Calendar·Risk Management·Enterprise Risk
Risk Identification and the Risk Register
FACULTY OF RISK MANAGEMENTEnterprise Risk • ~30 min

How to systematically identify organizational risks and build a risk register that actually gets used — identification techniques, risk categorization, ownership, and keeping the register current.

Risk Identification and the Risk Register

Price
$79
Lessons
4
Enroll
Share
EmailLinkedIn

What this course covers

01Risk Identification Techniques: How to Surface What You Do Not Know You Are Missing
02Building a Risk Register That Reflects Operational Reality
03Risk Categories, Ratings, and the Likelihood-Impact Matrix
04Ownership, Review Cycles, and Keeping the Register Alive

Scenario

A governance review conducted by an external consultant delivered findings that surprised the leadership of a mid-sized community services organization operating across 3 urban centres in central Canada. The organization, which had grown from a volunteer-run neighbourhood initiative 15 years earlier into an operation with 47 full-time staff and an annual budget of $4.2 million, had never formalized its approach to organizational risk. The board of directors received the consultant's report in late autumn, and among its observations was a pointed note: the organization maintained no risk register, conducted no systematic risk identification process, and relied entirely on the institutional memory of its executive director and 2 long-serving program managers to anticipate and respond to threats.

The observation landed differently depending on who read it. The executive director, who had been with the organization for 11 years, initially dismissed the concern as consultant-speak disconnected from how community organizations actually function. The board chair, a retired healthcare administrator with experience in accreditation processes, recognized the gap as significant. The finance committee chair, a professional accountant, noted that the organization's liability insurer had twice requested documentation of risk management practices in the previous 18 months, requests that had been answered with general assurances rather than evidence.

The organization's operational landscape had changed substantially over the preceding 5 years. It had expanded from 1 service location to 3, added a transportation program serving elderly clients, begun accepting referrals from child welfare authorities for supervised family visits, and hired its first information technology coordinator to manage client databases containing sensitive personal information. Each expansion had proceeded without a structured assessment of associated risks, and each had introduced exposures that no one had formally documented or assigned for monitoring.

The board passed a motion directing the executive director to develop a risk register within 90 days. The motion came with no budget allocation, no template, no training resources, and no clear guidance on what the board expected the document to contain or how it should be maintained once created. The executive director now faced the task of building a risk identification and documentation system from nothing, with limited time, competing operational demands, and uncertainty about whether the resulting document would be a genuine management tool or another compliance exercise destined for a forgotten folder on the shared drive.

More in this program

Building an Enterprise Risk Framework
~50 min · $149
Risk Appetite and Tolerance: Setting the Parameters
~30 min · $79
Risk Monitoring, Reporting, and Escalation
~50 min · $149

Rate this course

Complete the course to share your rating and feedback.