Most organisations have a risk register. Few have one that is actively used to manage risk. The difference between a compliance artifact and a management tool is where effective GRC begins.
A spreadsheet of risks is an artifact. A risk process is the set of decisions and reviews that keeps that artifact honest and useful. When a register stops being maintained, it is almost always because the process around it was never designed.
In order of impact: