Skip to main content

Five Signs Your Risk Register Is a Filing Cabinet, Not a Tool

Alyssa O'Brien6 min read

Board view with a compass and four live risk scores for third-party risk, regulatory change, incident exposure and control coverage.

Firms without board-level visibility into enterprise risk were 20% more likely1 to suffer six or more critical risk events than firms with that visibility in place. Hand a risk register to anyone who reviews these for a living, and they can usually tell how healthy the program is before reading a single line. The tell isn't the framework it's built on. It's whether the register survived contact with anything that actually happened after it was written.

Five Signs It's Become a Filing Cabinet

Risks Get Added and Almost Never Removed

A risk logged during an initial assessment tends to stay open indefinitely, technically “in progress,” because nobody wants to be the one who marks it closed. Registers accumulate entries the way a garage accumulates boxes: it's always easier to add one than to deal with what's already there.

Ownership Belongs to a Department, Not a Person

“IT” doesn't feel accountable for anything. A named individual does. A register where every risk has a department instead of a name in the owner field is a register where the mitigation plan hasn't moved in years, because nobody individually owns moving it.

The Score Is Frozen at the Initial Assessment

Scoring is supposed to be dynamic. In practice, a risk gets rated once and that score becomes gospel, even after the business has tripled in size or moved half its infrastructure to the cloud in the meantime. The number never updates because nothing in the process forces anyone to ask whether it still should.

The Heat Map Gets More Credit Than the Data Deserves

A red, yellow, green heat map looks decisive in a board deck. It's decoration if the register underneath it isn't current, and the pretty chart makes stale information look authoritative in exactly the moments that matter most.

Nobody Consults It Before a Real Decision

The real test of a risk register has nothing to do with its format. It's whether anyone opens it before a market entry, a vendor switch, a system migration. If that conversation happens in a different room than the one where the register lives, it was never a decision-making tool. It was something built to satisfy a reviewer during fieldwork.

Why Static Registers Keep Failing the Same Way

61% of senior finance leaders say the volume and complexity of the risks their organization faces has changed “mostly” or “extensively” in just the last five years,2 and 65% of executives say their approach to business continuity planning needs significant change.2 The 20% figure at the top of this piece isn't a correlation someone's guessing at either. It's the measured difference between firms where risk reaches the board continuously and firms where it reaches the board once a year, if at all. Devensa AI's vCRO vOfficer exists to keep that visibility live instead of seasonal.

The Model Most Registers Are Missing

Mature ERM programs, and the COSO ERM framework most of them follow, are typically organized around the Three Lines of Defense.

  • First line: the business operations that own and manage risk directly, day to day, as part of running the function.
  • Second line: risk and compliance functions that set policy, monitor exposure, and challenge the first line's decisions.
  • Third line: internal audit, providing independent assurance that the first two lines are doing what they report doing.

Devensa AI's TruMaturity™ Assessment scores enterprise risk management maturity against this model on the CMMI scale from Initial through Optimized, checking whether all three lines exist, whether they're staffed by named owners, and whether reporting between them actually reaches the dashboard leadership looks at, not a document that circulates separately.

Firms without board-level ERM visibility were 20 percent more likely to suffer six or more critical risk events, Forrester 2025.

Turning the Register Back Into a Tool

  • Assign every risk to a named person, not a department: a department in the owner field predicts a mitigation plan that hasn't moved in years.
  • Re-score on a trigger, not a calendar: a material business change, a new regulation, or a real incident should all prompt a re-score.
  • Require a closure date or an active update on every open risk: quarterly, at minimum, with no exceptions for “still relevant.”
  • Bring the register into the room for the next real decision: a market entry, a vendor switch, a system migration. If it isn't there, it isn't a decision-making tool yet.
  • Make board reporting continuous, not seasonal: a dashboard that updates as risk changes beats a slide deck that gets rebuilt once a year.

Frequently asked questions

What's the difference between a risk register and enterprise risk management?

A risk register is the document: a list of risks, scores, and owners. Enterprise risk management is the ongoing process that keeps that document current, connects risk across departments into one picture, and gets it in front of the board on a schedule. A register without the process behind it goes stale fast.

What framework should an ERM program be built on?

COSO ERM is the most widely referenced framework in the United States, organized around governance, strategy, performance, review, and reporting. ISO 31000 is a common international alternative.

How often should a risk register actually be updated?

Continuously for new risks as they emerge, and at minimum quarterly for a status update on existing ones. A risk untouched since its initial assessment, no matter how much time has passed, is a strong sign the register has stopped functioning as a management tool.

Can software replace a Chief Risk Officer?

Not the judgment. Devensa AI's vCRO vOfficer keeps risk scoring and reporting continuous and gets it in front of leadership on a live dashboard, but every recommendation still routes through human review before action. The platform handles the constant tracking; people still make the calls.

How do I know if my organization's risk register is actually working?

Ask whether it was consulted before the last major decision your organization made. If that conversation happened in a different room than the one where the register lives, it wasn't functioning as a decision-making tool. Was your register in the room last time?

Put Risk on a Live Dashboard, Not a Shelf

Devensa AI's vCRO vOfficer keeps risk scoring, ownership, and board reporting continuous, scored against the Three Lines of Defense and the CMMI scale, so leadership sees risk as it changes, not once a year.

Would your risk register survive being brought into the room for your next major decision?

Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai, if you'd rather start on your own.

Request a demo Join early access

Sources

  1. Forrester, The State of Enterprise Risk Management, cited via Secureframe. https://secureframe.com/blog/risk-management-statistics
  2. AICPA and NC State University, The State of Risk Oversight 2025, cited via Secureframe. https://secureframe.com/blog/risk-management-statistics