Name your real risks across the whole organization, rank them by how damaging and how likely they are, and put an owner on the serious ones, so exposure comes out of the shadows.
First in Find and Manage Your Risks, and revisited on a regular rhythm.
Work across each area. For each risk, name what could go wrong, how likely it is, and how damaging. People and safety outranks the others; anyone at risk right now is handled immediately, not logged.
| Area | What could go wrong | How likely | How damaging | Owner |
|---|---|---|---|---|
| People and safety | ||||
| Money and fraud | ||||
| Property and operations | ||||
| Contracts and partners | ||||
| Data and privacy | ||||
| Reputation |
Mark the risks that are both likely and damaging as your priorities, and put a named owner on each. Priority risks feed the insurance, contract-and-data, and people-safety work. A risk register is only useful if it is reviewed, so put a standing review on a rhythm, at least once a year with the board.
Your answers stay in your browser on this page and are never sent anywhere. Use Save or print to keep your copy.