Whole risk assessment process gathers lots of the data, like description of the risk, date on which we identified, probability of occurrence, effects on objectives etc.
And when you plan your risk response once again you will have lots of data regarding that risk like what response or actions are planned, completion of actions, owner of that risk etc.
So basically risk register is the list of data you gathered for each individual risk. Risk register have predefined format so that every risk will be registered in a specific format.
At the end of the project you can learn from that also, like what risks you have identified and what actually happened, whatever actions we planned was actually implemented or not etc.
In the whole organization, there can be different risk registers like, project risk register, operational risk register, strategic risk register etc.
The risk register is a very important and practical risk management tool that all companies should have these days. It takes several days, if not weeks, to produce, and needs to be reviewed and updated regularly – mainly annually (in conjunction with corporate governance guidelines).
The risk register is often laid out in the form of a tabular document with various headings:
(1) The risk title – stating what the risk might be.
(2) The likelihood of the risk – possibly measured numerically if a scale has been set e.g. 1 is unlikely, 5 is highly likely.
(3) The impact of the risk should it arise. Again this might be graded from, say, 1 (low impact) to 5 (high impact).
(4) The risk owners name will be given – usually a manager or director.
(5) The date the risk was identified will be detailed.
(6) The date the risk was last considered will be given.
(7) Mitigation actions should be listed i.e. what the company has done so far to reduce the risk. This might include training, insurance, further controls added to the system, etc.
(8) An overall risk rating might be given e.g. 1–10, so that management can immediately see which risks are the ones they should be concentrating on.
(9) Further actions to be taken in the future will be listed (if any).
(10) The ‘action lead’ name will be detailed i.e. who is responsible for making sure that these future actions are implemented.
(11) A due date will be stated – by when the action has to be implemented.
(12) A risk level target might be given i.e. a score lower than that given in step 8 above. This might mean that by implementing a control, the risk rating is expected to lower from, say, 8 to, say 2 (the target risk level).
(1) Loss of personal data i.e. unsecured use of mobile devices could result in personal identifiable information being lost, stolen or unauthorised access gained.
(2) Likelihood = 3
(3) Impact = 5
(4) Risk owner = Mike Smith (IT manager)
(5) 1.1.12
(6) 2.2.14
(7) Staff receives training every 2 years which highlights the risks. All laptops are encrypted. Regular audits are undertaken. Any incidents are reported to the Audit Committee.
(8) Overall risk rating = 7
(9) Encryption technology to be implemented which meets industry standard.
(10) Mike Smith
(11) 31.7.14
(12) Risk level target = 3
This lesson is waiting for its secure Vimeo video.