Mango’s Risk Register
The following page shows a blank risk register that you can use to record and
monitor your key financial risks.
How to use this register:
1. Identify the key financial risks facing your organisation and record them in the risk
register, together with the date the risk was identified.
2. For each risk
Consider the likelihood of the risk occurring. Assign a score from 1 (unlikely)
to 3 (highly likely)
Consider how serious the impact would be if that risk were to actually happen.
Assign a score from 1 (manageable) to 3 (critical).
Calculate a combined score by multiplying the two answers together, to give a
general indication of the severity of the risk (9 highest, 1 lowest).
Think of suitable controls to mitigate the key risks
Implement the controls
Reassess the risk in light of controls now in place.
3. Monitor progress on a regular basis (eg 6 monthly at board meetings)
4. Add new risks and take actions as necessary. When assigning responsibility for
action, be sure to distinguish between Board members and the CEO (through
his/her team).
The final page shows an example risk register, which is given for illustrative
purposes only. The types of risks and the scores assigned cannot be ‘copied and
pasted’ to other organisations.
The types of controls that may be effective to mitigate risks will vary according to
circumstances. The best people to take responsibility for particular actions will
depend on who you have available in your organisation.
Risks register 1 © Mango 2010
[Organisation name] Risks Register at [Date]
Initial risk assessment Current risk assessment
Risk Date Severity Overall
areas added to Likelihood of impact 'gross' Control procedure(s) Controls Retained Action needed:
identified register (score) (score) risk identified in place Comment 'Net' risk person responsible
1
Risks register 2 © Mango 2010
Example Risks Register at 31 December 2009
Initial risk assessment Current risk assessment
Risk Date Severity Overall
areas added to Likelihoo of impact 'gross' Control procedure(s) Controls Retained Action needed:
identified register d (score) (score) risk identified in place Comment 'Net' risk person responsible
1 Theft of May-08 High Medium High Asset register Not Medium Finalise asset
assets (3) (2) (6) Quarterly asset verification complete register: CEO
Engraving
Insurance
Limited access to key
assets
2 Fraud May-08 High High High Fraud policy in place In Medium Develop policy:
(3) (3) (9) Internal audits (6 monthly) progress Treasurer
Increase frequency to
quarterly: Treasurer
3 Road May-08 High Medium High Insurance Medium
accident (3) (2) (6) Road safety training for
drivers
4 Main Oct-08 Medium High High Diversify funding base Medium Develop financing
donor (2) (3) (6) (more donors) strategy: Treasurer
pulls out Generate local income
5 Fire Mar-09 Low High Medium Fire exits, fire extinguisher, Medium Renew insurance:
(1) (3) (3) smoke detectors CEO
Offsite backups Out of date Building works: CEO
Insurance
6 Electronic Mar-09 High Medium High Firewall Medium
virus (3) (2) (6) Backups
7 Exchange Sep-09 Medium Medium Medium Set donor contracts in local Donor Medium
losses (2) (2) (4) currency refused
8 Bribery – Dec-09 High High High Put ‘adequate procedures’ UK Bribery High Review
paying (3) (3) (9) in place Bill Oct 10 recommendations by
bribes TIUK and develop a
policy: CEO
Risks register 3 © Mango 2010