Most SME risk registers die the same death. They start as a thorough document, built with good intentions, and within a few months they're a list nobody looks at — too long to maintain, too generic to act on, and too stale to trust. The problem is almost never that the register was too small. It's that it was full of the wrong things. A risk register earns its place only if it drives decisions, and that means being ruthless about what goes in it.
What belongs
- Material conditions — things that would change a decision. The test for any entry is simple: if this risk materialised or worsened, would someone do something differently? Low cash runway, an overdue statutory obligation, a customer concentration that's crept past comfortable, a missing business continuity plan for a business that now depends on one — these change decisions. If an item wouldn't alter any action no matter what happened to it, it's noise dressed as diligence.
- Clear ownership. Every entry needs a name against it. Not a department, not "management" — a person responsible for the next step. Ownership is what separates a risk register from a worry list. An unowned risk is one that's been noticed and then abandoned.
- A useful review date. Risks aren't static, and a register without dates quietly becomes a snapshot of the past. Each live item should carry a date by which it's checked again — sooner for things that are moving, later for things being monitored. The date is what keeps the register alive between formal reviews.
- A plain-language reason. Anyone picking up the register should understand why an item is on it without decoding a rule code or a raw figure. "Cash runway is two months against upcoming payroll and BAS" tells the story. "F-01 breach" doesn't.
- Evidence that it was reviewed. A decision recorded against an item — accepted, assigned, deferred, resolved, with context — turns the register from a list of problems into a record of judgement applied. That record is what you stand behind when a client, board or regulator asks how a risk was handled.
What doesn't
- Theoretical risks with no owner and no trigger. "Economic downturn could affect revenue" is true of every business on earth. Unless it's specific, owned and actionable, it's filler that makes the real risks harder to see.
- Duplicates and over-granular noise. Ten variations of the same cash concern don't make the register more thorough — they bury the one entry that matters. Consolidate to the material condition and its connected effects, not every metric that touched it.
- Vanity entries. Risks added to look comprehensive, that nobody intends to act on, teach everyone to skim past the register. Each dead entry lowers the credibility of the live ones.
- Stale items never reviewed. An item with a review date three months in the past is worse than no item — it signals the whole register isn't maintained, which means none of it can be trusted. Close, resolve, or re-date, but don't let entries rot.
Governance and financial items are different — and both belong
Financial risks (cash, margin, receivables, payroll) recalculate from the numbers and often resolve themselves as the position changes. Governance and statutory items (a continuity plan, a registration, a policy) are usually confirmed once and revisited on a trigger. A good register handles both, but treats them differently: financial items stay live until the metric improves; governance items clear once reviewed and resurface when something expires or the business changes scale. Mixing the two without distinction is how registers get cluttered — governance items that were dealt with months ago sitting in the active list, crowding out the cash issue that needs attention today.
Keeping it alive
A register is only as good as the discipline around it: material items in, noise out, an owner and a date on everything live, decisions recorded, and closed items actually closed. Do that and it becomes the thing it was always meant to be — not a document you produce because you should, but the shortlist your review actually runs from. If it isn't driving decisions, it isn't a risk register. It's paperwork.
Orbiant turns this kind of structured review into a repeatable workflow — surfacing priority issues, recording decisions, and keeping a defensible trail across every client.
See how it works for advisors