risk manager. The Institute of Internal Auditors' Three Lines Model gives a clean way to map this: operational teams identify and own risks in the first line, risk and compliance functions provide oversight in the second, and internal audit provides independent assurance in the third. The model also makes a specific point worth repeating: the register custodian should be operationally neutral, responsible for data quality and reporting rather than for owning individual risks.

  • Risk owner: accountable for the risk itself, updates status and actions.
  • Register custodian: maintains data quality, consistency and the reporting calendar.
  • Governance committee: reviews escalated risks and challenges weak mitigation plans.
  • Executive sponsor: approves closure of major risks and allocates resource where needed.
  • Internal audit: tests whether the register and its controls actually work as described.

A short project RACI matrix applied to the register clears up most confusion: owners update entries, governance committees approve closure, and only the executive sponsor or board decides when a risk is serious enough to escalate upward.

Keeping the register usable: maintenance and lifecycle rules

Registers become unusable the same way inboxes do: everything gets added, nothing gets removed. The fix is a set of rules for what stays and what goes. Routine operational issues and known control deficiencies belong in standard operating procedures, not the register; the register is for genuine uncertainty with a material consequence, not for logging every snag a team encounters.

  • Archive risks once their trigger conditions no longer apply, rather than leaving them open indefinitely.
  • Tag entries by root cause so recurring patterns become visible across projects.
  • Require evidence before a status change, particularly before marking a risk closed.
  • Run a scheduled triage session, monthly for active programmes, to challenge stale entries.
  • Capture a short rationale whenever a score changes, so the audit trail explains the movement.

Automation helps enforce these rules rather than replace them: mandatory review-date fields, reminder emails when a date lapses, and version history on every entry all stop a register from quietly decaying between audits.

Pro Tip: Set the system to lock a risk's status field until a review date is logged, so nobody can mark an entry closed without leaving evidence behind.

Risk status locked until review evidence

Setting review cadence, reporting and KPIs

Cadence should match the level of decision being made. Operational teams benefit from weekly or fortnightly check-ins on active risks, programme boards from a monthly review, and executive or board-level reporting typically works well on a quarterly cycle, with ad hoc triggers whenever a score crosses an agreed threshold.

  • Operational reviews: weekly or fortnightly, focused on action progress.
  • Programme-level reviews: monthly, focused on emerging patterns and resourcing.
  • Executive and board reviews: quarterly, focused on the top risks and residual exposure.
  • Ad hoc escalation: triggered immediately when a risk's score crosses the agreed threshold.

Board and executive reports work best when they stay short: a small set of top risks by score, with trend directions, residual exposure after controls, overdue actions, and any concentration of risk sitting with one owner or one part of the portfolio.

The COSO ERM framework makes the case for this shift explicitly: registers should report trends and concentrations of risk rather than a static list, which is why time to close actions, percentage of overdue items, change in residual score and number of escalations are the KPIs worth tracking over raw risk counts. For consolidating exposure across a portfolio before it reaches the board, a structured portfolio risk analysis approach helps surface concentration that a simple list would hide.

A practitioner checklist for fast governance fixes

Most registers do not need a rebuild. They need two short interventions.

  1. 72-hour triage: confirm a named owner for every top-scoring risk, set a next review date for each, and check that cited controls actually have supporting evidence.
  2. 30-day fixes: standardise the field set across projects, apply a RACI to register tasks, switch on automated review reminders, and escalate any portfolio-level risk to the governance board.

This sequence tends to produce visible improvement fast because it fixes accountability and cadence before it touches scoring methodology or tooling. For a fuller view of what "good" looks like at each maturity stage, a governance maturity model is worth reading alongside this checklist.

Pro Tip: Run the 72-hour triage before any software migration. Moving a disorganised register into a new tool just produces a tidier mess.

Why governance-first registers cut audit friction

The two failure modes I see most often are registers with no named owner and registers padded with operational noise that should sit in procedures instead. Both make audits slower and boards less trusted in what they are being shown. For more on managing this in live delivery, see our guide to risk management in project delivery.

— Peter

How Keystone can help you put this into practice

If you recognise your own register in the problems above, that gap between a tidy spreadsheet and a register that actually drives decisions is exactly what our consultancy work closes. Keystone integrates directly with your team to redesign governance structures and field sets, and our Videra PM platform turns the blueprint in this article into mapped, auditable workflows with built-in review reminders and board-ready reporting.

Keystoneconsulting

  • A governance health check identifies where your current register breaks down against the Three Lines model.
  • A pilot on one programme shows how standardised fields and automated cadences perform before wider rollout.
  • A short demo of Videra PM shows how the fields, owners and review dates in this article map onto a live workspace.

Get in touch through our consultancy services page to book a health check or arrange a demo.

Sources

FAQ

What are the three components of a risk register?

Most registers need at minimum a clear risk statement, an owner and a score based on likelihood and impact. Practical frameworks such as those referenced by GSA's risk management guidance add controls, planned actions and a review date to make the entry auditable.

What does risk governance mean?

Risk governance is the structure of rules, roles and reporting lines that decide how an organisation identifies, owns and escalates risk. ISO 31000 frames it as part of leadership and governance rather than a separate compliance exercise.

What are the 5 components of ERM?

Definitions vary by framework, but the COSO ERM framework organises enterprise risk management around governance and culture, strategy and objective-setting, performance, review and revision, and information and communication. Each component ties risk activity back to organisational objectives rather than treating it as a standalone process.

What are the 5 pillars of risk management?

There is no single agreed list of five pillars across frameworks, so treat any version you encounter with caution. The consistent themes across COSO and ISO 31000 are leadership commitment, integration with strategy, structured identification and assessment, defined accountability, and continuous monitoring and reporting.

How often should a risk register be reviewed?

Cadence should match the decision level: operational risks benefit from weekly or fortnightly check-ins, programme-level risks from a monthly review, and board reporting typically works on a quarterly cycle with ad hoc triggers when a score crosses an agreed threshold.