{{ summaryTitle }}
{{ summaryValue }}

{{ summaryLine }}

Active{{ resultsReady ? computation.values.active_count : '—' }} Owner gaps{{ resultsReady ? computation.values.owner_gap_count : '—' }} Threshold{{ resultsReady ? `${computation.values.attention_threshold}/${computation.values.max_score}` : '—' }}
{{ summaryAnnouncement }}
Risk register source and scoring controls
Legacy five-column rows also work: risk, likelihood, impact, owner, response.
{{ sourceStatus || 'Drop one CSV or TXT file onto the source field.' }}
Used in the summary and review brief.
Choose the context in which reviewers will use the register.
Use 5×5 for finer prioritization or 3×3 for a quick workshop.
Valid range: 1 to {{ matrixMaximum }}.
points
Conservative language emphasizes escalation; open language emphasizes explicit acceptance decisions.
Entered residual ratings always take priority over this estimate.
Critical and high rows are scheduled sooner than the default cadence.
Critical rows use at most 3 days; high rows use at most 7 days.
days
Residual-first keeps the post-treatment backlog prominent.
The neutral default excludes archived rows from active artifacts.
{{ include_closed ? 'Enabled' : 'Disabled' }}
IDRisk statementCategoryInherentResidualOwnerResponseTriggerReviewStatusCopy
{{ row.id }}{{ row.risk }}{{ row.category }}{{ row.inherentScore }} · {{ row.inherentBand }}{{ row.residualScore }} · {{ row.residualBand }}{{ row.owner }}{{ row.response }}{{ row.trigger }}{{ row.reviewDate }}{{ row.status }}
{{ tableExportStatus }}
PriorityRiskOwnerNext actionReviewResidualCopy
{{ row.priority }}{{ row.id }} · {{ row.risk }}{{ row.owner }}{{ row.nextAction }}{{ row.reviewDate }}{{ row.residualScore }}
{{ tableExportStatus }}
{{ chartExportStatus }}

The chart renderer is unavailable. The scored rows remain available in the register.

{{ briefExportStatus }}
{{ reviewBrief }}

A risk register records uncertain events before they become incidents, missed milestones, control failures, or unplanned costs. Each row should be specific enough to assign an owner, watch an early warning, choose a response, and decide when the risk must be reviewed again.

Risk and issue are not interchangeable. A risk may occur, so a team can still avoid, reduce, transfer, accept, monitor, or escalate it. An issue has already occurred and usually needs an action plan, incident record, or decision log. Keeping that distinction clear prevents current problems from disappearing inside a future-risk list.

Core risk register concepts
ConceptQuestion it answersCommon mistake
LikelihoodHow likely is the event on the chosen scale?Treating a label as a measured probability.
ImpactHow serious is the consequence if it occurs?Using different impact meanings across rows.
Inherent exposureHow large is the risk before treatment?Comparing it with residual scores as if both use the same assumptions.
Residual exposureWhat remains after treatment?Assuming planned controls already work.
TriggerWhat observable change should prompt action?Writing a vague warning that cannot be monitored.

Semi-quantitative scores make a long register easier to sort, but they do not forecast loss or probability. Their value comes from consistent definitions, evidence, accountable owners, dated reviews, and explicit acceptance decisions. Changing from a 5 × 5 to a 3 × 3 matrix also changes the score range, so thresholds and comparisons must use the same matrix.

How to Use This Tool:

Choose one scoring convention for the review and make every risk row traceable to an owner or an explicit owner gap.

  1. Paste pipe-delimited, tab-delimited, or CSV rows. A header can map risk, category, ratings, owner, response, trigger, review date, residual ratings, and status; legacy five-column rows also work.
  2. Select the Scoring matrix and set an Attention threshold no higher than 25 for 5 × 5 or 9 for 3 × 3.
  3. Choose how missing residual ratings are estimated. Entered residual likelihood and impact always override the estimate.
  4. Set the review anchor and default cadence, then review the generated rows for inferred categories, rating conversions, owners, responses, triggers, and dates.
  5. Work through Treatment queue from owner gaps and high residual exposure downward. Confirm the ratings and decisions with the accountable team before relying on the review brief.

Interpreting Results:

Risks need attention counts active rows whose inherent or residual score is greater than or equal to the chosen threshold. Top residual exposure identifies the highest remaining score, not the most certain future event.

Owner gaps appear before other queue items because no treatment can be governed without accountability. A lower residual score is encouraging only when the residual ratings reflect implemented, tested controls. If they were estimated from response wording, treat them as a planning assumption and replace them with reviewed ratings when evidence is available.

Technical Details:

The scoring model multiplies ordinal likelihood and impact ratings. It is a transparent prioritization heuristic, not an ISO or NIST probability model. ISO 31000 and NIST guidance support structured identification, analysis, treatment, monitoring, and communication, but they do not prescribe these exact bands or response estimates.

Formula Core:

Inherent and residual exposure use the same multiplication rule, with ratings bounded by the selected matrix size.

Rinherent=Linherent×Iinherent,Rresidual=Lresidual×Iresidual

A 3 × 3 matrix produces scores from 1 to 9; a 5 × 5 matrix produces scores from 1 to 25. Numeric ratings are rounded and kept within the matrix. Text labels map to ordinal positions: low is 1, medium is 2 on 3 × 3 or 3 on 5 × 5, and high is the matrix maximum.

Rule Core:

Band boundaries are percentages of the matrix maximum, so they apply consistently to both matrix sizes.

Risk score band boundaries
BandBoundary5 × 5 scores3 × 3 scores
CriticalScore ÷ maximum ≥ 0.7218 to 257 to 9
High0.48 ≤ ratio < 0.7212 to 175 to 6
Moderate0.24 ≤ ratio < 0.486 to 113 to 4
LowRatio < 0.241 to 51 to 2

When residual ratings are absent, the selected treatment policy changes ratings according to response wording. Avoidance lowers likelihood and impact by 1, or by 2 under the strong policy. Transfer lowers impact by 1 or 2. Mitigation or escalation lowers likelihood by 1 and, under the strong policy, impact by 1. Strong monitoring lowers likelihood by 1. No-effect policy leaves both ratings unchanged, and every result remains between 1 and the matrix maximum.

Review scheduling rules by residual risk band
Residual bandGenerated review interval
CriticalThe earlier of 3 days or the default cadence
HighThe earlier of 7 days or the default cadence
ModerateAt least 7 days and no more than 14 days
LowAt least 21 days

An entered review date is retained when it has YYYY-MM-DD form; otherwise the interval is added to the review anchor. Queue priority is owner gap first, then residual score at or above the threshold, inherent score at or above the threshold, moderate-or-higher residual band, and finally monitoring. Closed risks are excluded unless explicitly included.

Accuracy and Privacy Notes:

Risk rows and imported files are processed in the browser. Avoid pasting secrets, personal data, or restricted incident details into material that may be shared. Generated categories, responses, residual estimates, review dates, and queue positions are planning aids; they do not replace accountable review, evidence, policy, or legal and regulatory requirements.

Worked Examples:

Explicit residual rating

A 5 × 5 row with high likelihood and very high impact scores 20 and falls in Critical. If reviewed residual ratings are medium likelihood and high impact, the residual score is 12 and falls in High. Those entered residual ratings take priority over any response-based estimate.

Unassigned low score

A low-likelihood, low-impact row scores 1, but a blank owner still places it at the top queue priority as an Owner gap. Low exposure does not remove the need for accountability.

References: