Why your risk register isn't working — and five things to fix it

Most organisations have a risk register. Few have one that is actively used to manage risk. The difference between a compliance artifact and a management tool is where effective GRC begins.

A spreadsheet of risks is an artifact. A risk process is the set of decisions and reviews that keeps that artifact honest and useful. When a register stops being maintained, it is almost always because the process around it was never designed.

In order of impact: