← University
Risk Identification and the Risk Register
0 of 4

A governance review conducted by an external consultant delivered findings that surprised the leadership of a mid-sized community services organization operating across 3 urban centres in central Canada. The organization, which had grown from a volunteer-run neighbourhood initiative 15 years earlier into an operation with 47 full-time staff and an annual budget of $4.2 million, had never formalized its approach to organizational risk. The board of directors received the consultant's report in late autumn, and among its observations was a pointed note: the organization maintained no risk register, conducted no systematic risk identification process, and relied entirely on the institutional memory of its executive director and 2 long-serving program managers to anticipate and respond to threats.

The observation landed differently depending on who read it. The executive director, who had been with the organization for 11 years, initially dismissed the concern as consultant-speak disconnected from how community organizations actually function. The board chair, a retired healthcare administrator with experience in accreditation processes, recognized the gap as significant. The finance committee chair, a professional accountant, noted that the organization's liability insurer had twice requested documentation of risk management practices in the previous 18 months, requests that had been answered with general assurances rather than evidence.

The organization's operational landscape had changed substantially over the preceding 5 years. It had expanded from 1 service location to 3, added a transportation program serving elderly clients, begun accepting referrals from child welfare authorities for supervised family visits, and hired its first information technology coordinator to manage client databases containing sensitive personal information. Each expansion had proceeded without a structured assessment of associated risks, and each had introduced exposures that no one had formally documented or assigned for monitoring.

The board passed a motion directing the executive director to develop a risk register within 90 days. The motion came with no budget allocation, no template, no training resources, and no clear guidance on what the board expected the document to contain or how it should be maintained once created. The executive director now faced the task of building a risk identification and documentation system from nothing, with limited time, competing operational demands, and uncertainty about whether the resulting document would be a genuine management tool or another compliance exercise destined for a forgotten folder on the shared drive.

Ownership, Review Cycles, and Keeping the Register Alive

A risk register that sits untouched in a shared drive, accumulating digital dust while the organization it was meant to protect evolves and changes, serves no protective function whatsoever. The document becomes a historical artifact rather than a living instrument of governance. This final lesson addresses what separates functional risk management from performative compliance: the establishment of clear ownership, the discipline of regular review cycles, and the organizational commitment required to keep a risk register responsive to emerging threats and opportunities. Without these elements, the considerable effort invested in identifying risks and constructing a register yields diminishing returns with each passing month.

The concept of risk ownership emerges from a fundamental truth about organizational behaviour: risks that belong to everyone effectively belong to no one. When a risk register lists hazards without assigning specific individuals the responsibility to monitor, mitigate, and report on those risks, the document becomes an exercise in collective avoidance. Each person who encounters an unowned risk reasonably assumes that someone else must be handling it. This diffusion of responsibility creates dangerous gaps in organizational awareness, allowing known risks to materialize into incidents while multiple people assume the situation is under control. The Canadian Standards Association's risk management framework, known as CSA Z1600 as of the date of authorship, explicitly addresses this concern by emphasizing that risk management requires defined roles, responsibilities, and authorities at appropriate organizational levels.

Risk ownership does not mean that a single individual must personally execute every control measure or monitoring activity associated with a given risk. Rather, ownership establishes accountability for ensuring that appropriate attention is paid to the risk, that control measures are functioning as intended, that changes in the risk profile are detected and communicated, and that escalation occurs when circumstances warrant senior attention. The risk owner serves as the point of integration, connecting various organizational functions that might each contribute to managing different aspects of a complex risk. For a construction company in Edmonton facing risks related to extreme weather events, the project manager designated as risk owner might coordinate between equipment maintenance personnel, scheduling staff, safety officers, and subcontractors without personally performing each function. The owner's role is to ensure nothing falls through organizational cracks.

Selecting appropriate risk owners requires careful consideration of several factors that Canadian organizations sometimes neglect. The owner must possess sufficient authority to direct resources toward risk mitigation and to escalate concerns when existing controls prove inadequate. Assigning risk ownership to junior staff who lack decision-making authority creates the appearance of accountability without its substance. Simultaneously, risk owners must possess relevant technical or operational knowledge about the risk domain. A financial controller assigned ownership of cybersecurity risks may struggle to evaluate whether technical controls are appropriately designed, while an information technology manager assigned ownership of financial reporting risks may miss nuances in accounting standards and internal control requirements. The most effective ownership assignments match organizational authority with domain expertise, though perfect alignment is not always possible.

Review cycles represent the heartbeat of a living risk register, determining how frequently the organization examines its risk profile, validates existing assessments, and considers emerging threats. The appropriate frequency varies dramatically based on organizational context, risk velocity, and regulatory requirements. A technology startup in Toronto operating in a rapidly evolving market might require monthly reviews to capture the pace of competitive and technological change, while a stable non-profit providing community services in Halifax might find quarterly reviews sufficient for most operational risks. The key is matching review frequency to the rate at which underlying conditions change, recognizing that different risks within the same organization may warrant different review cadences.

Canadian regulatory frameworks impose specific review requirements in certain sectors that establish minimum standards for risk register maintenance. The Office of the Superintendent of Financial Institutions, the federal regulator overseeing banks, insurance companies, and federally regulated pension plans, expects that risk assessments reflect current conditions and that governance bodies receive regular reporting on material risks. As of the date of authorship, OSFI's Corporate Governance Guideline emphasizes that boards must satisfy themselves that management has implemented appropriate risk management processes and that these processes function effectively over time. Organizations subject to OSFI oversight cannot treat risk registers as annual compliance exercises; continuous attention to evolving risks is an embedded regulatory expectation.

Beyond regulatory minimums, effective review cycles incorporate both scheduled and triggered reviews. Scheduled reviews occur at predetermined intervals regardless of whether any specific event has occurred, providing regular opportunities to validate that existing risk assessments remain accurate and that control measures continue to function. These scheduled reviews prevent organizational drift, where gradual changes accumulate unnoticed until a significant gap has developed between the risk register's contents and operational reality. Triggered reviews occur in response to specific events that signal potential changes to the risk landscape: significant incidents, near-misses, regulatory changes, major organizational restructuring, new strategic initiatives, or shifts in the external environment. An organization that conducts only scheduled reviews may miss critical developments between review dates, while an organization that relies exclusively on triggered reviews may allow less dramatic but still significant changes to accumulate unaddressed.

The discipline of keeping a risk register alive requires organizational commitment that extends far beyond the risk management function. Every employee who encounters changing conditions, emerging threats, or control failures becomes a potential source of intelligence that should inform the risk register. Cultivating this awareness requires deliberate effort. Staff must understand what the risk register is, why it matters, and how their observations can contribute to its accuracy. Organizations that treat risk registers as confidential documents accessible only to senior management sacrifice the early warning benefits that come from broad organizational awareness. While certain sensitive details might warrant restricted access, the general framework of organizational risks and the invitation to report relevant observations should extend throughout the workforce.

Consider a medium-sized manufacturing company operating in Saskatoon with approximately one hundred and twenty employees across production, administration, and sales functions. The organization produces specialized agricultural equipment and has maintained a risk register since its founding fifteen years ago. Initially, the register was a straightforward document listing equipment breakdown, supplier disruption, and workplace injury as primary concerns. The founder personally reviewed the register each December, making updates based on the previous year's experiences and his intuitions about the coming year. This informal approach served adequately when the company was small and the founder maintained direct involvement in all operational aspects.

As the company grew, this annual personal review became increasingly inadequate. The founder, now serving as chief executive, no longer possessed firsthand knowledge of daily operations across all departments. New risks emerged that he lacked the technical background to identify, including cybersecurity vulnerabilities in the company's increasingly computerized production systems and intellectual property concerns as competitors began producing similar products. The annual review cycle meant that significant changes in the risk landscape, such as the departure of a key supplier's quality control manager which preceded a noticeable decline in component reliability, went unrecognized for months. When a production line failure resulted in a missed delivery deadline and a substantial customer penalty, the investigation revealed multiple warning signs that had occurred throughout the year but never reached anyone with authority to act.

The company responded by fundamentally restructuring its approach to risk register maintenance. The chief executive designated specific risk owners for different categories of organizational risk, selecting individuals based on their operational authority and domain knowledge. The production manager assumed ownership of manufacturing and supply chain risks. The chief financial officer took responsibility for financial, credit, and insurance-related risks. A newly hired information technology manager became owner of cybersecurity and technology risks. The sales director assumed ownership of customer relationship and market risks. Each owner received training on their responsibilities, which included not only monitoring their assigned risks but also actively soliciting information from staff working in relevant areas.

The company established a formal review structure with multiple time horizons. Each risk owner conducts a monthly scan of their assigned risks, documenting any changes in conditions, control effectiveness, or emerging concerns. These monthly scans take approximately two hours and involve conversations with key staff, review of incident reports, and consideration of external developments such as industry news or regulatory changes. Quarterly, the full leadership team convenes for a comprehensive risk review meeting lasting approximately half a day. Each owner presents a summary of their domain, highlighting any risks requiring attention and proposing modifications to assessments or controls. This quarterly meeting serves as the primary forum for cross-functional discussion, allowing the team to identify risks that span multiple domains or require coordinated responses. Annually, the board of directors receives a formal risk report summarizing the year's developments, current risk profile, and planned mitigation initiatives for the coming year.

The company also established triggered review protocols. Any significant incident, defined as an event causing or potentially causing material harm to people, property, finances, or reputation, automatically triggers a risk register review within five business days. The relevant risk owner convenes an informal team to assess whether the incident reveals previously unidentified risks, whether existing risk assessments require modification, and whether control measures functioned as intended. This triggered review process ensures that the organization learns from its experiences rather than simply recovering from incidents and moving on.

Three years after implementing this structured approach, the company experienced a cybersecurity incident when an employee clicked a malicious link in a convincing phishing email. The information technology manager, serving as cybersecurity risk owner, had previously identified phishing as a moderate probability and high consequence risk and had implemented employee training and email filtering controls. When the incident occurred, the triggered review process activated immediately. The investigation revealed that the existing controls had reduced but not eliminated vulnerability, that the specific phishing technique was relatively new and had evaded the email filter, and that the affected employee had completed mandatory training but still fell for a sophisticated social engineering approach. The risk owner updated the register to reflect the proven inadequacy of existing controls, proposed additional technical measures including multi-factor authentication for sensitive systems, and recommended enhanced training focused on the specific techniques used in the recent attack. The board received an interim report given the incident's significance, and the annual risk review included detailed discussion of cybersecurity evolution.

This example illustrates several critical elements of effective risk register maintenance. Clear ownership ensures that each risk domain receives consistent attention from someone with appropriate authority and expertise. Structured review cycles create regular opportunities to validate assessments and catch gradual changes before they accumulate into significant gaps. Triggered reviews enable the organization to learn from incidents in real time rather than waiting for scheduled review dates. Communication channels, including the employee's willingness to immediately report the phishing click rather than concealing the error, allow operational intelligence to flow to decision-makers. Board engagement ensures governance oversight without requiring directors to manage operational details.

Quebec organizations should note that the civil law framework in that province creates distinctive considerations for risk register maintenance in certain contexts. While the general principles of ownership and review apply equally across Canadian jurisdictions, Quebec's Civil Code imposes specific obligations regarding organizational due diligence that may require documentation demonstrating ongoing risk management attention. Administrators of legal persons under Quebec law, which includes directors and officers of corporations and non-profits, bear particular responsibility for acting with prudence and diligence in accordance with Article 322 of the Civil Code of Quebec as of the date of authorship. A risk register that clearly documents regular review and active maintenance provides evidence of this prudent and diligent administration, while a stale and neglected register might suggest governance shortcomings. This documentation function makes consistent review cycles particularly valuable for Quebec organizations.

Non-profit organizations across Canada face distinctive challenges in maintaining risk registers that warrant specific attention. These organizations often operate with limited administrative capacity, relying heavily on volunteers and stretched professional staff. Assigning risk ownership to board members rather than employees may seem attractive given authority considerations, but creates practical difficulties when board members meet only periodically and lack daily operational involvement. The most effective approach for many non-profits involves dual ownership structures, pairing a board member who provides governance oversight with a staff member or senior volunteer who provides operational monitoring. This arrangement ensures that risks receive regular attention through operational involvement while maintaining governance-level accountability.

Review cycle design for non-profits must accommodate typical governance structures. Many Canadian non-profits conduct monthly board meetings, quarterly committee meetings, and annual general meetings. Aligning risk review cycles with these existing governance rhythms reduces administrative burden while ensuring regular attention. A monthly executive director review, quarterly risk committee discussion, and annual board presentation mirrors the structure that proved effective for the Saskatoon manufacturer while adapting to typical non-profit governance arrangements.

Financial constraints on non-profits sometimes lead to deferred attention to risk register maintenance as organizations prioritize direct service delivery. This creates particular vulnerability precisely because non-profits often operate with thin margins and limited reserves that leave little capacity to absorb unexpected costs from materialized risks. A community health organization in Winnipeg that neglects its risk register to focus available resources on client services may find itself unable to continue operations if an unmanaged risk materializes into a significant incident. The discipline of maintaining active risk oversight, even with modest time investment, protects the organization's capacity to pursue its mission over the long term.

Professional service firms, including those in accounting, law, engineering, and healthcare, face regulatory requirements that reinforce the importance of active risk management. Professional regulatory bodies across Canada increasingly expect that their members and member firms demonstrate systematic attention to risk. The approaches vary by profession and jurisdiction, but a common thread involves expectation that firms can demonstrate they have identified relevant risks to client service and professional standards and have implemented appropriate controls. A risk register that clearly documents regular review and ownership provides evidence of this systematic attention, potentially becoming relevant during regulatory investigations or professional liability claims.

The practical steps for keeping a risk register alive can be summarized through a series of questions that organizations should regularly ask themselves. First, has every significant risk in the register been assigned to a specific named individual who possesses both the authority to direct resources and the expertise to evaluate the risk domain? Second, has the organization established a formal schedule for reviewing the register that matches review frequency to the pace of change in relevant risk domains? Third, has the organization defined specific events or conditions that should trigger ad hoc risk reviews outside the regular schedule? Fourth, does the organization have functioning communication channels that allow staff at all levels to report relevant observations to risk owners? Fifth, does the organization's governance body receive regular reporting on risk management activities sufficient to provide effective oversight? Sixth, when the organization has experienced significant incidents, has it systematically captured lessons learned through risk register updates?

Documentation practices deserve attention as organizations mature their risk management approaches. Each formal review, whether scheduled or triggered, should generate a record indicating who participated, what was considered, what decisions were reached, and what follow-up actions were assigned. These records serve multiple functions. They create accountability by establishing clear expectations about who will do what by when. They enable continuity when personnel change by providing incoming risk owners or executives with historical context. They provide evidence of due diligence that may prove valuable in regulatory inquiries, litigation, or insurance claims. And they enable organizational learning by preserving institutional memory of why particular decisions were made.

The volume and formality of documentation should scale with organizational size and risk complexity. A sole proprietor operating a consulting practice in Montreal need not generate extensive written records for each risk review, though periodic notes capturing key observations and decisions remain valuable. A large resource extraction company operating in northern Alberta, facing substantial safety, environmental, and regulatory risks, requires correspondingly more formal documentation including meeting minutes, decision records, and audit trails. The guiding principle is that documentation should be sufficient to demonstrate that the organization paid appropriate attention to risk management and made considered decisions, without creating administrative burden disproportionate to organizational capacity and risk profile.

As Canadian organizations face increasingly complex and rapidly evolving risk landscapes, the discipline of maintaining living risk registers becomes ever more critical. Climate change introduces physical risks to facilities and operations while transitional risks emerge from shifting regulatory requirements and market expectations. Cybersecurity threats evolve continuously as malicious actors develop new techniques and exploit newly discovered vulnerabilities. Supply chain disruptions that seemed exceptional during recent global events now appear as recurring features of the operating environment. Demographic shifts affect workforce availability and customer expectations across industries and regions. Organizations that treat risk identification as a one-time exercise, rather than an ongoing discipline, will find their risk registers increasingly disconnected from operational reality.

The investment required to maintain a living risk register need not be overwhelming. Many Canadian small and medium businesses successfully maintain effective risk oversight through structured monthly reviews taking two or three hours, quarterly executive discussions taking half a day, and annual governance presentations. The key is consistency and commitment rather than elaborate process. An organization that dedicates modest but regular attention to its risk register will dramatically outperform one that conducts intensive annual exercises followed by eleven months of neglect. The register becomes living not through complexity but through regularity, ownership, and genuine organizational commitment to understanding and managing the risks that could threaten mission, reputation, and survival.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options