Someone's handed you a spreadsheet called a "risk register" and you're apparently meant to have opinions about it. Don't panic, it's a simpler thing than it looks.

A risk register is just an organised list of what could go wrong, how likely each thing is, how bad it would be, and who's dealing with it. That's it. Strip away the formatting and it's a to-do list for trouble.

What the columns usually mean

The risk. A plain description of what could happen. "A staff member falls for a phishing email and their account is compromised."

Likelihood. How probable it is, usually low, medium or high.

Impact. How much it would hurt if it happened, also low, medium or high.

Rating. Likelihood and impact combined. A thing that's both likely and damaging is a "high" and deserves attention first; something unlikely and minor can wait.

Owner. The person responsible for doing something about it. A risk with no owner is a risk nobody's actually handling.

Treatment (or plan). What you're doing about it: fixing it, reducing it, insuring against it, or consciously accepting it.

Status. Where that plan is up to.

The three numbers your board actually cares about

  1. How many high risks do we have right now? The headline number.
  2. How many of them have an owner and a plan? A high risk nobody's touching is the one that bites.
  3. Is that number going up or down? Trend matters more than any single figure. A board wants to see the worst risks shrinking on purpose.

Everything else is useful detail, but those three tell the story. And here's the mindset shift: a good risk register isn't about having zero risks, that's impossible for anyone. It's about knowing what your risks are, and deliberately shrinking the worst ones over time.

If your register is a bit of a mess, or you don't have one yet, that's usually where we start with a new client.

Charities can also grab the ACNC's free information asset register and cyber security checklist templates as a starting point.