Risk ID
A short, unique reference such as RSK-001. It lets you link a risk to its treatment, its owner, and any incident, without retyping the full description.
A risk assessment template is a structured form for recording each risk, scoring how likely and how damaging it is, and deciding what to do about it. This one is rendered in full on the page: risk ID, description, category, likelihood and impact, inherent and residual scores, owner, treatment, and status. Copy it as is, or take the editable version with you.
A risk assessment template is a repeatable form for capturing what could go wrong, scoring how likely and how damaging each risk is, and recording the decision on what to do about it. Completed row by row, it produces a register of named risks with scores, owners, controls, and treatment plans that a board, an auditor, or an insurer can read in one pass.
The structure is not proprietary. It follows the same activity every credible framework describes, identify, analyse, evaluate, treat, and monitor, so a template built this way carries cleanly into ISO 31000, NIST SP 800-30, ISO 27005, or COSO ERM work. It also doubles as a risk assessment form for a single project and, once you keep it current, as a risk register for the whole organization. For the wider context, read what a risk assessment is.
Ten columns cover a working assessment. The two that separate a real template from a static list are the inherent and residual scores, and a named owner on every row.
A short, unique reference such as RSK-001. It lets you link a risk to its treatment, its owner, and any incident, without retyping the full description.
One sentence that names the threat, the vulnerability, and the consequence. Write it so a reader outside the team understands what could go wrong and why it matters.
The risk family: cyber and IT, operational, financial, strategic, compliance, or physical and environmental. Categories let you roll risk up and spot concentrations.
How probable the risk is over the review window, from 1 (rare) to 5 (almost certain). Score against a written scale so two assessors land on the same number.
How damaging the consequence would be, from 1 (insignificant) to 5 (severe). Cover money, downtime, safety, and regulatory or reputational harm.
Likelihood multiplied by impact, from 1 to 25, before controls are credited. It ranks raw exposure so the biggest problems sort to the top.
One named person accountable for the risk, not a department. A risk without an owner is a risk nobody is treating.
The decision and the action: accept, treat, transfer, or avoid, plus the controls that carry it out. This is where the register turns into work.
Likelihood multiplied by impact again, after the controls in place are credited. Residual, not inherent, is what you manage day to day.
Where the risk sits now: open, in treatment, monitored, or accepted, with the next review date. It keeps the register current instead of a one-off snapshot.
Six example rows across the common risk categories. The inherent and residual scores are colour-banded so exposure reads at a glance. Copy the columns straight into your own document, or take the editable version below.
| Risk ID | Risk description | Category | Likelihood | Impact | Inherent | Owner | Treatment | Residual | Status |
|---|---|---|---|---|---|---|---|---|---|
| RSK-001 | Phishing leads to stolen staff credentials | Cyber and IT | 4 | 5 | 20Extreme | CISO | Treat: enforce MFA, run quarterly awareness training | 8Medium | In treatment |
| RSK-002 | Critical vendor outage halts order processing | Vendor and third party | 3 | 4 | 12High | Head of Procurement | Treat: contractual SLA, qualify a backup supplier | 6Medium | Monitored |
| RSK-003 | Loss of a key person in the finance team | Operational | 3 | 3 | 9Medium | CFO | Treat: cross-train and document core processes | 6Medium | Open |
| RSK-004 | Non-compliance with the HIPAA Security Rule | Compliance | 2 | 5 | 10High | Compliance Lead | Treat: annual risk analysis, close control gaps | 5Medium | In treatment |
| RSK-005 | Water ingress damages the on-site server room | Physical and environmental | 2 | 4 | 8Medium | Facilities Manager | Transfer: insurance plus verified offsite backups | 4Low | Accepted |
| RSK-006 | Currency volatility erodes overseas margin | Financial | 3 | 3 | 9Medium | Treasurer | Treat: board-approved FX hedging policy | 6Medium | Monitored |
Inherent score is likelihood multiplied by impact before controls. Residual score is the same calculation after the controls in place are credited. The drop between them is the value your controls are adding.
The template above is free to copy. If you want it as an editable spreadsheet, the free Risk Register Template carries the exact same columns, plus a 5-by-5 scoring key and a guidance tab for scoring consistently across teams. It is delivered through our free resources, with no credit card required.
Five steps take a blank template to a scored, owned register. Run them in order so the work compounds instead of restarting each cycle.
Work through each part of the business and name what could go wrong. Give each risk an ID and a one-sentence description with the threat, the vulnerability, and the consequence.
Use the same written scale for every row so the numbers are comparable. Rate how probable the risk is and how damaging it would be if it happened.
Likelihood times impact gives a number from 1 to 25. Sort the register by that score so the biggest raw exposures sit at the top before you credit any controls.
Give each risk one accountable owner. Choose accept, treat, transfer, or avoid, and record the controls that carry the decision out.
Score likelihood and impact again with the controls credited. The residual score is what you manage. Add a status and a next-review date so the register stays alive.
The matrix is how the template turns two 1-to-5 scores into a single number and a decision. Rate likelihood, rate impact, and multiply. The colour band tells you what to do. This is the same matrix behind the inherent and residual columns above.
| Likelihood / Impact | 1Insignificant | 2Minor | 3Moderate | 4Major | 5Severe |
|---|---|---|---|---|---|
| 5Almost certain | 5Medium | 10High | 15Extreme | 20Extreme | 25Extreme |
| 4Likely | 4Low | 8Medium | 12High | 16Extreme | 20Extreme |
| 3Possible | 3Low | 6Medium | 9Medium | 12High | 15Extreme |
| 2Unlikely | 2Low | 4Low | 6Medium | 8Medium | 10High |
| 1Rare | 1Low | 2Low | 3Low | 4Low | 5Medium |
Accept and monitor. Manage through routine procedures.
Treat where it pays. Assign an owner and a review date.
Treatment required. Escalate to management and track to target.
Act now. Senior leadership attention until it is reduced.
Document the scale in writing so "likely" and "major" mean the same thing to every assessor. A 3-by-3 matrix works for a small register, while the 5-by-5 gives a larger program the resolution it needs. For a deeper walkthrough, see the risk assessment matrix guide.
A template in a spreadsheet is the right place to start, and it is where most risk programs begin. It tends to break past roughly fifty risks or controls, or the moment a second framework, a third assessor, or a fourth business unit joins in.
RiskWatch has run this pattern since 1993, holds a 4.7 rating on G2, and reaches a live register in a 30-day median implementation. When the template becomes a program, move the same columns into risk management software and keep going from where the spreadsheet left off.
The questions buyers ask most often about the template, the fields, and the scoring.
Start a free trial and the template becomes a working register: owners, review cycles, cross-mapped controls across 40+ frameworks, and an audit-ready package on demand. No credit card required.
No credit card required · 30-day free trial · Cancel anytime