Seed-stage B2B SaaS startup
Sample for a fictional organisation · 3,334 words[Company] Risk Register
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This register records the risks to the confidentiality, integrity and availability of [Company]'s information and systems. It also records the risks of failing to meet the legal, regulatory and contractual obligations that come with them. Business risks with no security or compliance element, such as sales or funding, are recorded elsewhere.
The register covers [Company]'s own systems and information, the people who use them, and the suppliers and services the company depends on. Where [Company] keeps a more detailed record of a risk, such as an assessment of a supplier, that record holds the detail and this register carries the risk at summary level.
This register was prepared from a profile of [Company]'s size, sector, systems, data and obligations, not from a risk workshop or an audit. Each risk describes something that could happen, not something that has happened. The likelihood and impact scores are starting estimates, and the controls listed under each risk are the controls the register relies on to keep the risk at its residual level. At the first review, each risk owner confirms or corrects the description, the controls and the scores for the risks they own, and the CTO records the review in the document control list.
2. Roles
- The CTO keeps the register, scores new risks, runs the reviews and reports the highest risks to the CEO.
- The CEO approves the register and its risk ratings and accepts the risks the Risk Ratings table reserves for the CEO.
- Risk owners are the CTO, who owns the security and technology risks, and the CEO, who owns the people and fraud risks. A risk owner is accountable for the risk, confirms its scores and controls, and sees its actions through.
- Action owners are the risk owner, unless the risk's entry names another role.
- All staff report a new or changed risk to the CTO.
6. Risk Register
The table lists every risk, sorted by residual score with the highest first.
| ID | Risk | Category | Inherent | Residual | Owner |
|---|---|---|---|---|---|
| R-01 | Staff account taken over by attacker | Access and identity | 20 Critical | 12 High | CTO |
| R-02 | Flaw in own software is exploited | Change and software | 16 Critical | 12 High | CTO |
| R-03 | Reportable breach of personal data | Data and privacy | 20 Critical | 10 High | CTO |
| R-04 | Payment made to an impersonator | Fraud | 16 Critical | 9 Medium | CEO |
| R-05 | Key person leaves at short notice | People | 12 High | 9 Medium | CEO |
| R-06 | Outage at a service the company relies on | Continuity | 12 High | 9 Medium | CTO |
| R-07 | Ransomware or destructive malware | Systems and cloud | 20 Critical | 8 Medium | CTO |
| R-08 | Cloud misconfiguration exposes data | Systems and cloud | 16 Critical | 8 Medium | CTO |
| R-09 | Access kept after leaving or beyond role | Access and identity | 16 Critical | 6 Medium | CTO |
| R-10 | Backups cannot be restored | Continuity | 15 High | 6 Medium | CTO |
| R-11 | Change or migration causes outage or exposure | Change and software | 12 High | 6 Medium | CTO |
| R-12 | Laptop or phone lost or stolen | Systems and cloud | 12 High | 4 Low | CTO |
Read the full example
[Company] Risk Register
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This register records the risks to the confidentiality, integrity and availability of [Company]'s information and systems. It also records the risks of failing to meet the legal, regulatory and contractual obligations that come with them. Business risks with no security or compliance element, such as sales or funding, are recorded elsewhere.
The register covers [Company]'s own systems and information, the people who use them, and the suppliers and services the company depends on. Where [Company] keeps a more detailed record of a risk, such as an assessment of a supplier, that record holds the detail and this register carries the risk at summary level.
This register was prepared from a profile of [Company]'s size, sector, systems, data and obligations, not from a risk workshop or an audit. Each risk describes something that could happen, not something that has happened. The likelihood and impact scores are starting estimates, and the controls listed under each risk are the controls the register relies on to keep the risk at its residual level. At the first review, each risk owner confirms or corrects the description, the controls and the scores for the risks they own, and the CTO records the review in the document control list.
2. Roles
- The CTO keeps the register, scores new risks, runs the reviews and reports the highest risks to the CEO.
- The CEO approves the register and its risk ratings and accepts the risks the Risk Ratings table reserves for the CEO.
- Risk owners are the CTO, who owns the security and technology risks, and the CEO, who owns the people and fraud risks. A risk owner is accountable for the risk, confirms its scores and controls, and sees its actions through.
- Action owners are the risk owner, unless the risk's entry names another role.
- All staff report a new or changed risk to the CTO.
3. How Risks Are Scored
Every risk is scored on one scale. Likelihood is scored from 1 to 5 and impact from 1 to 5. The risk score is likelihood multiplied by impact, from 1 to 25, and the score sets the rating.
3.1 Likelihood
Likelihood is how often the risk is expected to occur.
| Level | Rating | Meaning |
|---|---|---|
| 1 | Rare | Not expected within the next 5 years |
| 2 | Unlikely | Could happen once in the next 2 to 5 years |
| 3 | Possible | Could happen within the next 2 years |
| 4 | Likely | Expected within the next 12 months |
| 5 | Almost certain | Expected several times a year |
3.2 Impact
Impact is how serious the consequences would be for [Company] and its customers.
| Level | Rating | Meaning |
|---|---|---|
| 1 | Minor | Work is disrupted for hours and the effect stays within one team, with no customers affected and nobody outside the company to be told. |
| 2 | Moderate | Work or service is disrupted for up to a day, one customer or a few staff are affected, and nobody outside the company must be told. |
| 3 | Significant | Work or service is disrupted for 1 to 3 days, several customers are affected, and a regulator or the people affected must be told. |
| 4 | Major | Work or service is disrupted for more than 3 days, most customers are affected, a regulator or the people affected must be told, and the company loses a major customer or a contract or is investigated by a regulator. |
| 5 | Severe | The company cannot operate, the whole customer base or the public is affected, a regulator or the people affected must be told, and the company faces a regulatory penalty, legal action or loss of its ability to trade. |
3.3 Risk Ratings
Each risk has two scores. Inherent risk is the likelihood and impact of the risk if none of the controls listed for it were in place. Residual risk is the likelihood and impact with the controls listed in place. Each residual score is set from the residual likelihood and impact, and the rating from the residual score decides who may accept the risk and how often it is reviewed.
| Rating | Scores | Acceptance | Review |
|---|---|---|---|
| Low | 1 to 4 | Accepted by the risk owner | Reviewed at the annual review |
| Medium | 5 to 9 | Accepted by the risk owner with the agreement of the CTO | Reviewed at the annual review |
| High | 10 to 15 | Accepted by the risk owner with the agreement of the CEO | Reviewed every 3 months |
| Critical | 16 to 25 | Not accepted as a residual rating except by the CEO in writing with a reason, and then only while treatment actions are under way | Reviewed every month until the rating falls to High or below |
Where the risk owner is also the role whose agreement a rating needs, the risk owner accepts alone.
Accepting a residual rating means the role named has agreed that the company can carry the risk at that level until its next review while any actions are completed. This is separate from choosing Accept as the treatment, which section 4 allows only for Low and Medium ratings. A residual score can never be higher than the inherent score for the same risk.
4. Treating Risks
Each risk is given one of four treatments:
- Reduce: add or strengthen controls.
- Accept: carry the risk as it is, where the residual rating is Low or Medium and the cost of reducing it further would outweigh the benefit.
- Avoid: stop or change the activity that creates the risk.
- Share: use a contract with a supplier or an insurance policy to carry part of the loss.
Every risk with a treatment of Reduce, Avoid or Share has at least one action with an owner and a due time. Actions are due within 3 months of the effective date for a Critical residual rating, 6 months for High and 12 months for Medium or Low. A risk is treated as Accept only after its owner has recorded the acceptance with the date and the reason. Where an action would put a contract or an insurance policy in place, the register does not say that the company already has it.
5. Review and Maintenance
- The first review of every risk takes place within 3 months of the effective date.
- Every risk is reassessed at least once every 12 months, and at the intervals its rating sets in section 3.3.
- A risk is reviewed sooner after a security incident, a significant change to systems, suppliers or ways of working, a new customer requirement or law, or an audit finding.
- New risks take the next unused ID, and IDs are never reused.
- The CTO closes a risk when it no longer applies. It stays in the register marked Closed.
- Previous versions of the register are kept for 3 years.
- The CEO reviews and approves the register at least once every 12 months.
6. Risk Register
The table lists every risk, sorted by residual score with the highest first.
| ID | Risk | Category | Inherent | Residual | Owner |
|---|---|---|---|---|---|
| R-01 | Staff account taken over by attacker | Access and identity | 20 Critical | 12 High | CTO |
| R-02 | Flaw in own software is exploited | Change and software | 16 Critical | 12 High | CTO |
| R-03 | Reportable breach of personal data | Data and privacy | 20 Critical | 10 High | CTO |
| R-04 | Payment made to an impersonator | Fraud | 16 Critical | 9 Medium | CEO |
| R-05 | Key person leaves at short notice | People | 12 High | 9 Medium | CEO |
| R-06 | Outage at a service the company relies on | Continuity | 12 High | 9 Medium | CTO |
| R-07 | Ransomware or destructive malware | Systems and cloud | 20 Critical | 8 Medium | CTO |
| R-08 | Cloud misconfiguration exposes data | Systems and cloud | 16 Critical | 8 Medium | CTO |
| R-09 | Access kept after leaving or beyond role | Access and identity | 16 Critical | 6 Medium | CTO |
| R-10 | Backups cannot be restored | Continuity | 15 High | 6 Medium | CTO |
| R-11 | Change or migration causes outage or exposure | Change and software | 12 High | 6 Medium | CTO |
| R-12 | Laptop or phone lost or stolen | Systems and cloud | 12 High | 4 Low | CTO |
7. Risk Details
7.1 R-01 Staff account taken over by attacker
- Risk: An attacker tricks a staff member into giving up a password or approving a login, or uses a password stolen from another service, and takes over a company account. The attacker could then reach email, code and customer data, leading to a data breach and a loss of customer trust.
- Category: Access and identity
- Inherent risk: Likelihood 5 (Almost certain) × Impact 4 (Major) = 20, Critical
- Controls relied on: Multi-factor authentication on all accounts; a unique password for each service; security awareness training for staff
- Residual risk: Likelihood 3 (Possible) × Impact 4 (Major) = 12, High
- Treatment: Reduce
- Actions: Move administrator accounts to hardware security keys (CTO, 3 months); start regular phishing exercises for all staff (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.2 R-02 Flaw in own software is exploited
- Risk: An attacker exploits a vulnerability in the company's own software, a secret committed to a GitHub repository, or a compromised dependency (third-party code the product relies on). Customer data could be exposed or the service disrupted, affecting several customers and damaging trust.
- Category: Change and software
- Inherent risk: Likelihood 4 (Likely) × Impact 4 (Major) = 16, Critical
- Controls relied on: Required code review before changes are merged; automated scanning of dependencies for known vulnerabilities; separate development and production environments
- Residual risk: Likelihood 3 (Possible) × Impact 4 (Major) = 12, High
- Treatment: Reduce
- Actions: Add automated scanning for secrets in code before it is merged (CTO, 3 months); commission an independent penetration test of the product (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.3 R-03 Reportable breach of personal data
- Risk: Personal data held by the company is exposed to or taken by an unauthorized party through an attack or an error, and must be reported to the customers whose data it is, and to the people affected where the data breach notification law of each state where the people affected live requires. The consequences would be notification effort, customer complaints, possible attention from regulators and a loss of customer trust.
- Category: Data and privacy
- Inherent risk: Likelihood 4 (Likely) × Impact 5 (Severe) = 20, Critical
- Controls relied on: Encryption of personal data in storage and in transit; access to customer data limited to those who need it; logging of access to production data
- Residual risk: Likelihood 2 (Unlikely) × Impact 5 (Severe) = 10, High
- Treatment: Reduce
- Actions: Add alerts for unusual access to production data (CTO, 6 months); set retention limits so personal data is deleted when no longer needed (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.4 R-04 Payment made to an impersonator
- Risk: An attacker posing as a supplier, a customer or an executive persuades staff to pay a fake invoice or change bank details. Money could be lost with little chance of recovery, and cash flow could be disrupted.
- Category: Fraud
- Inherent risk: Likelihood 4 (Likely) × Impact 4 (Major) = 16, Critical
- Controls relied on: Call-back to a known number before bank details are changed; approval of payments by a second person
- Residual risk: Likelihood 3 (Possible) × Impact 3 (Significant) = 9, Medium
- Treatment: Reduce
- Actions: Add email domain protection so messages that spoof the company's domain are rejected (CTO, 6 months); train everyone who handles payments to recognize impersonation requests (CEO, 6 months)
- Risk owner: CEO
- Status: Open
7.5 R-05 Key person leaves at short notice
- Risk: A person whose knowledge or access the company depends on, such as the only person who knows how AWS or Google Workspace is set up, leaves at short notice. The company could be unable to operate systems or support customers for several days.
- Category: People
- Inherent risk: Likelihood 3 (Possible) × Impact 4 (Major) = 12, High
- Controls relied on: Shared documentation of core systems; more than one administrator on each core system; company-owned accounts for all business services
- Residual risk: Likelihood 3 (Possible) × Impact 3 (Significant) = 9, Medium
- Treatment: Reduce
- Actions: Write a hand-over plan for each key role naming who takes over its systems and accounts (CEO, 12 months); record, for each core account, an emergency-access procedure the CEO can use if the administrators are unavailable (CEO, 12 months)
- Risk owner: CEO
- Status: Open
7.6 R-06 Outage at a service the company relies on
- Risk: AWS, Google Workspace, GitHub or another service the company depends on suffers a long outage, making the product or the company's working tools unavailable. Customers could be unable to use the product for a day or more, and staff work would stall.
- Category: Continuity
- Inherent risk: Likelihood 4 (Likely) × Impact 3 (Significant) = 12, High
- Controls relied on: Monitoring and alerting on service availability; hosting designed to survive the failure of a single data center; a way to tell customers about disruption
- Residual risk: Likelihood 3 (Possible) × Impact 3 (Significant) = 9, Medium
- Treatment: Reduce
- Actions: Keep copies of runbooks and customer contact details outside the main providers (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.7 R-07 Ransomware or destructive malware
- Risk: Ransomware (malware that locks data for payment) or destructive malware reaches company laptops or cloud systems through a malicious attachment, a download or a compromised account. The company and its customers could lose access to systems or data for days and customers might have to be told.
- Category: Systems and cloud
- Inherent risk: Likelihood 4 (Likely) × Impact 5 (Severe) = 20, Critical
- Controls relied on: Endpoint protection on all laptops; automatic security updates; backups kept separate from production systems
- Residual risk: Likelihood 2 (Unlikely) × Impact 4 (Major) = 8, Medium
- Treatment: Reduce
- Actions: Restrict software installation on laptops to an approved list (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.8 R-08 Cloud misconfiguration exposes data
- Risk: A storage bucket, database or other AWS resource is set up or changed so that it can be reached from the internet without proper protection. Customer data could be exposed and customers would have to be told.
- Category: Systems and cloud
- Inherent risk: Likelihood 4 (Likely) × Impact 4 (Major) = 16, Critical
- Controls relied on: Review of infrastructure changes before they are applied; administrator access limited to a few people
- Residual risk: Likelihood 2 (Unlikely) × Impact 4 (Major) = 8, Medium
- Treatment: Reduce
- Actions: Add automated alerts for any cloud resource exposed to the internet (CTO, 3 months); block public access to storage by default (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.9 R-09 Access kept after leaving or beyond role
- Risk: Accounts or permissions stay active after someone leaves, or grow beyond what a role needs as tasks change. A former or current team member could reach information they should not, and the access could go unnoticed and expose customer data.
- Category: Access and identity
- Inherent risk: Likelihood 4 (Likely) × Impact 4 (Major) = 16, Critical
- Controls relied on: A leaver checklist covering all core systems; role-based access limited to what each role needs
- Residual risk: Likelihood 2 (Unlikely) × Impact 3 (Significant) = 6, Medium
- Treatment: Reduce
- Actions: Start a quarterly review of who has access to each core system (CTO, 6 months); add automatic deactivation of departed staff accounts through the company directory (CTO, 12 months)
- Risk owner: CTO
- Status: Open
7.10 R-10 Backups cannot be restored
- Risk: Backups are incomplete or corrupted, or cannot be restored in the time needed, after a deletion, an attack or a provider failure. Customer data could be lost for good or the service could be down for days, and the company might miss its commitments to customers.
- Category: Continuity
- Inherent risk: Likelihood 3 (Possible) × Impact 5 (Severe) = 15, High
- Controls relied on: Automated regular backups of production data; backups stored in a separate account from production
- Residual risk: Likelihood 2 (Unlikely) × Impact 3 (Significant) = 6, Medium
- Treatment: Reduce
- Actions: Add alerts when a backup job fails (CTO, 3 months); add scheduled restore tests with results recorded (CTO, 6 months)
- Risk owner: CTO
- Status: Open
7.11 R-11 Change or migration causes outage or exposure
- Risk: A change to code, infrastructure or settings, or a migration between systems, goes live with an error that causes an outage or exposes data. Customers could lose service for hours to days, or data could be seen by people who should not see it.
- Category: Change and software
- Inherent risk: Likelihood 4 (Likely) × Impact 3 (Significant) = 12, High
- Controls relied on: Code review before release; a test environment; the ability to roll back a release
- Residual risk: Likelihood 3 (Possible) × Impact 2 (Moderate) = 6, Medium
- Treatment: Reduce
- Actions: Add automated tests that must pass before release (CTO, 6 months); use staged releases to a small share of customers first (CTO, 12 months)
- Risk owner: CTO
- Status: Open
7.12 R-12 Laptop or phone lost or stolen
- Risk: A laptop or phone holding company information is lost or stolen while traveling or from a home. Someone else could see the information on it, and the owner could be locked out of work until it is replaced.
- Category: Systems and cloud
- Inherent risk: Likelihood 4 (Likely) × Impact 3 (Significant) = 12, High
- Controls relied on: Full-disk encryption; a screen lock with a passcode; remote wipe of lost devices
- Residual risk: Likelihood 2 (Unlikely) × Impact 2 (Moderate) = 4, Low
- Treatment: Accept
- Actions: None. The risk owner records acceptance at the first review, with the agreement the Risk Ratings table requires.
- Risk owner: CTO
- Status: Open
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.