Risk Register
Track risks with likelihood, impact, owners, mitigations, status and review dates, then receive a Monday digest of risks due for review.
Included with every MangoApps plan.
Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.
Built for: Professional Services · Construction And Engineering · Financial Services · Healthcare Operations · Technology And Saas
Overview
The Risk Register is a working app for recording and reviewing risks in a MangoApps workspace. Each record has a required Risk description, a Category of Delivery, Financial, People, Compliance or Technical, required Likelihood and Impact values, an Owner, a Mitigation, a required Status of Open, Mitigating or Closed, and a Next review date. Together, these fields show what could happen, how serious it may be, who is responsible and what response is in progress.
Only managers and admins add records, which gives the register a controlled data-entry posture. Records can be edited or deleted, so administrators should agree how changes are governed if the register is used as an important management record. The Overview screen provides a metric row and board for a quick read, while the Register screen provides a grid and action bar for maintaining the full list.
Use the Open risks view for routine management, High impact for escalation and leadership discussion, and Review due in 30 days to prepare upcoming reassessments. The Monday review list runs at 08:00 each week and sends the app owner an AI summary digest titled Risks due for review. This template is not intended to replace a formal enterprise risk framework, incident log or audit evidence repository. It is best for a focused operational register where managers need a consistent record and a dependable review cue.
Standards & compliance context
- The Compliance category helps organisations identify and assign policy or regulatory exposure, but the register does not by itself demonstrate compliance with a specific law or standard.
- Use the register alongside your documented risk-management, approval and evidence-retention procedures when risks affect regulated activities.
- Because records can be edited and deleted, confirm whether your organisation needs a separate append-only record or audit trail for formal assurance purposes.
General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.
How to use this template
- Add the Risk Register template to your MangoApps workspace and confirm that managers and admins are the people allowed to add records.
- Create one record for each material risk, entering the Risk, Category, Likelihood, Impact, Owner, Mitigation, Status and Next review date rather than combining several risks in one description.
- Use the Overview screen for the metric row and board, then open the Register screen when managers need to inspect or update the full grid.
- Review Open risks and High impact risks regularly, and use the Review due in 30 days view to prepare the next risk discussion.
- Act on the Monday 08:00 Risks due for review digest sent to the app owner by reassessing the risk, updating its mitigation or changing its status.
- Close a record only when the agreed response has addressed the risk, leaving unresolved exposure as Open or Mitigating and maintaining the next review date where follow-up remains necessary.
Best practices
- Write each Risk as a specific uncertain event and consequence, not as a broad topic such as "operations" or "technology."
- Use Likelihood and Impact consistently by agreeing what Low, Medium and High mean before managers begin scoring records.
- Assign an Owner who can coordinate the Mitigation, rather than assigning a general department with no accountable person.
- Set a Next review date for every active risk so it appears in the Review due in 30 days view at the right time.
- Check High impact risks separately from the general Open risks list because a high-impact item may need leadership attention even when likelihood is Low.
- Keep one risk per record so Category, Owner, Mitigation, Status and Next review remain clear and actionable.
- Do not mark a risk Closed simply because a mitigation task was started; use Mitigating until the remaining exposure is accepted or resolved.
- Agree how managers and admins will document meaningful edits or deletions if the register supports a formal governance process.
What this template typically catches
Issues teams running this template most often surface in practice:
Common use cases
Frequently asked questions
What types of risks does this template cover?
The Risk Register covers Delivery, Financial, People, Compliance and Technical risks. Each record captures Likelihood, Impact, Owner, Mitigation, Status and Next review. Use it for operational and project risk tracking rather than incident reporting or a formal audit evidence system.
Who should add and maintain risk records?
Only managers and admins add records in this template, which keeps the register controlled and avoids duplicate or unreviewed entries. Owners can still be assigned to individual risks for mitigation and follow-up. Managers and admins should update the status, mitigation and Next review date as conditions change.
How often should the risk register be reviewed?
The app sends the owner a Monday review list at 08:00 for risks due within the next 30 days. Teams should also review High impact risks whenever a project, supplier, control or operating condition changes. Set Next review dates according to the risk's volatility and your governance cadence.
Does this replace a formal compliance or enterprise risk process?
It provides a practical working register for recording, prioritising and reviewing risks, but it does not replace a required enterprise risk methodology, audit file or legally mandated reporting process. Compliance risks can be categorised and assigned, while your organisation remains responsible for applying the relevant policies and approval controls.
What is a common mistake when using a risk register?
A frequent pitfall is recording a risk without a specific Owner, Mitigation or Next review date. Another is marking a risk Closed when the exposure has merely been reduced. Keep the record Open or Mitigating until the agreed response is complete, and use the status to show lifecycle rather than hiding unresolved exposure.
Can we customise the categories and fields?
The template starts with the fields and options needed for a simple risk register: Risk, Category, Likelihood, Impact, Owner, Mitigation, Status and Next review. In a demo, you can discuss adapting the category options, ownership approach or review workflow to match your organisation's risk policy.
Does the template integrate with other systems?
The supplied app includes its own typed fields, saved views, screens and a Monday review digest. No external integration is specified for this template. See the app in a demo to confirm whether your MangoApps workspace can support any additional connection or rollout requirement.
How is this better than a spreadsheet?
A spreadsheet can hold risk details, but this app provides named views for Open risks, High impact risks and Review due in 30 days, plus an Overview screen and a scheduled digest. The working register makes review dates and unresolved risks easier to act on without relying on someone to manually filter and email the list.
Related templates
Ready to use this template?
Risk Register runs on a platform app included with every MangoApps plan — pick a suite and it comes along.
Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.