Enterprise Risk Register — ISO 31000-Aligned Framework
A rigorous risk register for boards that need more than a single-rating spreadsheet — built around the ISO 31000 risk management process.
Most risk registers show one rating per risk and call it done. That's usually the first gap an experienced reviewer finds — because it doesn't show whether your controls are actually working.
This register rates every risk twice: inherent (before controls) and residual (after controls) — so the Committee can see at a glance where controls are genuinely reducing exposure, and where they're not. Each risk is then automatically checked against a Board-agreed risk appetite threshold, so “is this acceptable?” has a defined answer instead of a judgement call every time.
What's Included
• Context & Scope tab — documents the internal and external context risk is being assessed against, per ISO 31000's “establishing the context” step
• Risk Appetite Statement — Board-agreed appetite thresholds by risk category, feeding directly into the register
• Inherent & residual risk analysis — rated separately, with a live formula flagging whether residual risk sits within or outside appetite
• Consultation tracking — records who was involved in identifying and assessing each risk
• Pre-built example risks across financial, compliance, cyber, and strategic categories
• Strategic Risk Identification Guide (Word) — process, definitions, and worked examples for identifying strategic risk, included with every purchase
Who It's For
Boards and Audit & Risk Committees at commercial, ASX-listed, or larger complex organisations that need a genuinely mature risk framework — not a template built for a small NFP's operational risk log.
Format
Excel workbook (.xlsx), fully editable with dropdown validation and working formulas, plus a Word guide (.docx). Instant digital download.