Skip to main content
Loading...
Office & admin

Risk Register

Track risks with likelihood, impact, owners, mitigations, status and review dates, then receive a Monday digest of risks due for review.

Included with every MangoApps plan.

Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.

Built for: Professional Services · Construction And Engineering · Financial Services · Healthcare Operations · Technology And Saas

Overview

The Risk Register is a working app for recording and reviewing risks in a MangoApps workspace. Each record has a required Risk description, a Category of Delivery, Financial, People, Compliance or Technical, required Likelihood and Impact values, an Owner, a Mitigation, a required Status of Open, Mitigating or Closed, and a Next review date. Together, these fields show what could happen, how serious it may be, who is responsible and what response is in progress.

Only managers and admins add records, which gives the register a controlled data-entry posture. Records can be edited or deleted, so administrators should agree how changes are governed if the register is used as an important management record. The Overview screen provides a metric row and board for a quick read, while the Register screen provides a grid and action bar for maintaining the full list.

Use the Open risks view for routine management, High impact for escalation and leadership discussion, and Review due in 30 days to prepare upcoming reassessments. The Monday review list runs at 08:00 each week and sends the app owner an AI summary digest titled Risks due for review. This template is not intended to replace a formal enterprise risk framework, incident log or audit evidence repository. It is best for a focused operational register where managers need a consistent record and a dependable review cue.

Standards & compliance context

  • The Compliance category helps organisations identify and assign policy or regulatory exposure, but the register does not by itself demonstrate compliance with a specific law or standard.
  • Use the register alongside your documented risk-management, approval and evidence-retention procedures when risks affect regulated activities.
  • Because records can be edited and deleted, confirm whether your organisation needs a separate append-only record or audit trail for formal assurance purposes.

General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.

How to use this template

  1. Add the Risk Register template to your MangoApps workspace and confirm that managers and admins are the people allowed to add records.
  2. Create one record for each material risk, entering the Risk, Category, Likelihood, Impact, Owner, Mitigation, Status and Next review date rather than combining several risks in one description.
  3. Use the Overview screen for the metric row and board, then open the Register screen when managers need to inspect or update the full grid.
  4. Review Open risks and High impact risks regularly, and use the Review due in 30 days view to prepare the next risk discussion.
  5. Act on the Monday 08:00 Risks due for review digest sent to the app owner by reassessing the risk, updating its mitigation or changing its status.
  6. Close a record only when the agreed response has addressed the risk, leaving unresolved exposure as Open or Mitigating and maintaining the next review date where follow-up remains necessary.

Best practices

  • Write each Risk as a specific uncertain event and consequence, not as a broad topic such as "operations" or "technology."
  • Use Likelihood and Impact consistently by agreeing what Low, Medium and High mean before managers begin scoring records.
  • Assign an Owner who can coordinate the Mitigation, rather than assigning a general department with no accountable person.
  • Set a Next review date for every active risk so it appears in the Review due in 30 days view at the right time.
  • Check High impact risks separately from the general Open risks list because a high-impact item may need leadership attention even when likelihood is Low.
  • Keep one risk per record so Category, Owner, Mitigation, Status and Next review remain clear and actionable.
  • Do not mark a risk Closed simply because a mitigation task was started; use Mitigating until the remaining exposure is accepted or resolved.
  • Agree how managers and admins will document meaningful edits or deletions if the register supports a formal governance process.

What this template typically catches

Issues teams running this template most often surface in practice:

A risk is listed without a clear Owner, leaving mitigation work unassigned.
Likelihood and Impact are recorded inconsistently because different managers apply different scoring interpretations.
A Mitigation field contains a vague intention rather than a concrete response that someone can follow up.
The Next review date is blank or stale, so an active risk never reaches the Review due in 30 days view.
A High impact risk remains buried among ordinary Open risks instead of being reviewed through the High impact view.
A risk is marked Closed when the response has only begun, hiding exposure that should remain Mitigating.
Several unrelated concerns are combined in one Risk record, making ownership and review decisions unclear.
A spreadsheet-era list is updated manually but no one checks the Monday Risks due for review digest.

Common use cases

Project manager delivery review
A project manager records schedule, dependency and supplier risks under Delivery, assigns an Owner and sets a Next review date. The Open risks and High impact views support weekly project governance without sorting a separate spreadsheet.
Finance controller control register
A finance team uses Financial and Compliance categories to track exposure around forecasting, approvals or reporting processes. Managers can keep mitigations visible and use the Monday digest to bring due reviews into the control meeting.
IT service risk review
An IT manager records Technical risks affecting service reliability, systems or planned changes, then assigns mitigations to responsible owners. High impact risks remain easy to isolate while the Register grid provides the detailed working list.
People operations planning
People leaders use the People category for risks involving staffing, capability or critical-role coverage. Each item can carry a named Owner, an agreed Mitigation and a review date instead of remaining as an informal action in meeting notes.
Operations leadership meeting
Operations managers use the Overview board for a quick status discussion, then open Review due in 30 days to decide which risks need reassessment. Status changes to Open, Mitigating or Closed keep the conversation tied to the record.

Frequently asked questions

What types of risks does this template cover?

The Risk Register covers Delivery, Financial, People, Compliance and Technical risks. Each record captures Likelihood, Impact, Owner, Mitigation, Status and Next review. Use it for operational and project risk tracking rather than incident reporting or a formal audit evidence system.

Who should add and maintain risk records?

Only managers and admins add records in this template, which keeps the register controlled and avoids duplicate or unreviewed entries. Owners can still be assigned to individual risks for mitigation and follow-up. Managers and admins should update the status, mitigation and Next review date as conditions change.

How often should the risk register be reviewed?

The app sends the owner a Monday review list at 08:00 for risks due within the next 30 days. Teams should also review High impact risks whenever a project, supplier, control or operating condition changes. Set Next review dates according to the risk's volatility and your governance cadence.

Does this replace a formal compliance or enterprise risk process?

It provides a practical working register for recording, prioritising and reviewing risks, but it does not replace a required enterprise risk methodology, audit file or legally mandated reporting process. Compliance risks can be categorised and assigned, while your organisation remains responsible for applying the relevant policies and approval controls.

What is a common mistake when using a risk register?

A frequent pitfall is recording a risk without a specific Owner, Mitigation or Next review date. Another is marking a risk Closed when the exposure has merely been reduced. Keep the record Open or Mitigating until the agreed response is complete, and use the status to show lifecycle rather than hiding unresolved exposure.

Can we customise the categories and fields?

The template starts with the fields and options needed for a simple risk register: Risk, Category, Likelihood, Impact, Owner, Mitigation, Status and Next review. In a demo, you can discuss adapting the category options, ownership approach or review workflow to match your organisation's risk policy.

Does the template integrate with other systems?

The supplied app includes its own typed fields, saved views, screens and a Monday review digest. No external integration is specified for this template. See the app in a demo to confirm whether your MangoApps workspace can support any additional connection or rollout requirement.

How is this better than a spreadsheet?

A spreadsheet can hold risk details, but this app provides named views for Open risks, High impact risks and Review due in 30 days, plus an Overview screen and a scheduled digest. The working register makes review dates and unresolved risks easier to act on without relying on someone to manually filter and email the list.

Ready to use this template?

Risk Register runs on a platform app included with every MangoApps plan — pick a suite and it comes along.

Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.