Skip to content
AuditGRC

Risk register template & risk matrix generator

Add your risks, score likelihood and impact, and see them plotted live on a configurable heat map. Export to CSV for Excel when you are done. No signup — everything stays in your browser.

· 0 risks 0 high or above

Add a risk

Risk heat map

Cells show the number of risks at each likelihood × impact combination. Score = likelihood × impact.

Risk register

Risk register, sorted by score, highest first
Risk Category Owner L I Score Rating Actions
No risks yet — add one above, or load the sample set.

How to use a risk register

A risk register is the central record of the risks your organisation has identified. Each entry captures the risk, its category and owner, likelihood and impact scores, the controls already in place, and the treatment plan. The register is only useful if it is reviewed — a register updated once a year is documentation, not risk management.

Choosing a matrix size

A 5×5 matrix (scores 1–25) is the most common in regulated industries and gives enough granularity to distinguish risks meaningfully. 3×3 suits smaller organisations starting out — it forces clearer decisions and avoids false precision. Whichever you pick, define what each level actually means in your context (what is a "major" impact in currency, downtime or customers affected?) and publish those definitions alongside the register. Undefined scales are the most common reason risk scores are inconsistent between departments.

Inherent vs residual risk

Inherent risk is the exposure before controls; residual is what remains after them. Scoring both shows how much your controls are actually doing — and where you are relying on a control that has never been tested. Regulators across the GCC increasingly expect that linkage to be demonstrable, which is where dedicated tooling starts to pay for itself over spreadsheets.

When to move off spreadsheets

A spreadsheet register works until you need workflow — assessment cycles that chase themselves, treatment actions with reminders, evidence attached to controls, and an audit trail of who changed what. At that point, compare risk management platforms or a full GRC platform. If you are heading into a selection, our requirements checklist builder turns this into an RFP.