How to build a 5×5 risk register in a week (without hiring a consultant)
A pragmatic 7-day plan for standing up a board-grade risk register from scratch - the fixtures, the workshops, the anti-patterns.
The single biggest reason risk registers rot is that they are set up as an audit artefact instead of a management tool. If it takes ten minutes to answer 'what's our top risk right now?', the register will lose to whatever tool answers in ten seconds - usually a whiteboard or a Slack DM.
Day 1–2 · Fixtures
Agree the scope (enterprise vs. cybersecurity vs. product), pick one owner per category, and lock the 5×5 scoring rubric. Don't invent a bespoke scale - Likelihood 1–5 (Rare → Almost certain) × Impact 1–5 (Negligible → Catastrophic) is what boards already read. Publish the rubric in one page, in plain English, with two concrete examples per level.
Day 3 · Seed the register
Bring 15–25 risks - not 200. If you have a legacy spreadsheet, take the top-of-mind risks, not everything. Every entry needs a statement ("If X, then Y, causing Z"), an owner, and inherent + current scores. Target score is optional on day 3 - you'll set those after appetite.
Day 4 · Workshop with the exec
45 minutes. Only three questions: does this belong on the register, is the owner right, is the current score defensible. Anything that stalls gets parked. The workshop is not a review - it's a calibration pass.
Day 5 · Controls & appetite
Link the controls that actually reduce each risk (SEC-001 → R-001, etc.). Get the board to sign the appetite bands: what severity is auto-acceptable, what needs an approval, what needs a formal exception. This is the step most teams skip. It's also the step that turns the register from paperwork into a decision engine.
Day 6 · Acceptances & findings
Any current-score-above-appetite risk becomes an acceptance request or a mitigation plan. Findings from your last audit or pentest get linked to the risk they touch (not the control) - you want to trace outcomes, not activity.
Day 7 · Snapshot
Generate a snapshot PDF and send it to your CFO before you send it to the board. If the CFO can't tell you the top 3 risks and their trajectory in 60 seconds, iterate the summary - not the register.
Anti-patterns
- Scoring every risk on inherent AND current AND residual AND target - pick two. Inherent + current tells the story.
- Colouring every cell red - if 30% of your register is red, the appetite is wrong, not the risks.
- Making "strategic" a category. Strategy isn't a bucket; it's an owner problem.
- Copy-pasting last year's register. If nothing has changed, either the business is dead or the register is.
Reach out at hello@riskeye.io if you want us to sit in on the day-4 workshop - we'll take notes and hand you the register on day 7.
A 30-minute session with a seQure advisor is free. We'll seed a private tenant, walk through the working, and hand you super-admin keys the same day.