0% found this document useful (0 votes)
136 views16 pages

Sample Risk Register Composable

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
136 views16 pages

Sample Risk Register Composable

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
  • Introduction
  • Instructions
  • Risk Register Details
  • Impact Assessment
  • Likelihood Assessment
  • Risk Assessment Matrix

Gartner for IT Leaders Tool

Sample Risk Register


(Composable)

A risk register is a valuable communications tool for Security and Risk Management Leaders. This tool will help effectively
communicate the potential business impacts of risks, record issues and control weaknesses and help support the design,
implementation and monitoring of risk treatment activities.

Approved for external reuse — not for resale.


Unless otherwise marked for external use, the items in this Gartner Tool are for internal noncommercial use by the licensed Gartner client. The
materials contained in this Tool may not be repackaged or resold. Gartner makes no representations or warranties as to the suitability of this Tool for
any particular purpose, and disclaims all liabilities for any damages, whether direct, consequential, incidental or special, arising out of the use of or
inability to use this material or the information provided herein.

The instructions, intent and objective of this template are contained in the source document. Please refer back to that document for details.

© 2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. or its affiliates. This
presentation, including all supporting materials, is proprietary to Gartner, Inc. and/or its affiliates and is for the sole internal use of the
intended recipients. Because this presentation may contain information that is confidential, proprietary or otherwise legally protected, it may
not be further copied, distributed or publicly displayed without the express written permission of Gartner, Inc. or its affiliates.

# Classification: Internal
© 2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. or its affiliates. This
presentation, including all supporting materials, is proprietary to Gartner, Inc. and/or its affiliates and is for the sole internal use of the
intended recipients. Because this presentation may contain information that is confidential, proprietary or otherwise legally protected, it may
not be further copied, distributed or publicly displayed without the express written permission of Gartner, Inc. or its affiliates.

# Classification: Internal
# Classification: Internal
Instructions
Security and Risk Management Leaders should use the risk register to record and monitor the current status of Cyber and I
treatment of related control weaknesses within an organization. It is designed to record all identified issues and findings an
Risk Management leaders to :

1) Familiarize yourself with the tabs within the risk register.


This template contains the following five tabs:
The "Risk Register" tab contains the risk register, which is populated with a small set of risks that are representative of the
of register.
The "Issue Register" tab contains the issue register, which is populated with a small set of identified issues and findings th
weaknesses and issues linked to the risk register and typically tracked on this form of register.
The "Pick List Data" tab contains the pick lists that are used as choices for columns that are of the fixed-choice type.
The "Likelihood Assessment" tab provides a table that can be used as a guide for assessing the likelihood of a particular
suggested example only — you may choose to adjust this table, or use an alternative approach if preferred.
The "Impact Assessment" tab provides a table that can be used as a guide for assessing the impact of a particular risk, sh
of assessing the impact using criteria other than direct financial loss. This table is a suggested example only. As with the
adjust this table, or use an alternative approach if preferred.
The "Risk Assessment Matrix" tab is a lookup table that provides an indication of the risk based on severity of the busine
approach described in ISO/IEC 27005:2011. You may choose to modify the risk outcome in each of the cells to suit local

2) Familiarize yourself with the fields.


Review the field names and field descriptions in embedded comments to familiarize yourself with the approach, definitions a
issue register can look like. Each field is described below as "unique identifier", "free text," "fixed choice" or "calculated." Th
the Pick List Data tab, which should be changed to match your enterprise's terminology. While it may be difficult to apply on
appropriate choice.

3) Customize the risk register to your organization.

In the risk register Excel spreadsheet, modify the following tabs to match the organization's definitions and preferences:
- Pick List Data
- Likelihood Assessment
- Impact Assessment
- Risk Assessment Matrix
Note that any changes made in any one of these tabs must be reflected in other tabs to ensure internal consistency.

4) Conduct risk assessments and update risk register


Update the risk register spreadsheet, modifying your existing risks or adding new risks in the risk register tab as required. T
regular cadence or be triggered by some event or incident — some example triggers are the creation of a new entity,chang
significant control weaknesses, including audit findings, , or change in the threat or risk landscape.
If the residual risk is greater than the risk tolerance, identified findings should be recorded in the issue register and manage
residual risk into compliance with the risk tolerance.

5) Track and remediate control weakness when identified


Continually add findings, issues and control weaknesses to the issue register as identified and link to the risks in the risk reg
reassessment of risks in the risk register.

# Classification: Internal
# Classification: Internal
# Classification: Internal
RISK REGISTER

Sample Risk Register


` Inherent Risk Assessment Output Control Assessment Output Residual Risk Assessment Output Residual Gap
Frequency /
Risk Control Residual Risk
Risk Event Type (Level 2) Risk Exposure (Level 1) Risk Description Risk Owner(s) Risk Type Description of Risk and Impact Likelihood Impact Inherent Risk Existing Mitigating Controls Likelihood Impact Next Risk Issue(s) identified
Identifier Effectiveness Risk Tolerance
Assessment
Unique
Fixed choice Fixed choice Free Text Free text Fixed choice Free text Fixed choice Fixed choice Calculated Free text Fixed choice Fixed choice Fixed choice Calculated Fixed choice Free text Free text
identifier

We suffer a coordinated operation of multiple claims against existing • Payment procedures using phasing and delay mechanisms to
Significant fraud event arising from fraudulent retirement funds to fraudsters impersonating existing clients, based on identify potentially fraudulent claims and prevent outflow of funds.
ISSUE001 - Inadequate authentication of claimants
RISK001 Cybercrime - Business Email Compromise Cybercrime payment to a person impersonating a senior CFO Cyber and IT what appears to be authentic paperwork and knowledgeable calls to our Rare/Remote/Improbable Large Medium • Payment claims of greater than $100,000 must be lodged Effective Rare/Remote/Improbable Moderate Low Low Annual
ISSUE002 - Lack of fraud detection and training
executive. customer service line. We fail to recover the payments. Such a fraud physically and identification sighted.
requires a well-informed, coordinated operation.

We suffer a significant outage to customer service workstations due to a • Desktop and network anti-malware software installed and updated
Significant system downtime on customer service
ransomware outbreak. This inhibits our ability to serve customers regularly.
RISK002 Cybercrime - Ransomware Cybercrime workstations due to an uncontrolled ransomware Head of Retail Cyber and IT Almost Certain/Frequent Large Extreme Partially Effective Probable/Likely Large High Low Annual ISSUE003 - Limited Zero day attack mitigation
effectively. There are also secondary financial and brand impacts. • Forensic and diagnostics support available on demand.
outbreak.

• Legal protection (patents) exists on all significant IP.


One of our own staff gains access to key IP and provides it to a
• Strong incentive and disincentive balance to encourage desired
Theft, Loss or Improper access to Data - competitor. The competitor uses it to go to market first. As a
Leakage of intellectual property (IP — product road staff behavior.
RISK003 Data Leakage of Company Intellectual Theft, Loss or Improper access to Data Head of Research Cyber and IT consequence, we waste our R&D investment and lose significant market Probable/Likely Severe Extreme Effective Possible Severe High Low Annual ISSUE004 - Employee susceptiablity to bribes
map and designs) to a competitor. • Strong access control restrictions on IP considered to be strategic
Property share. In this scenario, we consider insider leaks only, not external
assets.
penetration.
• DLP implemented to detect exfiltration of IP.

name of customer-facing business web application system> delayed due


Significant system downtime <name of customer- to major Distributed Denial of Service attack. This inhibits our ability to • Bandwidth is 2x more than required to handle peak traffic.
General Manager,
RISK004 Cybercrime - Denial of Service Cybercrime facing business web application system> delayed due Operational serve customers effectively. There are also secondary financial and Almost Certain/Frequent Moderate High • Redundancy is built into network design and security controls Partially Effective Possible Moderate Medium Medium Annual ISSUE005 - Lack of DDOS detection and monitoring
Online Delivery
to major Distributed Denial of Service attack. brand impacts as customers are unable to find and transact with us • DDOS mitigation support available on demand.
online for a period of time

A rumor appears in social media or the popular press that the company is
about to become embroiled in a financial scandal. The rumor is not true, ISSUE006 - Lack of Brand monitoring
Online Brand Risk - Social media Unfounded rumor in social or popular media that a
RISK005 Online Brand Risk SVP, Public Affairs Cyber and IT but it causes a depression on the stock price. The rumor does not Almost Certain/Frequent Moderate High None. Ineffective Almost Certain/Frequent Moderate High Low Annual ISSUE007 - Inadequate incident response plan
misinformation financial scandal is about to engulf the company.
subside and continues to depress the price. The most likely scenario is ISSUE008 - Poor perception of brand related to security and trust
that this will be started by activists who object to our business.

We send out a batch of credit card numbers to an unauthorized person.


Our most significant exposure to this is accidental release via email
Accidental release of credit card numbers to an
Theft, Loss or Improper access to Data - directed to an erroneous address. This risk specifically excludes
RISK006 Theft, Loss or Improper access to Data unauthorized recipient (more than 500 numbers per Head of Cards Cyber and IT Almost Certain/Frequent Large Extreme Data encryption for credit card numbers to authorized recipients. Ineffective Almost Certain/Frequent Large Extreme Low Annual ISSUE009 - Inadequate monitoring of data leakage related to credit cards
Data Leakage of PCI Data malicious acts. The impact of this would be potentially heavy fines from
single incident).
the card schemes, in addition to secondary exposures from fraud and
brand damage.

A disgruntled staff member sends out the compensation package details


Malicious, internal transmission throughout the of other staff members throughout the organization. This would create • Access to compensation details is segmented and restricted.
Theft, Loss or Improper access to Data -
RISK007 Theft, Loss or Improper access to Data organization of the compensation packages of SVP, HR Cyber and IT jealousy and conflict among staff, and lead to further widespread Possible Moderate Medium • High degree of audit logging on access to the details. Effective Rare/Remote/Improbable Moderate Low Low Annual None
Theft of Employee data
multiple staff members. disgruntlement, with a loss of productivity and possible departure of key • Strong organizational culture.
staff.

A portion of our consolidated internal-use-only customer demographic


Theft, Loss or Improper access to Data - information is leaked to an unauthorized third party (for example, the
External exposure of non-personally identifiable • Open architecture, but with a high degree of monitoring and audit ISSUE010 - All employees have the ability to extract and download significant amounts of
RISK008 Improper access to Non-Sensitive Theft, Loss or Improper access to Data CMO Cyber and IT media). Although the information is for internal use only, it is not Possible Severe High Effective Unlikely/Seldom Severe Medium Low Annual
information (PII) customer demographic data. logging that are traceable to individuals. company non-confidential informaiton
Customer data regulated. However, the public may perceive this as a breach of their
details (in this scenario, it is not), and their trust in our brand is degraded.

This risk assumes that the vulnerability information is outdated. If it was


current, then the risk profile would be worse. The assumption is that the
A staff member maliciously sends outdated security
Theft, Loss or Improper access to Data - staff member is attempting to embarrass the organization by portraying it • Access to vulnerability information is restricted to authorized staff
RISK009 Theft, Loss or Improper access to Data vulnerability information to the media to embarrass the CISO Cyber and IT Possible Large Medium Effective Unlikely/Seldom Large Medium Low Annual ISSUE011 - Inadequate monitoring of data leakage of vulnerability information
Theft of Company Confidential Data as incompetent. This leads to erroneous assertions by media who are trained to manage that information with discretion.
organization.
commentators that our security is lax, and our brand becomes a byword
for the same.

We would incur fines of over $1 million from regulators. Depending on the


Accidental transmission of customer name and actions of the third party, subsequent effects would include significant
Theft, Loss or Improper access to Data - ISSUE012 - Inadequate monitoring of data leakage of customer information
RISK010 Theft, Loss or Improper access to Data address information (only) from a CRM database via CIO Cyber and IT brand damage, adverse media exposure, loss of customer confidence Almost Certain/Frequent Large Extreme None. Ineffective Almost Certain/Frequent Large Extreme Low Annual
Data Leakage of Sensitive Customer Data ISSUE013 - Inadequate training of staff related to securing customer information
email to an unauthorized third party. and possibly loss of revenue. Major risk of accidental loss is via the email
channel.

RISK011
RISK012
RISK013
RISK014
RISK015
RISK016
RISK017
RISK018
RISK019
RISK020
RISK021
RISK022
RISK023
RISK024
RISK025

GARTNER LEADER'S TOOLKIT_x000D_ Classification: Internal


#
7
ISSUE REGISTER

Sample Issue Register


Issues Identified Management Plan to Address Residual Gap

Issue Related Risk


Issue Name Issue Description Issue Priority Issue Source Issue Date Issue Owner Plan of Action & Milestones Action Owner Action Status Date of Update Target Completion Date Actual Completion Date
identifier Identifier

Unique Unique
Free Text Free Text Fixed Choice Free text Free text Free text Free Text Free Text Fixed Choice Free text Free text Free text
identifier identifier

• Modify procedures so that payment claims of


Audit identified that :
greater than $25,000 must be lodged physically and
• Failure to adequately identify the claimant when not SVP, Customer
ISSUE001 Inadequate authentication of claimants Medium Internal Audit Thursday, March 12, 2020 CFO RISK001 identification sighted. Issue closed Thursday, April 15, 2021 Tuesday, March 30, 2021 Monday, March 15, 2021
physically present. Service Division
• Modify procedures to cross-check contact and
account details out of band.

Audit identified that :


• Extend postclaim, prepayment fraud detection
• No mechanism to detect clustering of retirement
capability to detect claims clustering.
ISSUE002 Lack of fraud detection and training fund claims across multiple customer service staff. Low Internal Audit Tuesday, March 17, 2020 CFO RISK001 CSO Issue overdue Thursday, April 15, 2021 Friday, October 30, 2020
• Train staff to ask profiling questions.
• Staff not trained to identify high-risk payment
situations.

Post incident review identified that : • Implement sandboxing technology to improve


• No protection against Day 0-type attacks. identification and containment capabilities.
ISSUE003 Limited Zero day attack mitigation High Post Incident Review Sunday, July 12, 2020 CISO RISK002 IT PMO Issue in progress Thursday, April 15, 2021 Wednesday, June 30, 2021
• No early-warning system for malware tailored • Commission a threat intelligence service to monitor
specifically for our systems. for early signs of a potential attack.

• Implement a "panic" protocol for staff exposed to


extreme situations (for example, a family member
who is kidnapped).
• Incentive and disincentive program is ineffective in
• Commission a project to develop a method for
abnormal situations (for example, under extreme
ISSUE004 Employee susceptiablity to bribes High Risk Assessment Sunday, July 12, 2020 Head of Research RISK003 identifying staff at risk of blackmail or in other CSO Issue closed Thursday, April 15, 2021 Sunday, February 28, 2021 Thursday, April 1, 2021
stress, such as kidnap, hostage or extortion [KHE]
personal forms of distress (such as a problem with
scenarios).
gambling).
• Implement technology to detect unusual patterns of
access to identify "slow leaks."

No proactive detection capability to distinguish


ISSUE005 Lack of DDOS detection and monitoring Low Risk Assessment Thursday, October 15, 2020 CISO RISK004 • Implement DDOS or traffic monitoring capability CSO Issue Risk accepted Friday, January 31, 2020 Friday, January 15, 2021 Thursday, December 31, 2020
between DDOS and normal increases in traffic

• Implement monitoring for mentions of our brand in


social or popular media.
ISSUE006 Lack of Brand monitoring We do not monitor for mentions of our brand at all. Medium Post Incident Review Friday, October 30, 2020 SVP, Public Affairs RISK005 SVP, Public Affairs Issue in progress Thursday, April 15, 2021 Monday, May 31, 2021
• Prepare media statements for immediate use,
should the need ever arise.

• Develop a relationship with law enforcement to


Lack of contact details for law enforcement included in
ISSUE007 Inadequate incident response plan Critical Post Incident Review Saturday, November 14, 2020 CISO RISK005 support rapid response and prosecution, should the SVP, Security Issue closed Thursday, April 15, 2021 Wednesday, April 7, 2021 Wednesday, March 31, 2021
Incident response plan
risk occur.

Recent incident highlighted that there is poor


Poor perception of brand related to security • Bolster "brand trust" via triple-bottom-line strategy SVP, Marketing and
ISSUE008 perception of our brand related to trust and security Critical Post Incident Review Tuesday, January 12, 2021 SVP, Public Affairs RISK005 Issue in progress Thursday, April 15, 2021 Tuesday, November 30, 2021
and trust and existing marketing campaign. Community
that may be impacting our performance in the market.

We do not currently trap instances of credit card


numbers being sent to unauthorized recipients, and
Inadequate monitoring of data leakage related the benefit of existing mitigating controls in isolation is Implement a network data loss prevention (DLP)
ISSUE009 High Internal Audit Monday, March 1, 2021 Head of Cards RISK006 CISO Issue in progress Thursday, April 15, 2021 Monday, January 31, 2022
to credit cards therefore negligible. Our major exposure is accidental solution.
release via email, although we have lesser exposures
via other channels.

• Upgrade the staff awareness program so that staff


must positively acknowledge actions and provide
All employees have the ability to extract and The adoption of an open architecture to this
justification when a large volume of information is
ISSUE010 download significant amounts of company non- information places heavy reliance on the culture and High Internal Audit Monday, March 1, 2021 CISO RISK008 CMO Issue in progress Thursday, April 15, 2021 Monday, August 30, 2021
extracted.
confidential informaiton awareness of staff, which has not be formally tracked
• Colocate one staff member from the internal
investigation team on-site in a liaison role.

• Implement a network DLP solution to identify any


potential leaks to the media over electronic
channels.
Although access is restricted and staff are trained, a
Inadequate monitoring of data leakage of • Implement an endpoint DLP solution to detect
ISSUE011 rogue staff member could transfer this information, as Medium Internal Audit Monday, March 1, 2021 CISO RISK009 CISO Issue in progress Thursday, April 15, 2021 Wednesday, June 30, 2021
vulnerability information downloading of information to removable media or
no monitoring is performed.
printing of information.
• Escalate audit logging on access to the
vulnerability database.
We currently have no method of identifying the
Inadequate monitoring of data leakage of
ISSUE012 outflow of customer information via email or any other Critical Internal Audit Monday, March 1, 2021 CIO RISK010 • Implement a network DLP solution. CISO Issue in progress Thursday, April 15, 2021 Thursday, September 30, 2021
customer information
channel.

Internal Audit identified that there is no training of


Inadequate training of staff related to securing • Launch an awareness program for individuals who Head of Customer
ISSUE013 individuals who have access to customer data on their Medium Internal Audit Monday, March 1, 2021 CISO RISK010 Issue in progress Thursday, April 15, 2021 Monday, August 30, 2021
customer information have access to customer data. Service Division
obligations for securing the data.

ISSUE014
ISSUE015
ISSUE016
ISSUE017
ISSUE018
ISSUE019
ISSUE020
ISSUE021
ISSUE022
ISSUE023
ISSUE024
ISSUE025

GARTNER LEADER'S TOOLKIT_x000D_Classification: Internal


#
8
Pick List Data
Primary
Risk
Risk Type Risk Exposure (Level 1) Risk Event (Level 2) Risk Likelihood Risk Level Control Effectiveness Issue Priority Issue Status Impact
Impact
Category
Financial Cybercrime Cybercrime - Business Email Compromise Insignificant Open — not yet assessed Financial
Rare/Remote/Improbable Minute Highly Effective
Low
Operational Online Brand Risk Cybercrime - Ransomware Unlikely/Seldom Small Low Effective Medium Issue assessed — determining treatment Customer
Cyber and IT Theft, Loss or Improper access to Data Cybercrime - Phishing Possible Moderate Medium Partially Effective High Issue overdue Opportunity
Strategic Technology Failure Cybercrime - Denial of Service Probable/Likely Large High Ineffective Critical Issue in progress Shareholder
Compliance Regulatory Compliance Online Brand Risk - Social media misinformation Almost Certain/Frequent Severe Extreme Issue waiting on closure Commercial
To be expanded based on client risk assessment and taxonomy Online Brand Risk - Fraudulent mobile apps Issue closed Staff
Theft, Loss or Improper access to Data - Data Leakage of PCI Data Issue Risk accepted Brand
Theft, Loss or Improper access to Data - Theft of PCI Data
Theft, Loss or Improper access to Data - Data Leakage of Employee data
Theft, Loss or Improper access to Data - Theft of Employee data Media
Theft, Loss or Improper access to Data - Improper Access of Non-Sensitive Customer data Regulator
Theft, Loss or Improper access to Data - Data Leakage of Company Confidential Data
Theft, Loss or Improper access to Data - Theft of Company Confidential Data
Theft, Loss or Improper access to Data - Data Leakage of Sensitive Customer Data
Theft, Loss or Improper access to Data - Theft of Sensitive Customer Data
Technology Failure - Software
Technology Failure - Network
Technology Failure - Cloud
Regulatory Compliance - Privacy fine
To be expanded based on client risk assessment and taxonomy

Classification: Internal
#
Impact Assessment Decision Table

Business Impact
Financial Impact Customer Impact Opportunity Impact
Insolvency, or negative Complete failure of We lose rights to our IP.
profit outlook. service across multiple Competitor gains first-
lines of business >= 5 mover advantage.
Severe minutes.

Material financial loss (as Failure (partial or Compromise of IP or


formally defined), or loss complete) of service trade secret, and
above the board- across multiple lines of competitor generates
Large reportable threshold. business < 5 minutes, or significant market share
complete failure across a using it.
single line of business >=
1 day.
Financial loss greater Partial service disruption Compromise of IP or
than budget allowance, in a single line of trade secret, but we are
requiring budget business >= 1 day, or able to recover through
adjustment across total service disruption in legal or other means.
Moderate
multiple lines of a single line of business
business. >= 1 hour.

Financial loss greater Partial service disruption Competitor gains insight


than budget allowance, in a single line of into our IP and generates
requiring budget business < 1 day, or total inferior competitive
Small adjustment within a disruption in a single line offering.
single line of business. of business < 1 hour, or
attributable rise in daily
call center load >= 20%.
Financial loss within Insignificant service IP or trade secret leaked
annual budget disruption, or attributable prior to planned release.
Insignificant allowance. rise in daily call center
load < 20%.

# Classification: Internal
Impact Dimensions
Shareholder Impact Commercial Impact Staff Impact Brand Impact
Attributable negative Commercial liability Actual or high risk of Company name
share price movement exposure threatens death or injury. becomes a byword for
>= 10%. viability of the company. corporate misconduct or
misadventure.

Attributable negative Exposure to punitive Risk of death or injury Loss of multiple high-
share price movement damages, or loss of Tier rated higher than value customers, or
>= 5% but < 10%. 1 customer. insignificant, or major job introduction of
losses. widespread negative
brand sentiment.

Attributable negative Exposure to restitution or Minor job losses, or Loss of one high-value
share price movement similar damages for significant loss of customer or multiple
>= 1% but < 5%. breach of contract, or productivity (>= 30 midlevel customers, or
loss of lower-tier person days). introduction of short-term
customer. negative brand
sentiment.

Attributable negative Minor penalties incurred Minor staff disruption, or Loss of multiple low-
share price movement < for exceptions explicitly minor loss of productivity value customers, or
1%. articulated in the (< 30 person days). reinforcement of existing
contract. negative brand
sentiment.

Attributable negative No impact to commercial No staff impact. Insignificant customer


share price movement obligations, or no penalty loss.
insignificant (< 0.1%). incurred for missed
obligations.

# Classification: Internal
Media Impact Regulator Impact
International long-term One or more lines of
media coverage. business are shut down,
or an executive faces
personal legal liability.

International short-term Regulator issues a notice


media coverage, or to comply under penalty
national long-term media of service termination.
coverage.

National short-term Regulator issues an


media coverage. enforceable undertaking.

Local long-term media Regulator requires


coverage. regular reporting until
resolution.

No media coverage, or No regulator interest, or


local short-term report to regulator is
coverage. optional.

# Classification: Internal
Likelihood Assessment Criteria Table

Likelihood Criteria
Likelihood Level
Likelihood of occurrence in next 12 months
Rare/Remote/Improbable Less than 5%
Unlikely/Seldom 5% - 20%
Possible 20% to 50%
Probable/Likely 50% to 80%
Almost Certain/Frequent Greater than 80%

# Classification: Internal
Likelihood Criteria
Frequency in years
Every 10+years
Every 5-10 years
Every 3-5 years
Every 2-3 years
Every year

# Classification: Internal
Risk Assessment Matrix

Likelihood of Risk
Rare/Remote/Improbable Unlikely/Seldom

Severe Medium Medium

Large Medium Medium


Severity of
Business Moderate Low Medium
Impact
Small Minute Low

Insignificant Minute Minute

# Classification: Internal
Likelihood of Risk Scenario
Possible Probable/Likely Almost Certain/Frequent

High Extreme Extreme

Medium High Extreme

Medium Medium High

Medium Medium Medium

Low Medium Medium

# Classification: Internal

#Classification: Internal
Approved for external reuse — not for resale.
The instructions, intent and objective of this templa
#Classification: Internal
© 2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark
#Classification: Internal
#Classification: Internal
Instructions
1) Familiarize yourself with the tabs within the risk register.
This template contains
#Classification: Internal
#Classification: Internal
RISK REGISTER
GARTNER LEADER'S TOOLKIT_x000D_ #Classification: Internal
7
Sample Risk Register 
`
Inherent Risk Assessment Ou
ISSUE REGISTER
GARTNER LEADER'S TOOLKIT_x000D_#Classification: Internal
8
Sample Issue Register
Issues Identified
Management
#Classification: Internal
Pick List Data
Risk Type 
Risk Exposure (Level 1)
Risk Event (Level 2)
Risk Likelihood
Risk Level
C
#Classification: Internal
Impact Assessment Decision Table
Business Impact
Financial Impact
Customer Impact
Opportunity Impac

You might also like