Risk toolkit/Deliver

Example Risk, Control and Action Registers

Three starter registers, not system upload files. They show the fields a working framework actually needs. Replace the examples with your own, or use them as the language you agree before an implementation.

Excel workbooks

What is in the file

  1. Risk register - taxonomy, inherent and appetite positions, review vs assessment frequencies, 4Ts response, and links to controls. Eight worked examples.
  2. Control register - type, importance, cadence, design review vs operating-effectiveness assessment, and evidence. Matching controls for the risks.
  3. Action register - named owners, due dates, status, and links back to the risks. Includes planned, in progress, overdue and completed items.

What these are not

They are not implementation upload files. Owner roles, organisational scope, due-date engines and workflow routing are set during implementation. Residual scores are not typed on the risk register - they come from assessments of linked controls.

Want this running as BAU, not a file

Initia is the platform these templates were taken from. Same fields, without the reconciliation.