What this is
What is an annual risk register review?
What is an annual risk register review?
It is a scheduled re-test of every risk already on the register, not a hunt for new ones. Each entry is examined to see whether its likelihood and consequence still hold, whether the controls named against it still exist, and whether those controls still work. The output is a change record: scores that moved, risks closed, risks added, and the reason for each.
What is residual risk, and why review it rather than inherent risk?
Residual risk is what remains once the controls work as designed. Inherent risk barely changes year to year because the hazard does not change. Residual risk moves whenever a control degrades, is removed, or is bypassed, which is what a review exists to catch. This template scores change in residual risk and treats an increase as bad.
What is the difference between a control being in place and a control being effective?
In place means the control exists and can be pointed at: the guard is fitted, the procedure is published, the permit system runs. Effective means it actually reduces the risk under real conditions, which requires evidence such as a verification result or an inspection record. This template asks the two separately because a site can pass the first and fail the second.
Scope
When is an annual risk register review required?
This is a periodic health check on an existing register. It re-examines what has already been assessed, and is not the place to work out a new hazard from first principles.
Use this template when
- The annual cycle has come round and the register needs re-testing entry by entry
- A major incident, acquisition, or process change has invalidated a block of existing ratings at once
- An audit or management review has asked for evidence that the register is current
- Ownership has churned and a large number of risks now sit against people who have left
- You need a defensible count of risks increased, decreased, closed and added over the period
Do not use it for
- Risk Assessment, which is where a single risk is assessed in full for the first time and the entry on the register is created.
- Change Risk Review, which handles a specific proposed change to plant, process or organisation rather than the whole register on a cycle.
- Critical Control Verification, which tests one named control in the field to prove it performs, and produces the evidence this review consumes.
- High Potential Risk Review, which goes deep on a small set of fatal-risk entries instead of covering the register broadly.
- Bowtie Analysis, which maps threats, barriers and consequences for a single major hazard and is a modelling exercise, not a periodic check.
Compliance mapping
Which ISO 31000 cl.6.6 requirements does this satisfy?
ISO 31000 treats monitoring and review as a continuing part of the process, not an annual formality. The mapping shows where each obligation lands.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 31000:2018 cl.6.6 | Monitoring and review is planned, its results recorded, and it covers all parts of the risk management process | Register health |
| ISO 31000:2018 cl.6.6 | Review confirms whether assumptions behind existing risk analysis still hold | Risks reviewed |
| ISO 31000:2018 cl.6.4.3 | Risk analysis accounts for the effectiveness of existing controls, not merely their presence | Risks reviewed |
| ISO 31000:2018 cl.6.5 | Treatment is selected and its implementation assigned where evaluation shows action is required | Result |
| ISO 31000:2018 cl.6.7 | Risk management activity and its outcomes are recorded and reported to those accountable | Result |
| ISO 31000:2018 cl.5.4.4 | Authorities, responsibilities and accountabilities for risk are assigned to named people | Header |
What it does not cover
- A cycle where every score is unchanged and no reason is recorded, which cannot demonstrate that assumptions were re-tested and reads as a signature exercise to any auditor.
- Reviewing part of the register and reporting the cycle as complete, which is why Review Coverage Percent is a scored field rather than a statistic buried in a report.
- Marking Controls Still In Place as Yes with no verification evidence behind it, which conflates the existence of a control with its performance and defeats ISO 31000 cl.6.4.3.
- Recording an incident against a risk without re-scoring that risk, which leaves a rating standing that the site has already disproved.
- Setting Programme Action Required to Yes and leaving CAPA ID and Action Owner blank, which produces a finding with nobody accountable for closing it.
Global
Annual Risk Register Review requirements by country
ISO 31000 is guidance, not law. The duty to keep a risk picture current comes from national health and safety legislation, and it is worded differently in each of the places this template is most used.
Management of Health and Safety at Work Regulations 1999, reg.3
The assessment must be reviewed if there is reason to suspect it is no longer valid, or if there has been a significant change.
There is no statutory annual interval in Great Britain. The duty is triggered by suspicion and by change, so an annual cycle is a way of periodically manufacturing that suspicion, not of discharging the duty on a timer.
Model WHS Regulations, reg.38
Control measures must be reviewed and revised when a control is not working effectively, before a change, if a new hazard is identified, or if a health and safety representative requests it.
Australia ties review to the control, not the assessment document. A failed Controls Still Effective answer is itself a statutory trigger, which is why that field is separated from Controls Still In Place.
Council Directive 89/391/EEC, Article 6(3)
The employer must evaluate risks and adapt preventive measures to take account of changing circumstances, aiming to improve existing situations.
The framing is explicitly directional: measures should improve, not merely persist. Overall Direction, with the counts of risks increased against decreased, is what evidences that direction.
How to complete it
How to complete an annual risk register review, step by step
Most of this template is arithmetic. Four judgements decide whether the completed record would survive scrutiny.
Reviewed This Cycle and Review Coverage Percent only mean something if the site agrees what reviewed means. A defensible rule is that an entry counts only where Score Still Valid, Controls Still In Place and Controls Still Effective all carry an answer from someone who looked at the work. Counting entries merely opened and closed inflates the percentage and destroys the one number management review relies on.
Pass, Partial and Fail are conclusions about performance, so decide in advance what evidence licenses each. Verification results, inspection records and maintenance history support a Pass; the absence of complaints does not. Where no evidence exists, Partial is the honest answer, and more useful than an unsupported Pass because it names the gap without overstating the failure.
Incidents Since Last Review scores Yes at zero deliberately. The judgement is whether the event was on the pathway the risk describes. If it was, the rating has been falsified by the site and Score Changed should read Yes with a New Residual Band and a Reason For Change, whatever the reviewer's instinct about frequency. Case ID ties the review entry back to the investigation so the two records cannot drift apart.
Programme Action Required is not a summary of individual findings. It asks whether the register itself, or the way the site manages risk, needs fixing. Widespread missing owners, a large overdue count, or Deteriorating in Overall Direction are programme problems even when no single risk failed. Answering Yes commits the site to a CAPA ID, an Action Owner and a Priority; High scores zero because it signals the register is in trouble.
What auditors find
Most common annual risk register review findings
These are the findings that recur when a register review is audited rather than filed.
| Finding | Clause | What fixes it |
|---|---|---|
| Coverage reported as complete while Risks Overdue For Review is non-zero | ISO 31000:2018 cl.6.6 | Reconcile the two numbers before signing. Where overdue entries cannot be reviewed in the cycle, record the cycle as partial and raise a programme action rather than reporting completion. |
| Score Changed reads Yes but New Residual Band and Reason For Change are empty | ISO 31000:2018 cl.6.4.4 | Both fields are conditional on Score Changed and exist to carry the justification. Make them required in your copy so a movement cannot be recorded without its rationale. |
| Controls Still In Place marked Yes on controls that were removed during a plant change | ISO 31000:2018 cl.6.4.3 | Cross-check the entry against change records for the period. Where the control was superseded, record No and treat the replacement as a new control needing its own effectiveness evidence. |
| Risks With No Named Owner recorded but never actioned | ISO 31000:2018 cl.5.4.4 | Treat any non-zero owner gap as an automatic Programme Action Required, with the assignment of owners as the CAPA deliverable and a named Action Owner to close it. |
| Reported To Management Review left as No with no follow-up | ISO 31000:2018 cl.6.7 | Reporting is the point of the cycle. If the review closes before the management review sits, hold the record open until it is tabled, or record the date it will be. |
| Next Review Due set twelve months out regardless of what the cycle found | ISO 31000:2018 cl.6.6 | Where Overall Direction is Deteriorating or several controls failed, shorten the interval. A fixed annual date on a worsening register is the frequency ignoring its own result. |
Case in point
Case in point: the register that had been right for six years
A multi-site manufacturer ran its register review every January without interruption, reporting 100 per cent coverage across 214 risks. In the sixth year an auditor compared the register against the version from three years earlier and found 190 of the 214 residual ratings identical, including entries covering a line that had since been substantially re-engineered.
The reviews were genuine in that people opened every entry. What was missing was any requirement to reconstruct the rating or point at evidence for the controls. Once the site split the control question into in place and effective, and made an incident force a re-score, the next cycle moved 31 ratings, closed 12 risks and raised 4 carried at the wrong band. Overall Direction was recorded as Deteriorating, the first accurate statement the register had produced.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- SAF-065
- Archetype
- Review
- Record ID
- RREV-2026-000
- Scoring
- Change in residual risk
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 31000 cl.6.6
- Links
- Links Risk Assessments
- Tags
- Risk, Governance
- Sections
- 4
- Fields
- 38
- Follow up fields
- 6
- Repeating sections
- 1
- Links out
- 3
Header
8 fieldsReview ID*
Auto sequence. Format RREV-2026-0000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Review Period From*
Review Period To*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Reviewed By*
Area Managers Involved*
Register health
5 fieldsRisks On Register*
Reviewed This Cycle*
Review Coverage Percent*
Risks Overdue For Review*
Risks With No Named Owner*
A risk without an owner is not being managed.
Risks reviewed
Repeats10 fieldsRisk Assessment
Risk ID
Format RSK-2026-00000.
Links to FDN-012 Risk ID
Score Still Valid*
- Yes3 pts
- Partly1 pt
- No0 pts
Controls Still In Place*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Controls Still Effective*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Score Changed*
New Residual Band
Reason For Change
Incidents Since Last Review*
An incident on a risk rated low means the rating was wrong.
- No3 pts
- Yes0 pts
Case ID
Thread key
Result
15 fieldsRisks Increased*
Risks Decreased*
Risks Closed*
New Risks Added*
Overall Direction*
- Improving3 pts
- Stable2 pts
- Deteriorating0 pts
Programme Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
- N/Aexcluded from denominator
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Reported To Management Review*
Next Review Due*
Reviewed By*
Signature*
Site Manager*
Second Signature*
SAF-065 · record IDs look like RREV-2026-000 · Links Risk Assessments
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The review is a day's work. Keeping the register worth reviewing is a year's work, and it is spread across the systems that hold the controls.
Holds the register and the underlying risk assessments, tracks which entries are overdue, and surfaces owner gaps and coverage figures before the cycle starts rather than during it.
Supplies the maintenance and inspection history behind engineered controls, so Controls Still Effective can be answered from asset evidence rather than from the reviewer's impression of the plant.
Carries the CAPA raised when the review finds a programme-level problem, holds its owner and due date, and keeps it visible at management review until closed.

Assembles the cycle: pulls incidents on each risk pathway, flags entries where the rating contradicts what happened, drafts the change summary, and holds every write for approval.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Annual Risk Register Review definitions and key terms
- Residual risk
- The risk that remains after existing controls are taken into account. The figure this template tracks for movement, where an increase is treated as a bad outcome.
- Risk register
- The standing record of identified risks with their ratings, controls and owners. It is a live artefact, and its value decays as soon as it stops being re-tested.
- Control effectiveness
- Whether a control actually reduces risk under real operating conditions, evidenced by verification or inspection, as opposed to whether it merely exists.
- Review coverage
- The proportion of register entries genuinely re-tested in a cycle. Scored here as Review Coverage Percent, because partial coverage is the usual failure.
- CAPA
- Corrective and preventive action. The record raised when the review concludes the register or the risk process needs fixing, carrying an owner and a priority.
FAQ
Frequently asked questions about annual risk register review
Does ISO 31000 actually require an annual review?+
No. ISO 31000 cl.6.6 requires monitoring and review to be planned and its results recorded, but sets no interval. Annual is a reasonable default for a whole register; the standard expects the frequency to match how quickly the risk picture changes.
Do we have to review every risk in one cycle?+
Not necessarily, but be honest about it. A rolling programme covering a quarter of the register each quarter is defensible. What is not is reporting a cycle complete while Review Coverage Percent shows partial coverage and Risks Overdue For Review is non-zero.
Who should sign the review?+
The template requires two signatures: the reviewer, and the site manager. That split matters because the reviewer is attesting to the technical judgement while the site manager is accepting the resulting risk position, including any risks left at High or Critical.
What happens if a risk gets worse during the review?+
Score Changed is set to Yes, a New Residual Band is chosen, and Reason For Change records why. If enough entries move upward, Overall Direction reads Deteriorating, which should prompt Programme Action Required and a shorter Next Review Due date.
How does this relate to individual risk assessments?+
The Risks reviewed section links each entry to a Risk Assessment record and carries its Risk ID, so the review is a layer over the assessments, not a replacement. Where a rating changes here, update the underlying assessment to match rather than leaving it contradicting the register.
Can the template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to Risk Assessment and CAPA records travel with it. Most sites run it unmodified for one cycle, then tighten the required flags on the conditional justification fields once they see where their reviewers cut corners.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Risk Assessment
The single risk assessment used across the whole business
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
More in Risk Studies
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
Pre-Task Risk Assessment
A short check done by the crew right before work starts, covering what has changed today
Task Risk Assessment
A fuller assessment of a task, its hazards and its controls, using the shared risk method
Hazard Identification Study
A structured search for hazards across an area, process or new installation
Bowtie Analysis
Maps a major hazard from its causes through to its consequences, and shows which barriers sit in between
What If Study
A guided team discussion asking what could go wrong at each stage of a process

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 31000:2018 — Risk management, cl.6.4 to cl.6.7
- ISO 45001:2018 — Occupational health and safety management systems, cl.6.1.2 and cl.9.3
- Management of Health and Safety at Work Regulations 1999 (UK), reg.3
- Model Work Health and Safety Regulations (Australia), reg.38
- Council Directive 89/391/EEC — Framework Directive on safety and health at work, Article 6
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.