← University
Risk Identification and the Risk Register
0 of 4

A governance review conducted by an external consultant delivered findings that surprised the leadership of a mid-sized community services organization operating across 3 urban centres in central Canada. The organization, which had grown from a volunteer-run neighbourhood initiative 15 years earlier into an operation with 47 full-time staff and an annual budget of $4.2 million, had never formalized its approach to organizational risk. The board of directors received the consultant's report in late autumn, and among its observations was a pointed note: the organization maintained no risk register, conducted no systematic risk identification process, and relied entirely on the institutional memory of its executive director and 2 long-serving program managers to anticipate and respond to threats.

The observation landed differently depending on who read it. The executive director, who had been with the organization for 11 years, initially dismissed the concern as consultant-speak disconnected from how community organizations actually function. The board chair, a retired healthcare administrator with experience in accreditation processes, recognized the gap as significant. The finance committee chair, a professional accountant, noted that the organization's liability insurer had twice requested documentation of risk management practices in the previous 18 months, requests that had been answered with general assurances rather than evidence.

The organization's operational landscape had changed substantially over the preceding 5 years. It had expanded from 1 service location to 3, added a transportation program serving elderly clients, begun accepting referrals from child welfare authorities for supervised family visits, and hired its first information technology coordinator to manage client databases containing sensitive personal information. Each expansion had proceeded without a structured assessment of associated risks, and each had introduced exposures that no one had formally documented or assigned for monitoring.

The board passed a motion directing the executive director to develop a risk register within 90 days. The motion came with no budget allocation, no template, no training resources, and no clear guidance on what the board expected the document to contain or how it should be maintained once created. The executive director now faced the task of building a risk identification and documentation system from nothing, with limited time, competing operational demands, and uncertainty about whether the resulting document would be a genuine management tool or another compliance exercise destined for a forgotten folder on the shared drive.

Risk Categories, Ratings, and the Likelihood-Impact Matrix

Risk management begins with seeing clearly. Before any organization can protect itself, respond to threats, or seize opportunities, it must first understand what it is facing. This understanding does not emerge from intuition alone, nor from a simple list of worries scribbled during a leadership meeting. It emerges from a structured process of categorization, assessment, and prioritization that transforms vague concerns into actionable intelligence. The likelihood-impact matrix, supported by thoughtful risk categories and consistent rating scales, provides the analytical foundation that Canadian organizations need to move from reactive crisis management to proactive risk governance. This lesson explores how these tools work together, why they matter for organizations of every size, and how Canadian businesses and non-profits can implement them effectively within their own operations.

The practice of categorizing risks serves a fundamental purpose that extends beyond mere organization. When risks are grouped into meaningful categories, patterns emerge that would otherwise remain invisible. A manufacturing company in Hamilton might identify a dozen individual risks related to equipment failure, supply chain delays, and quality control problems, but only when these are grouped under an operational risk category does the organization recognize that its operational vulnerabilities constitute its greatest exposure. Categories create coherence from complexity, and this coherence enables strategic resource allocation. The International Organization for Standardization, through ISO 31000:2018, establishes risk management principles that emphasize the importance of structuring risk information in ways that support decision-making, and as of the date of authorship, this standard remains the foundational international framework adopted across Canadian industries. Canadian organizations commonly employ categories that reflect both the nature of risks and the functional areas they affect. Strategic risks encompass threats and opportunities related to an organization's fundamental direction, competitive position, and long-term viability. Operational risks arise from the day-to-day activities that keep an organization functioning, including process failures, human errors, and system breakdowns. Financial risks involve exposure to currency fluctuations, credit defaults, liquidity constraints, and market volatility. Compliance risks relate to an organization's obligations under federal and provincial legislation, regulatory requirements, and contractual commitments. Reputational risks, increasingly significant in an era of instantaneous communication, involve threats to stakeholder trust and public perception. Each category demands different expertise, different controls, and different monitoring approaches, which is precisely why categorization matters.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.