The biggest risk in any organisation is the risk nobody knows about. Serious work therefore starts by gathering what people in the field know, not what the head office imagines.
1 Methods for surfacing risks
- Workshops: a session with the management team to draw out risks through structured discussion.
- One-to-one interviews: an employee will say in private what they would not say in front of their manager.
- Analysing historical data: breakdowns, complaints and recurring errors point to the weak spots.
- Internal and external audit findings: a ready and rich source of risks.
- Checklists by sector, the experience of comparable organisations, and market events.
- Process analysis: walk the process step by step and ask: what if this step failed?
The question that opens the door
In any workshop, ask: “What one thing, if it happened next week, would wreck our plan?” And then: “What stops it today?” — the second answer is your existing controls.
2 Wording the risk
Because of…
The existing weakness or circumstance
there is a chance that…
The uncertain event
leading to…
The effect on the objective
A three-part formula that makes a risk measurable, treatable and trackable
3 The risk register
The risk register is a single table gathering all identified risks and their status. These are its core columns:
| Column | What it holds |
|---|---|
| Reference | A fixed identifier for tracking the risk over time |
| Risk description | In the three-part form: cause, event, effect |
| Category | Strategic / financial / operational / compliance / technology / reputation |
| Risk owner | A person by their role, not a department with no name attached |
| Existing controls | What is actually in place today |
| Impact and likelihood | Before controls (inherent) and after them (residual) |
| Treatment required | The action, the owner and the date |
| Indicator | What is monitored to reveal the risk moving |
| Status | Open / in treatment / closed / accepted |
| Reference | MR-07 |
| Description | Because collections rely on manual follow-up, customer receivables may age beyond 90 days, squeezing liquidity and delaying payments to suppliers |
| Category | Financial |
| Owner | Finance director |
| Existing controls | Monthly receivables ageing report · collector follow-up calls |
| Impact / likelihood | High / medium |
| Treatment | An approved credit policy · a credit limit per customer · an automatic alert at 30 days — owner: the CFO — date: end of quarter |
| Indicator | Share of receivables over 90 days as a proportion of total receivables |
| Status | In treatment |
4 The risk owner
Every risk has one owner who holds the decision and the resources needed to treat it. The risk owner is not whoever writes the register, but whoever can actually do something about it. A risk with no defined owner sits in the register for years without moving.
Mistakes that ruin a register
Generic risks with no cause or effect · an undefined owner · controls written down but not actually applied · confusing a risk with a problem that has occurred · a register so long nobody reads it. A register of 20 risks that is followed up beats 200 risks that are filed away.
Lesson summary
- Surfacing risks depends on the field: workshops, interviews, data and audit findings.
- The three-part wording (cause, event, effect) makes a risk manageable.
- The risk register is a living document with clear columns and an up-to-date status.
- Every risk has one owner who holds the decision and the resources.
- A short register that is followed up is more useful than a huge one that is archived.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. Who is the most appropriate owner of the risk of delayed collections?
The owner is whoever holds the decision and the resources to treat the risk — here, finance. The risk team facilitates and follows up, and the auditor verifies.
2. Which of the following is not a risk identification method?
Preparing the statements is routine accounting work, although its results may reveal indicators later used in identification.
3. What is the difference between inherent and residual risk?
The gap between the two measures the effectiveness of existing controls: the wider it is, the more the controls are doing.