Knowella

Enterprise Risk Register

The recurring failure is not a missing register, it is a duplicated one: someone rolls up the top rows of every operational risk assessment into a single sheet and calls it enterprise risk. The result has forty entries, no genuine strategic risks, no named owners at the right level, and nothing the board would recognise as the handful of things that could actually stop the organisation meeting its objectives.

KnowComplyRegisterCMP-026Pinned in navigation49 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 31000 cl.6.4
Workspace
KnowComply
Form type
Register
Review cadence
Quarterly, owned by senior management
Record type
Singleton — one live register per workspace

The short version

  • This register holds the small number of risks that could stop the organisation meeting its objectives, not the hundreds of task-level entries that belong on operational risk assessments.
  • It is a singleton — one live register per workspace, reviewed quarterly and owned by senior management, not a per-event record raised and closed like most templates in the library.
  • Scoring runs on high risks open, and low is the good direction, which only holds if inherent, control effectiveness and residual ratings are entered honestly rather than pre-agreed to land green.
  • It is built against ISO 31000 cl.6.4 and sits inside the Management System Governance programme, feeding management review and drawing from the operational risk registers beneath it.

What this is

What makes a risk 'enterprise' rather than operational?

What makes a risk 'enterprise' rather than operational?

An enterprise risk threatens the organisation's ability to meet its objectives, not the completion of a single task. A forklift near-miss is operational and belongs on a site risk assessment. A single-source supplier whose failure would stop production across every site is enterprise, because it needs senior sign-off on the response.

What is the difference between inherent and residual risk?

Inherent risk is the rating before any existing control is credited — the raw exposure. Residual risk is what remains after the controls actually in place and verified are taken into account. The gap between the two is the control effectiveness claim, and it is the number auditors and boards test hardest.

How does risk appetite relate to this register?

Risk appetite is the amount and type of risk the organisation has decided to accept, set out in a separate appetite statement. This register applies that appetite to named risks and records whether the residual position sits inside it, is marginal, or breaches it. Without a stated appetite, 'within appetite' is a guess dressed up as an assessment.

Scope

When is an enterprise risk register required?

This register sits inside a larger governance programme. Using it for work that belongs to a neighbouring template produces a document nobody can report on with confidence six months later.

Use this template when

  • The workspace is being set up for the first time and a top-level risk register needs to exist before management review can function
  • A new strategic, financial, supply-chain or multi-site risk has emerged and needs a named owner above the level of a single team
  • A previously accepted risk has changed materially — a new control has failed, a supplier has changed, a regulatory threat has escalated — and the residual rating needs revisiting
  • Quarterly review is due and the register needs its ratings, treatment plans and appetite position refreshed before it goes to senior management
  • Management review needs a single, current view of the risks that could prevent the organisation meeting its stated objectives

Do not use it for

  • Risk Appetite Statement, which sets how much risk is acceptable per domain — do not invent appetite thresholds inside individual register rows.
  • Risk Acceptance Record, which documents a deliberate decision to accept a specific risk rather than treat it — a 'Tolerate' entry here is not the same as a signed acceptance.
  • Bow Tie Analysis Record, which maps threats, the top event, consequences and barriers for a single major hazard — this register holds the summary rating, not the barrier-level analysis.
  • Operational or task-level risk assessments, which belong in the workspace that owns the process and should feed this register only once judged enterprise-scale
  • Management Review Action Log, which tracks actions raised from review meetings, once this register has stated the risk position

Compliance mapping

Which ISO 31000 cl.6.4 requirements does this satisfy?

ISO 31000 describes risk management as a process, and the sections below map each stage onto where it is actually captured in the form.

ClauseRequirementWhere it lands
ISO 31000 cl.6.4.2Risk identification — find, recognise and describe risks in terms that support later analysisRisks
ISO 31000 cl.6.4.3Risk analysis — understand the nature of the risk, including likelihood, consequence and the effect of existing controlsRisks
ISO 31000 cl.6.4.4Risk evaluation — compare the analysis result against the organisation's risk criteria and appetite to decide if treatment is neededRisks
ISO 31000 cl.6.5Risk treatment — select and implement an option to modify the risk, and record who resources itRisks
ISO 31000 cl.6.6Monitoring and review — of both individual risks and the effectiveness of the overall risk management frameworkRegister quality
ISO 31000 cl.6.7Recording and reporting — through mechanisms that support decision-making and are communicated to stakeholdersOutcome
ISO 31000 cl.6.2Communication and consultation — with those accountable for the risk and those affected by it, at the appropriate level of seniorityGovernance

What it does not cover

  • Risks On Register, which is high but every entry is task-level rather than enterprise-scale, so the count reflects scope creep rather than genuine coverage.
  • Control Effectiveness Assessed, which is marked Yes across the board with no evidence of when or how effectiveness was tested, rather than assumed from the control existing on paper.
  • Within Risk Appetite, which is answered without a Risk Appetite Statement anywhere in the workspace to compare the residual rating against.
  • Treatment Plans Resourced, which is marked Yes for a Treat or Transfer approach with no budget, owner capacity or named third party committed.
  • Reported To Management Review, which is marked Yes while that period's Management Review Record shows no risk item on its agenda.

Global

Enterprise Risk Register requirements by country

ISO 31000 is guidance, not a certifiable standard, so the register's real teeth come from governance and disclosure regimes that expect one to exist and be current.

United Kingdom

UK Corporate Governance Code (FRC), Provisions 28–29

The board must state it has assessed the company's principal and emerging risks, including those threatening its business model or solvency, and describe how they are managed.

This register is the working evidence behind that statement, expected to show named owners, inherent/residual ratings and a treatment plan, not a narrative written after the fact.

United States

SEC Regulation S-K Item 106; COSO ERM framework

Public companies must describe their processes for assessing material risks and name the board committee responsible for oversight, with cybersecurity risk called out under Item 106.

Under a US-listed parent, this register is the artefact showing the process runs on a cycle, rather than being reconstructed at year end for disclosure.

International / certification

ISO 31000:2018 cl.6; ISO 9001/45001/14001 cl.6.1

ISO 31000 carries no certification itself, but its process is the reference model inside every certifiable management system's clause 6.1 risk requirement.

A certification auditor on any linked standard expects this identify-analyse-evaluate-treat-monitor process to be traceable, even though this register is not itself audited against ISO 31000.

How to complete it

How to complete an enterprise risk register, step by step

Filling in fields is mechanical. The four calls below decide whether a register is defensible in front of a board or quietly decorative.

Where the enterprise line actually sits

Every organisation draws the operational/enterprise line differently. Set it explicitly — by consequence severity, sites affected, or threat to a stated objective — and apply it consistently, or the register drifts wider every quarter.

Whether control effectiveness is tested or assumed

Marking a control Strong because it exists on paper is not the same as marking it Strong because someone checked it operated last quarter. The residual rating is only as honest as this judgement.

When a risk graduates from an operational register

The escalation route from operational registers needs a trigger, not a feeling — a rating threshold, a repeat occurrence, or a change in scale. That choice decides whether this register stays current or stale.

How 'marginal' against appetite gets resolved

Within Risk Appetite has a middle answer, Marginal, and that is where most governance failures start — neither the urgency of a breach nor the comfort of clear acceptance. Deciding who reviews marginal entries, and how often, is left to you.

What auditors find

Most common enterprise risk register findings

These recur across registers that look complete on the surface but do not hold up once a specific risk is traced end to end.

FindingClauseWhat fixes it
Every risk carries the same handful of generic owners rather than named individuals accountable for that specific risk.ISO 31000 cl.6.2Assign one named owner per risk who can speak to its status without escalating the question, and revisit ownership at every quarterly review.
Inherent and residual ratings are identical across most rows, suggesting controls were never credited or the rating was set once and never re-derived.ISO 31000 cl.6.4.3Require a stated control and its assessed effectiveness before any gap is entered — an unexplained gap should read as a data quality flag, not a result.
No Risk Appetite Statement exists in the workspace, so Within Risk Appetite is answered against an unstated, personal threshold.ISO 31000 cl.6.4.4Stand up the Risk Appetite Statement first, or flag every appetite answer here as provisional until it exists.
Treatment Approach is set to Treat or Transfer on high-residual risks with no entry showing resource, budget or a named third party.ISO 31000 cl.6.5Block a Treat or Transfer selection from closing without a linked action or contract reference, so the approach is resourced rather than aspirational.
Coverage gaps sit against domains the workspace actually operates in — no environmental or supply-chain entries despite both being live exposures.ISO 31000 cl.6.4.2Walk Coverage against the workspace's real risk profile at each review and add missing domains explicitly rather than assuming silence means no risk.
Risks are reviewed on paper quarterly but the Management Review Record for the period shows no risk item discussed or actioned.ISO 31000 cl.6.7Make Reported To Management Review conditional on a traceable reference into that period's Management Review Record, not a standalone tick.

Case in point

Case in point: the register that only had lagging risks

A distribution business ran its enterprise risk register for two years with entries that read well — single-source supplier failure, warehouse fire, key person dependency — each rated, each with an owner. Every rating stayed identical review after review, because nobody had gone back to test whether the stated controls were still operating.

When a genuinely new risk emerged — a major customer's compliance requirements changing, threatening a third of site revenue — it took six weeks to surface at board level because the register had become a static list. The fix was not a new template; it was treating quarterly review as a re-assessment, with control effectiveness re-tested rather than carried forward, and a standing agenda item on emerging risks.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

49fields
6 sections
Reference
CMP-026
Archetype
Register
Record ID
ERR-2026-000
Scoring
High risks open
Direction
Low is good
Singleton
Yes
Basis
ISO 31000 cl.6.4
Links
Links Risk register, Management review
Tags
Governance, Risk
Sections
6
Fields
49
Follow up fields
3
Repeating sections
1
Links out
2
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Register ID*

Generated on save

Auto sequence. Format ERR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Last Reviewed*

Users

Owner*

Date & Time

Next Review Due*

Info

The Bridge To What The Board Discusses

Operational risk registers hold hundreds of task level entries. This one holds the handful that could stop the organisation meeting its objectives.

Register quality

6 fields
Single Choice

Risks Linked To Objectives*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Each Risk Has A Named Owner*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Causes And Consequences Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Existing Controls Documented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Control Effectiveness Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Residual Position Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Coverage

6 fields
Single Choice

Safety Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Food Safety Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Environmental Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

People And Capability Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Supply Chain Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Financial And Commercial Risks Represented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Governance

6 fields
Single Choice

Reviewed At Senior Level*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Escalation From Operational Registers Works*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Risk Appetite Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Treatment Plans Resourced*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Emerging Risks Captured*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Reported To Management Review*

YesNo

Risks

Repeats9 fields
Text

Risk Title*

Single Choice

Domain*

SafetyFood safetyQualityEnvironmentalOccupational healthEngineeringWarehouseTransport
Users

Risk Owner*

Single Choice

Inherent Rating*

Scored
  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Very high0 pts
Single Choice

Control Effectiveness*

Scored
  • Strong3 pts
  • Adequate2 pts
  • Weak0 pts
Single Choice

Residual Rating*

Scored
  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Very high0 pts
Single Choice

Within Risk Appetite*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Single Choice

Treatment Approach*

Scored
  • Treat3 pts
  • Transfer2 pts
  • Tolerate1 pt
  • Terminate3 pts
Date & Time

Review Date*

Outcome

14 fields
Numeric Answer

Risks On Register*

Scored
Numeric Answer

High Risks Open*

Scored
Numeric Answer

Risks Without Treatment Plans*

Scored
Single Choice

Register Effective*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Review Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-026 · record IDs look like ERR-2026-000 · Links Risk register, Management review

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

Keeping a singleton register honest across a quarter is a coordination problem, not a form-filling one — ratings drift and escalations get missed without something watching the whole picture.

KnowComply

Holds the enterprise risk register against the appetite statement and the operational registers beneath it, flags ratings that have not moved in a suspiciously long time, and keeps the escalation path traceable.

KnowSafe

Feeds safety and occupational health exposures up from site-level assessments so a genuine enterprise-scale safety risk reaches this register rather than staying buried in a local log.

KnowLogistics

Surfaces single-source supplier and distribution dependencies that belong on this register once they cross the threshold from an operational inconvenience to a strategic exposure.

Ella
Ella

Coordinates the crew across workspaces, rolls quarterly review status and appetite breaches into one view, and holds every write for your approval before it touches the register.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Enterprise Risk Register definitions and key terms

Inherent risk
The level of risk before crediting any control that is currently in place — the raw exposure if nothing were being done about it.
Residual risk
What remains after existing, verified controls are taken into account. The number that should actually drive a treatment decision.
Risk appetite
The amount and type of risk an organisation has explicitly decided it is willing to accept in pursuit of its objectives, usually set per domain in a separate statement.
Risk treatment
The set of options for modifying a risk — treat it, transfer it to a third party, tolerate it deliberately, or terminate the activity that creates it.
Escalation
The route by which a risk identified at operational level is raised to enterprise level once it exceeds a defined threshold of consequence or scale.

FAQ

Frequently asked questions about enterprise risk register

Do we need a separate register for every site, or one enterprise register?+

One enterprise register per workspace. Sites keep their own operational risk assessments; only risks that could affect the whole organisation's objectives escalate into this singleton register.

How many risks should realistically be on this register?+

Most functioning registers hold somewhere between five and twenty entries. A much longer list is usually evidence that operational risks have not been filtered out before being added.

What triggers a review outside the normal quarterly cycle?+

A material change to an existing risk — a control failing, a supplier changing, a new regulatory threat — or the identification of a new enterprise-scale risk should trigger an off-cycle update rather than waiting for the next quarter.

Who should be named as the owner of a risk on this register?+

Someone senior enough to authorise treatment and resourcing, not the person who happens to monitor the risk day to day. If the named owner cannot approve a budget or a change in approach, ownership sits too low.

How does this register relate to the Risk Appetite Statement?+

The appetite statement sets the threshold per domain; this register applies it to named risks and records whether each one sits within, at the margin of, or outside that threshold.

Is ISO 31000 certifiable on its own?+

No. It is guidance rather than a certification standard, but its risk process is embedded in the clause 6.1 requirements of ISO 9001, ISO 45001 and ISO 14001, so a certified management system is effectively assessed against it indirectly.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 31000:2018 cl.6 — Risk management process
  • UK Corporate Governance Code (FRC), Provisions 28–29
  • SEC Regulation S-K Item 106 — Cybersecurity risk disclosure
  • COSO Enterprise Risk Management — Integrating with Strategy and Performance

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.