Template

Risk Register

Track the risks you know about, who owns them, and what you decided to do — including accepting them.

Intended audience
Program owners
Difficulty
Intermediate
Estimated time
35 minutes
Access
Free
NIST CSF
ISO 27001
NIST SP 800-30
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Capture the columns needed to describe a risk, its likelihood, and its impact.
  • Distinguish inherent risk from residual risk after controls are applied.
  • Record a treatment decision — mitigate, transfer, avoid, or accept — for every risk.
  • Document risk acceptance with a named owner and a revisit date.

Columns to capture

  • Risk identifier and short description.
  • Affected systems or data.
  • Likelihood and impact.
  • Inherent rating and rating after controls.
  • Treatment decision: mitigate, transfer, avoid, or accept.
  • Owner, target date, and review date.

Accepting risk

Acceptance is a valid decision when it is written down, owned by a named person, and revisited on a date.

Key takeaways

  • A risk register needs both an inherent rating and a rating after controls, so the effect of mitigation is visible.
  • Every risk needs a treatment decision recorded: mitigate, transfer, avoid, or accept.
  • Accepting a risk is a legitimate decision, but only when it is written down, owned by a named person, and given a revisit date.
  • Assigning an owner and target date to each risk keeps the register from becoming a static list nobody acts on.
  • The register should tie each risk to the specific systems or data it affects, not stay abstract.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.

Matched on shared frameworks, topics, and program packs.

Exercise

Practice Writing Policy Statements

Turn vague intentions into policy statements that are testable and enforceable.

Intermediate
20 min
Free
NIST CSF
ISO 27001

Published · v1.0.0 · 2026-08-01

Guide

Preparing for Vendor Questionnaires

How to answer customer security questionnaires quickly, accurately, and without overpromising.

Intermediate
12 min
Free
SOC 2
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Annual Review Checklist

The once-a-year pass that keeps a program from quietly going stale.

Beginner
30 min
Free
NIST CSF
ISO 27001

Published · v1.0.0 · 2026-08-01

Template

Information Security Policy

The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.

Intermediate
45 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Guide

Building a Security Program from Scratch

A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.

Beginner
14 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intermediate
15 min
Free
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.