Reviewing your organisation’s Risk Register seems like a task that is best scheduled for tomorrow, right? But regularly reviewing your Risk Register is a power move that can support business resilience, manage costs and improve organisational outcomes.

Why?

Reviewing your Risk Register helps you stay on top of your identified risks and helps you with identifying emerging risks (but more on that next week!).  This proactive move will support management of your risks, help you prioritise the most important risks that need urgency or attention, and supports a review of your risk control effectiveness. All of this can better protect your business, bring down financial cost and ensure good governance practices for your organisation.

How?

Step 1. Risk Categories – you already have these listed on your Risk Register but review them to check that they are your current risks.

Step 2. Risk Descriptions – these described HOW the risk category is impacting or has the potential to impact your business. As your environment, your workplace and your industry changes, how you describe the risk to your business might also change. So review your Risk Descriptions and update them in need.

Step 3. Risk Ratings – this is an important one, because rating your risks allows you to PRIORITISE your risks.  You have limited time, money and resources. Put your efforts into the risks with the highest priority. Unless you rate your risks, you will not understand what is urgent and important! So review your current ratings and update them in need.

Step 4. Risk Controls – another important one. You need to ensure that your risk controls are actually in place, effective and working as intended. If they are not, they are ineffective as risk controls. Undertake some assurance activities to make sure your risk controls are working. Update your risk controls to ensure they really are effective at controlling the risk!

Of course, as you work your way through these steps, make sure you involve key stakeholders – risk management is a team activity!

When you’ve finished the steps above, report to your Board, your Risk Committee and other relevant stakeholders to ensure that they understand the risk landscape for the organisation and to give them confidence you are adopting a risk managed approach!