What this is
What makes a risk 'enterprise' rather than operational?
What makes a risk 'enterprise' rather than operational?
An enterprise risk threatens the organisation's ability to meet its objectives, not the completion of a single task. A forklift near-miss is operational and belongs on a site risk assessment. A single-source supplier whose failure would stop production across every site is enterprise, because it needs senior sign-off on the response.
What is the difference between inherent and residual risk?
Inherent risk is the rating before any existing control is credited — the raw exposure. Residual risk is what remains after the controls actually in place and verified are taken into account. The gap between the two is the control effectiveness claim, and it is the number auditors and boards test hardest.
How does risk appetite relate to this register?
Risk appetite is the amount and type of risk the organisation has decided to accept, set out in a separate appetite statement. This register applies that appetite to named risks and records whether the residual position sits inside it, is marginal, or breaches it. Without a stated appetite, 'within appetite' is a guess dressed up as an assessment.
Scope
When is an enterprise risk register required?
This register sits inside a larger governance programme. Using it for work that belongs to a neighbouring template produces a document nobody can report on with confidence six months later.
Use this template when
- The workspace is being set up for the first time and a top-level risk register needs to exist before management review can function
- A new strategic, financial, supply-chain or multi-site risk has emerged and needs a named owner above the level of a single team
- A previously accepted risk has changed materially — a new control has failed, a supplier has changed, a regulatory threat has escalated — and the residual rating needs revisiting
- Quarterly review is due and the register needs its ratings, treatment plans and appetite position refreshed before it goes to senior management
- Management review needs a single, current view of the risks that could prevent the organisation meeting its stated objectives
Do not use it for
- Risk Appetite Statement, which sets how much risk is acceptable per domain — do not invent appetite thresholds inside individual register rows.
- Risk Acceptance Record, which documents a deliberate decision to accept a specific risk rather than treat it — a 'Tolerate' entry here is not the same as a signed acceptance.
- Bow Tie Analysis Record, which maps threats, the top event, consequences and barriers for a single major hazard — this register holds the summary rating, not the barrier-level analysis.
- Operational or task-level risk assessments, which belong in the workspace that owns the process and should feed this register only once judged enterprise-scale
- Management Review Action Log, which tracks actions raised from review meetings, once this register has stated the risk position
Compliance mapping
Which ISO 31000 cl.6.4 requirements does this satisfy?
ISO 31000 describes risk management as a process, and the sections below map each stage onto where it is actually captured in the form.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 31000 cl.6.4.2 | Risk identification — find, recognise and describe risks in terms that support later analysis | Risks |
| ISO 31000 cl.6.4.3 | Risk analysis — understand the nature of the risk, including likelihood, consequence and the effect of existing controls | Risks |
| ISO 31000 cl.6.4.4 | Risk evaluation — compare the analysis result against the organisation's risk criteria and appetite to decide if treatment is needed | Risks |
| ISO 31000 cl.6.5 | Risk treatment — select and implement an option to modify the risk, and record who resources it | Risks |
| ISO 31000 cl.6.6 | Monitoring and review — of both individual risks and the effectiveness of the overall risk management framework | Register quality |
| ISO 31000 cl.6.7 | Recording and reporting — through mechanisms that support decision-making and are communicated to stakeholders | Outcome |
| ISO 31000 cl.6.2 | Communication and consultation — with those accountable for the risk and those affected by it, at the appropriate level of seniority | Governance |
What it does not cover
- Risks On Register, which is high but every entry is task-level rather than enterprise-scale, so the count reflects scope creep rather than genuine coverage.
- Control Effectiveness Assessed, which is marked Yes across the board with no evidence of when or how effectiveness was tested, rather than assumed from the control existing on paper.
- Within Risk Appetite, which is answered without a Risk Appetite Statement anywhere in the workspace to compare the residual rating against.
- Treatment Plans Resourced, which is marked Yes for a Treat or Transfer approach with no budget, owner capacity or named third party committed.
- Reported To Management Review, which is marked Yes while that period's Management Review Record shows no risk item on its agenda.
Global
Enterprise Risk Register requirements by country
ISO 31000 is guidance, not a certifiable standard, so the register's real teeth come from governance and disclosure regimes that expect one to exist and be current.
UK Corporate Governance Code (FRC), Provisions 28–29
The board must state it has assessed the company's principal and emerging risks, including those threatening its business model or solvency, and describe how they are managed.
This register is the working evidence behind that statement, expected to show named owners, inherent/residual ratings and a treatment plan, not a narrative written after the fact.
SEC Regulation S-K Item 106; COSO ERM framework
Public companies must describe their processes for assessing material risks and name the board committee responsible for oversight, with cybersecurity risk called out under Item 106.
Under a US-listed parent, this register is the artefact showing the process runs on a cycle, rather than being reconstructed at year end for disclosure.
ISO 31000:2018 cl.6; ISO 9001/45001/14001 cl.6.1
ISO 31000 carries no certification itself, but its process is the reference model inside every certifiable management system's clause 6.1 risk requirement.
A certification auditor on any linked standard expects this identify-analyse-evaluate-treat-monitor process to be traceable, even though this register is not itself audited against ISO 31000.
How to complete it
How to complete an enterprise risk register, step by step
Filling in fields is mechanical. The four calls below decide whether a register is defensible in front of a board or quietly decorative.
Every organisation draws the operational/enterprise line differently. Set it explicitly — by consequence severity, sites affected, or threat to a stated objective — and apply it consistently, or the register drifts wider every quarter.
Marking a control Strong because it exists on paper is not the same as marking it Strong because someone checked it operated last quarter. The residual rating is only as honest as this judgement.
The escalation route from operational registers needs a trigger, not a feeling — a rating threshold, a repeat occurrence, or a change in scale. That choice decides whether this register stays current or stale.
Within Risk Appetite has a middle answer, Marginal, and that is where most governance failures start — neither the urgency of a breach nor the comfort of clear acceptance. Deciding who reviews marginal entries, and how often, is left to you.
What auditors find
Most common enterprise risk register findings
These recur across registers that look complete on the surface but do not hold up once a specific risk is traced end to end.
| Finding | Clause | What fixes it |
|---|---|---|
| Every risk carries the same handful of generic owners rather than named individuals accountable for that specific risk. | ISO 31000 cl.6.2 | Assign one named owner per risk who can speak to its status without escalating the question, and revisit ownership at every quarterly review. |
| Inherent and residual ratings are identical across most rows, suggesting controls were never credited or the rating was set once and never re-derived. | ISO 31000 cl.6.4.3 | Require a stated control and its assessed effectiveness before any gap is entered — an unexplained gap should read as a data quality flag, not a result. |
| No Risk Appetite Statement exists in the workspace, so Within Risk Appetite is answered against an unstated, personal threshold. | ISO 31000 cl.6.4.4 | Stand up the Risk Appetite Statement first, or flag every appetite answer here as provisional until it exists. |
| Treatment Approach is set to Treat or Transfer on high-residual risks with no entry showing resource, budget or a named third party. | ISO 31000 cl.6.5 | Block a Treat or Transfer selection from closing without a linked action or contract reference, so the approach is resourced rather than aspirational. |
| Coverage gaps sit against domains the workspace actually operates in — no environmental or supply-chain entries despite both being live exposures. | ISO 31000 cl.6.4.2 | Walk Coverage against the workspace's real risk profile at each review and add missing domains explicitly rather than assuming silence means no risk. |
| Risks are reviewed on paper quarterly but the Management Review Record for the period shows no risk item discussed or actioned. | ISO 31000 cl.6.7 | Make Reported To Management Review conditional on a traceable reference into that period's Management Review Record, not a standalone tick. |
Case in point
Case in point: the register that only had lagging risks
A distribution business ran its enterprise risk register for two years with entries that read well — single-source supplier failure, warehouse fire, key person dependency — each rated, each with an owner. Every rating stayed identical review after review, because nobody had gone back to test whether the stated controls were still operating.
When a genuinely new risk emerged — a major customer's compliance requirements changing, threatening a third of site revenue — it took six weeks to surface at board level because the register had become a static list. The fix was not a new template; it was treating quarterly review as a re-assessment, with control effectiveness re-tested rather than carried forward, and a standing agenda item on emerging risks.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-026
- Archetype
- Register
- Record ID
- ERR-2026-000
- Scoring
- High risks open
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 31000 cl.6.4
- Links
- Links Risk register, Management review
- Tags
- Governance, Risk
- Sections
- 6
- Fields
- 49
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 2
Header
8 fieldsRegister ID*
Auto sequence. Format ERR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Last Reviewed*
Owner*
Next Review Due*
The Bridge To What The Board Discusses
Operational risk registers hold hundreds of task level entries. This one holds the handful that could stop the organisation meeting its objectives.
Register quality
6 fieldsRisks Linked To Objectives*
- Yes3 pts
- Partly1 pt
- No0 pts
Each Risk Has A Named Owner*
- Yes3 pts
- Partly1 pt
- No0 pts
Causes And Consequences Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Existing Controls Documented*
- Yes3 pts
- Partly1 pt
- No0 pts
Control Effectiveness Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Residual Position Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Coverage
6 fieldsSafety Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
Food Safety Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
Environmental Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
People And Capability Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
Supply Chain Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
Financial And Commercial Risks Represented*
- Yes3 pts
- Partly1 pt
- No0 pts
Governance
6 fieldsReviewed At Senior Level*
- Yes3 pts
- Partly1 pt
- No0 pts
Escalation From Operational Registers Works*
- Yes3 pts
- Partly1 pt
- No0 pts
Risk Appetite Applied*
- Yes3 pts
- Partly1 pt
- No0 pts
Treatment Plans Resourced*
- Yes3 pts
- Partly1 pt
- No0 pts
Emerging Risks Captured*
- Yes3 pts
- Partly1 pt
- No0 pts
Reported To Management Review*
Risks
Repeats9 fieldsRisk Title*
Domain*
Risk Owner*
Inherent Rating*
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
Control Effectiveness*
- Strong3 pts
- Adequate2 pts
- Weak0 pts
Residual Rating*
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
Within Risk Appetite*
- Yes3 pts
- Marginal1 pt
- No0 pts
Treatment Approach*
- Treat3 pts
- Transfer2 pts
- Tolerate1 pt
- Terminate3 pts
Review Date*
Outcome
14 fieldsRisks On Register*
High Risks Open*
Risks Without Treatment Plans*
Register Effective*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-026 · record IDs look like ERR-2026-000 · Links Risk register, Management review
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
Keeping a singleton register honest across a quarter is a coordination problem, not a form-filling one — ratings drift and escalations get missed without something watching the whole picture.
Holds the enterprise risk register against the appetite statement and the operational registers beneath it, flags ratings that have not moved in a suspiciously long time, and keeps the escalation path traceable.
Feeds safety and occupational health exposures up from site-level assessments so a genuine enterprise-scale safety risk reaches this register rather than staying buried in a local log.
Surfaces single-source supplier and distribution dependencies that belong on this register once they cross the threshold from an operational inconvenience to a strategic exposure.

Coordinates the crew across workspaces, rolls quarterly review status and appetite breaches into one view, and holds every write for your approval before it touches the register.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Enterprise Risk Register definitions and key terms
- Inherent risk
- The level of risk before crediting any control that is currently in place — the raw exposure if nothing were being done about it.
- Residual risk
- What remains after existing, verified controls are taken into account. The number that should actually drive a treatment decision.
- Risk appetite
- The amount and type of risk an organisation has explicitly decided it is willing to accept in pursuit of its objectives, usually set per domain in a separate statement.
- Risk treatment
- The set of options for modifying a risk — treat it, transfer it to a third party, tolerate it deliberately, or terminate the activity that creates it.
- Escalation
- The route by which a risk identified at operational level is raised to enterprise level once it exceeds a defined threshold of consequence or scale.
FAQ
Frequently asked questions about enterprise risk register
Do we need a separate register for every site, or one enterprise register?+
One enterprise register per workspace. Sites keep their own operational risk assessments; only risks that could affect the whole organisation's objectives escalate into this singleton register.
How many risks should realistically be on this register?+
Most functioning registers hold somewhere between five and twenty entries. A much longer list is usually evidence that operational risks have not been filtered out before being added.
What triggers a review outside the normal quarterly cycle?+
A material change to an existing risk — a control failing, a supplier changing, a new regulatory threat — or the identification of a new enterprise-scale risk should trigger an off-cycle update rather than waiting for the next quarter.
Who should be named as the owner of a risk on this register?+
Someone senior enough to authorise treatment and resourcing, not the person who happens to monitor the risk day to day. If the named owner cannot approve a budget or a change in approach, ownership sits too low.
How does this register relate to the Risk Appetite Statement?+
The appetite statement sets the threshold per domain; this register applies it to named risks and records whether each one sits within, at the margin of, or outside that threshold.
Is ISO 31000 certifiable on its own?+
No. It is guidance rather than a certification standard, but its risk process is embedded in the clause 6.1 requirements of ISO 9001, ISO 45001 and ISO 14001, so a certified management system is effectively assessed against it indirectly.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Risk Governance
Risk Appetite Statement
States how much risk the organisation is prepared to accept in each domain, so decisions are consistent
Risk Acceptance Record
Records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 31000:2018 cl.6 — Risk management process
- UK Corporate Governance Code (FRC), Provisions 28–29
- SEC Regulation S-K Item 106 — Cybersecurity risk disclosure
- COSO Enterprise Risk Management — Integrating with Strategy and Performance
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.