← Belian Advisory Get in touch
Risk Assessment

The Risk Register Nobody Reads (And How to Fix It)

Almost every business we work with already has a risk register. Somebody built one at some point — for an audit, a customer questionnaire, an investor's due diligence checklist. It lives in a shared drive, usually as a spreadsheet with forty or fifty rows, colour-coded red, amber, green. It was current the week it was created.

Nobody has opened it since.

That's not a discipline problem. It's a design problem. Most risk registers are built to satisfy whoever asked for one, not to actually help anyone make a decision — and a document built for that purpose will always end up ignored, no matter how conscientious the person who filled it in was.

What a risk register is actually for

A risk register earns its keep by changing what someone does. It should sit in front of the person who decides where budget goes, what gets fixed first, and what gets accepted as a known trade-off — and it should make that decision easier, not just documented.

That's a much narrower job than most registers try to do. A risk register isn't a complete inventory of everything that could possibly go wrong — that's a different exercise, and trying to make one document do both jobs is usually where things start going sideways.

Why the spreadsheet in your drive isn't working

A few patterns show up in almost every risk register we're handed to review.

It's too long to be useful. Fifty or eighty rows feels thorough. In practice it means nobody can hold the actual priorities in their head, so the document stops functioning as a decision tool and becomes an archive nobody visits.

The scoring is theatre. A 5×5 likelihood-times-impact matrix looks rigorous, but if the numbers going in are guesses dressed up as precision, the output is a guess dressed up as a ranking. People stop trusting a score they know was made up on the spot, and once they stop trusting it, they stop reading it.

Ownership exists on paper, not in practice. There's a column for "owner," someone's name is in it, and nothing happens next. No one follows up when the owner hasn't touched their risks in six months, because nobody's actual job is to check.

Nothing is tied to a real decision. The register lists a risk. It doesn't say what changes because of it — what gets funded, what gets deferred, what a board or a customer is actually being told. A risk sitting on a list with no consequence attached might as well not be written down.

A risk register that nobody acts on isn't a risk management tool. It's a liability with extra steps — proof you knew, and did nothing.

What actually gets read

The registers that survive contact with a busy leadership team tend to share the same handful of traits, and none of them require more sophistication — usually less.

Short enough to hold in your head. Ten to fifteen real risks, not fifty theoretical ones. If something hasn't moved or mattered in two review cycles, it either gets resolved, accepted, or removed — it doesn't get to sit there forever as dead weight.

Scored simply, and consistently. High, medium, low is honest about the level of precision you actually have. A five-point matrix that nobody calibrated the same way twice is worse than a three-point scale everyone actually agrees on.

Owned by someone who's asked about it. Ownership only means something if someone else checks in. The follow-up is what makes the ownership column real — not the name sitting in the cell.

Reviewed on a cadence tied to how the business already runs. Not "quarterly" on a calendar reminder nobody opens — folded into a meeting that was already happening, like a monthly leadership sync or a board update, so reviewing it doesn't require anyone to carve out new time.

Written for the room it's read in. A risk register a board sees should read like a short list of things they need to weigh in on — not a raw export of every finding an assessment turned up. Translate the assessment's detail into the handful of things that actually need a decision.

Where to actually start

If you're staring at an old spreadsheet right now, the fastest fix isn't a rebuild. Pull out the five to ten risks that would genuinely change a decision if they materialised — the ones a board member would actually want to know about. Everything else either gets folded into that shortlist or set aside as accepted, documented, and left alone. Then put a real date on the calendar, attached to a meeting that already exists, where those risks get looked at again.

That's a smaller document than what you probably have now. It's also the first version of it anyone's likely to actually open twice.


Belian Advisory builds risk registers sized to actually get used in decision-making — not filed away until the next audit. If you want a straight look at whether yours is doing its job, get in touch.