Risk register template
A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.
Risk3 Sept 20263 min readUpdated 5 Sept 2026
On this page
risk-register.xlsx · 13 kBLicensed CC BY 4.0
What this is
A working information security risk register: one sheet for the rows, one for the anchored scales and acceptance criteria, and one for the licence and the standing rules. It is the artefact produced by the method in The risk register other people trust, and it supports one decision per row: treat the risk, or accept it, with a name and a date. A register that records no decision is a list, and a list is not evidence.
How to use it
- Fill the Scales sheet first. Consequence and likelihood both run 1 to 5, and each value carries a sentence-level anchor rather than an adjective. Replace every anchor with wording the organisation's own management forum will recognise. See the playbook, section 3.1.
- Have management approve the acceptance criteria on the same sheet: who may accept each level, for how long, and what record is required. See the playbook, section 3.7.
- Delete the three example rows, then fill the Register sheet left to right. The Fields table below names each column; the playbook, sections 3.3 to 3.5, explains the thinking.
- Read Inherent level off the published lookup on the Scales sheet, never from multiplying likelihood by consequence.
- Take the two mandatory decisions on every row. Treatment option is exactly one of modify, retain, avoid or share; Accepted by and Accepted on are filled together or not at all.
- Close the row. Review date is mandatory, and Status moves through open, planned, in progress, accepted and closed.
Delete a column only if the organisation has no use for it, and record that on the Read first sheet.
What good looks like
Six of the sixteen columns, from the rows shipped in the workbook.
| ID | Risk statement | Likelihood | Consequence | Treatment | Accepted by / on |
|---|---|---|---|---|---|
| R-001 | Bought credentials used to sign in to the customer portal and export personal data | 4 | 4 | Modify | — |
| R-002 | A hosting region unavailable past the agreed recovery time stops the ordering service | 2 | 4 | Retain | Revenue objective owner / 2026-08-18 |
| R-003 | An unreviewed production access change removes a control the Statement of Applicability records as implemented | 3 | 3 | Modify | — |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Risk statement | yes | Source, event, consequence, in one sentence | A missing control written as a risk |
| Asset or objective | yes | What the consequence lands on | A class too broad to score |
| Likelihood, Consequence | yes | The anchored 1-5 values | Scoring against undefined adjectives |
| Inherent level, Residual level | house rule | The level before and after existing controls | Multiplying the two scores |
| Treatment option, Control refs | yes | The decision, and the link to the Statement of Applicability | A blank option, or references that do not reconcile |
| Risk owner, Accepted by, Accepted on | yes when retaining | Who holds the risk, who accepted it, and when | An acceptance with no name, date or expiry |
| Review date, Status | yes | When the row is next examined, and where it stands | A date that passes with no review logged |
Download
- File:
risk-register.xlsx(xlsx, 13 KB) — three sheets: Register, Scales, Read first. - Markdown variant: the same three tables in plain markdown, at
content/templates/assets/_risk-register.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-03. No personal data or organisation names; the example rows are invented.
Related
- Playbook: The risk register other people trust — the method, and its section 7 clause mapping for every column.
- Playbook: Risk appetite and criteria that decisions can use — where the Scales sheet comes from.
- Template: Risk acceptance record — the record behind an Accepted by pair.
References
- ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en
[1](#grcide-source-1) - ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en
[1](#grcide-source-1) - ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en
[1](#grcide-source-1)
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO OBP · verified 2026-09-03