Getting started

How to build a 5×5 risk register in a week (without hiring a consultant)

A pragmatic 7-day plan for standing up a board-grade risk register from scratch - the fixtures, the workshops, the anti-patterns.

Nadia Kaan, Principal Advisor February 1, 2026 7 min read Register

The single biggest reason risk registers rot is that they are set up as an audit artefact instead of a management tool. If it takes ten minutes to answer 'what's our top risk right now?', the register will lose to whatever tool answers in ten seconds - usually a whiteboard or a Slack DM.

Day 1–2 · Fixtures

Agree the scope (enterprise vs. cybersecurity vs. product), pick one owner per category, and lock the 5×5 scoring rubric. Don't invent a bespoke scale - Likelihood 1–5 (Rare → Almost certain) × Impact 1–5 (Negligible → Catastrophic) is what boards already read. Publish the rubric in one page, in plain English, with two concrete examples per level.

Day 3 · Seed the register

Bring 15–25 risks - not 200. If you have a legacy spreadsheet, take the top-of-mind risks, not everything. Every entry needs a statement ("If X, then Y, causing Z"), an owner, and inherent + current scores. Target score is optional on day 3 - you'll set those after appetite.

Day 4 · Workshop with the exec

45 minutes. Only three questions: does this belong on the register, is the owner right, is the current score defensible. Anything that stalls gets parked. The workshop is not a review - it's a calibration pass.

Day 5 · Controls & appetite

Link the controls that actually reduce each risk (SEC-001 → R-001, etc.). Get the board to sign the appetite bands: what severity is auto-acceptable, what needs an approval, what needs a formal exception. This is the step most teams skip. It's also the step that turns the register from paperwork into a decision engine.

Day 6 · Acceptances & findings

Any current-score-above-appetite risk becomes an acceptance request or a mitigation plan. Findings from your last audit or pentest get linked to the risk they touch (not the control) - you want to trace outcomes, not activity.

Day 7 · Snapshot

Generate a snapshot PDF and send it to your CFO before you send it to the board. If the CFO can't tell you the top 3 risks and their trajectory in 60 seconds, iterate the summary - not the register.

Anti-patterns

  • Scoring every risk on inherent AND current AND residual AND target - pick two. Inherent + current tells the story.
  • Colouring every cell red - if 30% of your register is red, the appetite is wrong, not the risks.
  • Making "strategic" a category. Strategy isn't a bucket; it's an owner problem.
  • Copy-pasting last year's register. If nothing has changed, either the business is dead or the register is.

Reach out at hello@riskeye.io if you want us to sit in on the day-4 workshop - we'll take notes and hand you the register on day 7.

Talk to us
Want us to walk this through with your team?

A 30-minute session with a seQure advisor is free. We'll seed a private tenant, walk through the working, and hand you super-admin keys the same day.

Keep reading