Risk Management

Risk Register Explained: 4 Signals That Reveal a Stale Risk Picture

A risk register is useful only when it reflects current exposure, ownership, controls, and decisions. Learn four signals that reveal when the picture is stale.

By 5 min read
Safety leader reviewing a risk register against current operating conditions

Key takeaways

  1. 01Treat the risk register as a decision record, not an audit archive.
  2. 02Name controls precisely enough to verify their presence and performance.
  3. 03Assign owners who have authority to change the exposure.
  4. 04Use operational changes and field evidence as review triggers.
  5. 05Challenge lower risk scores when no evidence shows that exposure fell.

A risk register is a controlled record of significant hazards, exposed people, existing controls, accountable owners, and decisions required to keep risk within agreed boundaries. It becomes useful when teams update it from field evidence, not when they preserve old descriptions to satisfy an audit.

What is a risk register?

A risk register translates uncertainty into a management record that can be reviewed, assigned, and challenged. It should show what can cause harm, who may be exposed, which controls are meant to prevent the event, and what evidence supports the current assessment.

The register is not a longer version of a risk matrix. A matrix classifies a result after likelihood and consequence are considered, while a register preserves the reasoning, ownership, assumptions, and follow-up that make the classification actionable. The distinction matters because a precise score can still rest on an untested control.

Andreza Araujo connects this discipline with the difference between formal compliance and operating culture in Safety Culture: From Theory to Practice. A document can look complete while the work it describes has already changed.

What should a useful risk register contain?

A useful register normally connects four pieces of information. It names the hazard and exposed activity, records the credible consequence, identifies the preventive and mitigative controls, and assigns an owner who has authority to change the condition.

It also records assumptions and review triggers. A contractor change, a new chemical, a shift pattern, a failed inspection, or a near miss can make an old assessment unreliable even when the process name remains the same. The entry therefore needs a review date that responds to change, not only to an annual calendar.

Teams that need a broader boundary for decision-making can compare each entry with risk criteria for leadership decisions, because the register should show how the organization decides that exposure is tolerable, unacceptable, or in need of escalation.

What four signals reveal a stale risk picture?

Signal 1: The control description is generic

“Training provided” or “procedure available” does not explain how a critical exposure is controlled. A current entry names the barrier, the person who verifies it, the condition that weakens it, and the evidence that confirms it is working.

Signal 2: The owner cannot change the exposure

An owner who can only monitor an action cannot manage the risk. When authority sits with maintenance, engineering, procurement, or operations, the register should show that interface instead of assigning responsibility to the nearest safety professional.

Signal 3: The review date has no trigger

An annual review can miss a changed task that became dangerous yesterday. A register is stale when the next review depends only on a date and ignores events that alter people, equipment, materials, workload, or supervision.

Signal 4: The score improves without field evidence

A lower residual rating is a decision, not proof that risk fell. The entry should point to inspection results, test records, maintenance evidence, observations, or other information that supports the change. Without that evidence, the score may reflect optimism rather than control performance.

How do you distinguish a live register from a filing exercise?

A live register changes when evidence changes. The entry is discussed in operating reviews, connected to action ownership, and challenged when a worker, supervisor, engineer, or contractor reports a mismatch between the written control and the task.

Across 25+ years leading EHS in multinational operations, Andreza Araujo has seen that the strongest registers are not the longest ones. They are the records that make a difficult decision visible, including who must act, by when, and what will demonstrate that the exposure is lower.

This is also where risk-matrix distortions deserve attention. A register can preserve a weak score, but it can also expose the assumptions behind that score when leaders ask for evidence.

When should a risk register be reviewed?

Review an entry before planned changes and after events that can alter the risk. Examples include process modifications, abnormal production demands, serious near misses, control failures, new contractors, staffing changes, and evidence that workers are using an unintended workaround.

The review should end with a decision. Keep the current controls, improve them, suspend the task, transfer the risk for a higher-level decision, or accept the remaining exposure under an explicit boundary. A meeting that produces no decision has not completed the review.

Risk register versus risk matrix, which tool does what?

ToolPrimary purposeQuestion it should answer
Risk registerPreserve exposure, controls, ownership, assumptions, and follow-upWhat must be managed, by whom, and what evidence is missing?
Risk matrixClassify likelihood and consequence using agreed criteriaHow does this exposure compare with the organization’s decision boundary?
Control verificationTest whether a critical barrier performs as intendedIs the stated control present, functional, and available under pressure?

A register becomes more reliable when it points to control evidence rather than treating a matrix color as the final answer. For barrier-focused reviews, the Bow-Tie structure can help teams separate preventive controls from mitigative controls without losing ownership.

What should leaders do after finding a stale entry?

Start with the exposure that has the highest credible consequence and the weakest evidence, not the entry that is easiest to edit. Confirm the work in the field, name the missing decision, assign an owner with authority, and set a verification date that reflects the speed at which the risk can change.

In more than 250 companies served worldwide, the practical lesson is consistent. Risk management improves when the record is treated as a decision tool whose accuracy depends on conversation, evidence, and follow-through. A register should make it harder to confuse documentation with control.

FAQ

What is the main purpose of a risk register? Its main purpose is to keep significant exposures, controls, owners, assumptions, and follow-up decisions visible in one controlled record.

Is a risk register the same as a risk matrix? No. A matrix classifies likelihood and consequence, while a register preserves the management reasoning and ownership behind that classification.

How often should a risk register be updated? Update it when evidence or operating conditions change, and use scheduled reviews as a minimum rhythm rather than the only trigger.

Who should own a risk-register action? The owner should have authority over the condition or control that must change. The safety function may coordinate the process without owning every operational action.

What makes a risk-register entry stale? Generic controls, unclear authority, date-only reviews, and lower scores without field evidence are strong signals that the entry no longer reflects actual exposure.

Risk registers create value when they keep changing with the work. If an entry cannot explain the current exposure, the responsible decision, and the evidence that supports the controls, it is a record of the past rather than a tool for preventing harm.

Topics risk-register risk-management risk-perception ehs-manager safety-leadership

Frequently asked questions

What is the main purpose of a risk register?
Its main purpose is to keep significant exposures, controls, owners, assumptions, and follow-up decisions visible in one controlled record.
Is a risk register the same as a risk matrix?
No. A matrix classifies likelihood and consequence, while a register preserves the management reasoning and ownership behind that classification.
How often should a risk register be updated?
Update it when evidence or operating conditions change, and use scheduled reviews as a minimum rhythm rather than the only trigger.
Who should own a risk-register action?
The owner should have authority over the condition or control that must change. The safety function may coordinate the process without owning every operational action.
What makes a risk-register entry stale?
Generic controls, unclear authority, date-only reviews, and lower scores without field evidence are strong signals that the entry no longer reflects actual exposure.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI