← University
Risk Identification and the Risk Register
0 of 4

A governance review conducted by an external consultant delivered findings that surprised the leadership of a mid-sized community services organization operating across 3 urban centres in central Canada. The organization, which had grown from a volunteer-run neighbourhood initiative 15 years earlier into an operation with 47 full-time staff and an annual budget of $4.2 million, had never formalized its approach to organizational risk. The board of directors received the consultant's report in late autumn, and among its observations was a pointed note: the organization maintained no risk register, conducted no systematic risk identification process, and relied entirely on the institutional memory of its executive director and 2 long-serving program managers to anticipate and respond to threats.

The observation landed differently depending on who read it. The executive director, who had been with the organization for 11 years, initially dismissed the concern as consultant-speak disconnected from how community organizations actually function. The board chair, a retired healthcare administrator with experience in accreditation processes, recognized the gap as significant. The finance committee chair, a professional accountant, noted that the organization's liability insurer had twice requested documentation of risk management practices in the previous 18 months, requests that had been answered with general assurances rather than evidence.

The organization's operational landscape had changed substantially over the preceding 5 years. It had expanded from 1 service location to 3, added a transportation program serving elderly clients, begun accepting referrals from child welfare authorities for supervised family visits, and hired its first information technology coordinator to manage client databases containing sensitive personal information. Each expansion had proceeded without a structured assessment of associated risks, and each had introduced exposures that no one had formally documented or assigned for monitoring.

The board passed a motion directing the executive director to develop a risk register within 90 days. The motion came with no budget allocation, no template, no training resources, and no clear guidance on what the board expected the document to contain or how it should be maintained once created. The executive director now faced the task of building a risk identification and documentation system from nothing, with limited time, competing operational demands, and uncertainty about whether the resulting document would be a genuine management tool or another compliance exercise destined for a forgotten folder on the shared drive.

Building a Risk Register That Reflects Operational Reality

A risk register is not a compliance artifact or a document created to satisfy auditors and then filed away until the next review cycle. It is a living operational tool that, when constructed thoughtfully, reflects the actual texture of organizational risk as experienced by the people who manage operations, deliver services, and make daily decisions. The distinction matters because too many Canadian organizations treat risk registers as theoretical exercises disconnected from the realities of their operations, and this disconnect undermines the entire purpose of enterprise risk management. A risk register that does not reflect operational reality is worse than useless—it creates a false sense of security, diverts attention from genuine threats, and can expose an organization to liability when post-incident review reveals that documented risks bore no relationship to actual hazards.

The foundation of an effective risk register lies in understanding what the document must accomplish. At its core, a risk register catalogues the risks an organization faces, describes their potential impact, estimates their likelihood, identifies existing controls, and tracks planned responses. This sounds straightforward, but the execution determines whether the register serves as a genuine decision-support tool or becomes bureaucratic theatre. The International Organization for Standardization's ISO 31000:2018 standard, which provides guidance on risk management principles and implementation, emphasizes that risk management must be integrated into organizational governance and decision-making processes. As of the date of authorship, ISO 31000 remains the predominant international framework referenced by Canadian organizations across sectors, though it operates alongside sector-specific requirements in regulated industries such as financial services, healthcare, and resource extraction.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.