0% found this document useful (0 votes)
29 views14 pages

Nonprofit Risk Register Template

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
29 views14 pages

Nonprofit Risk Register Template

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Sample Completed Risk Register

There are a number of approaches and frameworks for developing an organisation’s Risk Management System and Risk Register. This document
reflects the framework recommended by the Charities Regulator, though any non-profit may find it useful. This document is intended for guidance
only and all organisations should develop their own Risk Management System and Risk Register.
Introduction

The identified risks are grouped under 7 key risk areas.

Key Risk Areas

1. Governance (G)
2. Strategic (S)
3. Compliance (legal & regulatory) (C)
4. Operational (O)
5. Financial (F)
6. Environmental or External (E)
7. Reputational (R)

Each risk on the register is given a brief description of the potential risk for the organisation and the potential impact if the risk was to occur. Each risk is also assigned a Risk
Owner who has oversight responsibility for monitoring the risk and the implementation/ review of the steps to be taken to mitigate the likelihood of the risk occurring or if it
does occur, the impact on the organisation. The monitoring frequency is specified and the risk owner needs to ensure that this monitoring occurs.

Each of the risks are assessed in terms of (1) likelihood of the risk occurring on a scale of 1 – 5 where 1 is very unlikely and 5 is very likely; (2) the impact for the Organisation
if the risk was to happen also rated on a scale of 1 -5 and (3) the controls in place or steps to be taken to mitigate the risk. The controls are rated of a scale of 1 to 3 where 1 it
is felt that the controls are very effective and 3 an assessment that the controls or steps are not very strong and/or likely to be effective in preventing the risk or the mitigating
its impact if it did occur. The risk score is determined by multiplying the risk impact by the risk likelihood by the effectiveness of the controls. (Likelihood X Impact) X Controls.

The following traffic light system is used on a risk register to highlight / prioritise risk:

Risk Level Risk Score


High 25+
Medium 13 – 24
Low 0 – 12

Sample Completed Risk Register 1


The Risk Committee oversees the preparation and regular update of the risk register, the monitoring of risks and the regular review and assessment of the Highest Risks to
determine if any new or additional steps to mitigate or control the risk should be implemented. The Risk No Column can be colour coded to reflect the Risk Score, for
example:

Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

F1 Dependency on a Cash flow and CEO  Identify major Annual review of the risk by the 3 4 2 24
limited number of budget impact of funding/income source Risk Committee reporting to the
income/funding loss of income dependencies board. The review will assess;
sources source  Implement adequate
 Adequacy of reserves to
reserves policy
sustain an income shock
 Opportunities for income
diversification or to develop
additional income sources

Risk Register

Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

Risk Category: Governance


G1 Board lacks  The Organisation Chairperson  Conduct regular Annual review of the risk by
relevant skills or becomes moribund board skills audits the Risk Committee reporting
commitment to or fails to achieve its and agree skills to the board. The review will
meet its purpose required assess;
responsibilities  Oversight and  Develop and review
and duties  Skill needs/gaps of
guidance of the annually a board
the board
organisation is succession plan
 Actions/updates
inadequate  Provide induction for
needed to the
 Key decisions are new board members
succession plan
made that bypass This is done for all
the Board new members
 Attendance by board  Review board
meetings is poor and training needs and
difficulties in getting provide relevant
training to board
Sample Completed Risk Register 2
Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

a quorum for board members Item for


meetings discussion by Risk
 Board sub Committee and to
committees meet make
irregularly and are recommendations to
not focused board
 Poor decision
making reflected in
poor service delivery
and dissatisfied
clients, members and
funders
 Resentment or
apathy amongst staff
G2 Loss of key staff/  Experience or skills Risk  Succession planning Annual review of the risk by
staff retention lost Committee On-going the Risk Committee reporting
 Operational impact and the CEO  Document systems, to the board of
of key projects and activities and adequacy/effectiveness of
priorities projects the mitigation steps to
 Loss of contact base  Implement training manage/minimise this risk.
and corporate programme On- The review will assess the
knowledge going positions considered to be
 Agree notice periods most at risk and if any
and handovers additional measures need to
 Ensure adequate be put in place.
terms and conditions
for all staff, in line
with industry norms
 Ensure a vibrant and
supportive working
environment
 Put in place effective
performance
management
structures to
stimulate and
support excellent

Sample Completed Risk Register 3


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

work performance
and motivation
G3 Quality of  Inadequate Chair  Assessed as part of Annual review of the risk by
reporting to information resulting annual board the Risk Committee reporting
Board (accuracy, in poor quality evaluation process. to the board of
timeliness & decision making Positive responses adequacy/effectiveness of
relevance)  Failure of board to from board members the information provided to
fulfil its control on quality the board.
functions
 Board becomes
remote and ill
informed
Risk Category: Strategic
S1 The Organisation  The organisation Board  Develop and monitor Annual review of this risk by
lacks an drifts with no clear 3-year strategic plan the Strategy, Committee
appropriate objectives, priorities which sets out the reporting to the board of
strategic direction or plans key aims, objectives adequacy/ effectiveness of
or focus that is in  Issues are and targets of the the mitigation steps to
tune with the addressed piecemeal Organisation manage/minimise this risk
evolving needs with no strategic  Regularly review (at
and business reference / context least every 5 years)
/operating  Difficult decisions are the Organisation’s
environment avoided or put on the vision and
long finger constitution Review
 Needs of of Constitution
beneficiaries not fully  Develop and monitor
addressed annual operational/
 Financial business plans
management  CEO's report to the
difficulties Board mapped
 Loss of reputation against strategic
aims and objectives
S2 The Organisation  Dramatic loss of Board  Review the Annual review of the risk by
does not have income up to closure experience of the the Risk Committee reporting
the flexibility or of some parts of all Covid-19 pandemic to the board of
the sustainability operations of the and assess what adequacy/effectiveness of
to survive a Organisation worked well and the mitigation steps to
major what should be done manage/minimise this risk.

Sample Completed Risk Register 4


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

catastrophic differently if a similar


event such as catastrophic event
global pandemic were to reoccur
 Review and update
the Disaster
Recovery and
Business Continuity
Plan in light of the
Covid-19
experience.
 Build/Maintain
strong reserves to
provide emergency
funding to keep
operations going
while responses to
the loss of income
are being
developed.
 Maintain good
relations with
funders and national
bodies
S3 Ineffective or  Lack of information CEO  Use organisation Review of the risk by the
inappropriate flow and poor chart and job roles & Strategy Committee at least
organisational decision-making responsibilities to once every 3 years as part of
structure procedures provide a clear the strategic development
 Certain activities understanding of process reporting to the
may not get roles and duties board of adequacy/
appropriate  Develop a scheme effectiveness of the
management of delegated mitigation steps to
direction and authority to the CEO manage/minimise this risk
oversight  Delegation and
 Certain activities monitoring should
may get too much be consistent with
time given their good practice
relative importance  Conduct regular
or contribution reviews of the

Sample Completed Risk Register 5


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Remoteness of organisation
senior managers structure, and the
/staff from allocation of
operational activities responsibilities and
 Uncertainly or lack of time
clarity as to roles and
duties
 Decisions made at
an inappropriate
level of excessive
bureaucracy
 Decision bottlenecks
due to too many
decisions being
taken by one or two
individuals
 Uneven workloads
Risk Category: Compliance (Legal or Regulatory)
C1 Compliance with  Fines, penalties or CEO  Identify key legal and CEO to submit a legal &
legislation and censure from licensing regulatory regulatory compliance report
regulations or activity regulators requirements that to the board annually.
appropriate to the  Loss of licence to apply to the
activities, size undertake a particular Organisation Risk Committee to regularly
and structure of activity  CEO submits a review and assess the risk
the charity  Employee or compliance report register & mitigation steps to
beneficiary take action annual to the board report to the board
for negligence  Allocate
 Suffer damage to our responsibility for key
reputation compliance All compliance reports/
procedures concerns received from the
 Put in place a CRA, funders or regulators to
process for be brought to the attention of
compliance the board.
monitoring and
reporting to the
board overseen by
the Risk Committee

Sample Completed Risk Register 6


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Maintenance and
regular review of the
Organisation’s risk
register overseen by
the Risk Committee
 Prepare for
compliance visits
 Review compliance
reports /concerns
from regulators,
inspectors, auditors
and staff when
received take
appropriate action to
address issues/
concerns

C2 Regulatory and  Regulatory action CEO  Review and agree CEO to confirm to the board
funder reporting taken against the compliance annually that all regulatory
requirements are Organisation procedures and and funder reporting
not adequately  Suffer damage to our allocation of staff requirements have been met
met reputation responsibilities
 Negative impact on All compliance reports/
future funding concerns received from the
CRA, and any other funders
or regulators to be brought to
the attention of the board.

Risk Category: Operational


O1 Inadequate  Computer systems CEO  Review and update Annual review of the risk and
Disaster failures or loss of the Disaster assessment of the mitigation
Recovery & data Recovery and steps by the Risk Committee
Business  Destruction of Business Continuity reporting to the board
Continuity property, equipment, Plan in light of the
planning records through fire, covid-19 experience.
floods or similar  Review & update the
damage IT back-up &
recovery plan

Sample Completed Risk Register 7


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Implement and
periodically test the
data back-up
procedures and
security measures
 Review insurance
cover at least once
every 3 years
 Review/update
disaster recovery
plan at least once
every 3 years
O2 Poor Health &  Staff injury CEO  Comply with the law Annual review of the risk and
Safety  Service liability and regulations assessment of the mitigation
 Ability to operate all  Get our external steps by the Risk Committee
or some of our safety advisors to reporting to the board
services curtailed or review and update
suspended our safety plan
 Injury to Resident  Train staff and safety
Member staff, visitors officer
and the public  Put in place
monitoring and
reporting procedures
O3 Poor staff  Employment CEO  Review regularly the Annual review of the risk and
performance, disputes effectiveness and assessment of the mitigation
morale or attitude  High staff turnover quality of our steps by the Risk Committee
rates recruitment process reporting to the board
 Health & Safety  Ensure that all new
issues staff receive a
 Claims for injury, structured induction
stress, harassment, training
unfair dismissal  Adhere to the
 Equal opportunity & Organisation’s
diversity issues policies for checking
 Adequacy of staff references, job
training descriptions,
 Low morale contracts of
employment,

Sample Completed Risk Register 8


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Abuse of vulnerable appraisals &


staff or clients feedback procedures
 Create a positive
working environment
and culture where
staff feel safe in
raising concerns
 Implement job
training and
development
 Assess regularly the
on-going training
needs of staff
 Implement health &
safety training and
monitoring
 Communicate the
Organisation’s
protected disclosure
(whistle-blowing)
policy
Risk Category: Financial
F1 Dependency on a Cash flow and budget CEO  Identify major Annual review of the risk by
limited number of impact of loss of income funding/income the Risk Committee reporting
income/funding source source to the board. The review will
sources dependencies assess;
 Implement adequate
 Adequacy of reserves to
reserves policy
sustain an income shock
 Opportunities for income
diversification or to
develop additional
income sources
F2 Danger of Fraud  Financial loss Finance  Review financial Risk monitored by the Audit
or error  Reputational risk Manager control procedures & Finance Committee
 Loss of staff morale  Segregate duties reporting to the board. The
 Regulatory action  Set & review monitoring will include
authorisation limits following reviews/
Sample Completed Risk Register 9
Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Impact on existing  Review security of assessments of the following


and future funding assets areas (undertaken at least
 Identify insurable once every 3 years);
risks  Adherence to and
adequacy of financial
control procedures
 Confirmation that key risk
duties are segregated
 Adherence to and
adequacy of the set
authorisation limits
 Adequacy of the insurable
risks cover
F3 Cyber breach  Loss of funds CEO &  Identify and assess Annual review of the risk and
(phishing) Finance main vulnerability assessment of the mitigation
 Loss of important Manager areas and implement steps by the Risk Committee
data (personal, appropriate control reporting to the board
account, passwords) measures
 Reputational damage  Develop a cyber-
security guidance
document for staff
 Maintain staff
awareness and
alertness to cyber
fraud to regular
reminders and
communication
 Obtain and
implement
prevention advice
and measures from
experts, insurers and
financial service
providers
 Keep firewall and
anti-virus software
up to date

Sample Completed Risk Register 10


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Advise staff working


remotely of the need
to adhere our cyber
risk controls and
procedures
 Avail of relevant
training and
guidance
Risk Category: Environmental or External
E1 Loss of statutory  Inability to provide CEO  Ensure regular Annual review of the risk by
funding, Lack of services contact and briefings the Risk Committee reporting
available staff/ to major funders to the board
skills in the  Report fully on
sector or a projects
limitations on  Meet funders’ terms
available funds or and conditions
staffing and as a  Ensure maintenance
result we are of existing good
unable to fully relationships with all
meet the needs stakeholders
of our service
users
E2 Competition from  Loss of income CEO  Monitor and assess Annual review of the risk by
similar not-for-  Reduced public performance and the Risk Committee reporting
profit and for profile quality of our to the board
profit  Profitability of trading services
organisations activity – services run  Enhance and
providing similar at a loss or require innovate
services and subsidisation from  Review market
supports to us other activities assessments and
methods of service
delivery
 Ensure regular
contact with funders
and service users
 Monitor public
awareness and
profile

Sample Completed Risk Register 11


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

 Strategic selection of
markets segments
that we wish to target
and serve.
 Explore, assess and
regularly
opportunities for
collaboration,
partnership, joint
ventures or mergers
Risk Category: Reputational
R1 Adverse publicity  Loss of funder Risk  Monitor complaints Annual review of the risk by
generated by the confidence or Committee received (both the Risk Committee reporting
Organisation funding internal and external) to the board
 Loss of influence  Agree and regularly
 Impact on staff review a crisis
morale management
 Loss of confidence strategy for handling
by service users adverse publicity
including
consistency of key
messages and
nominated
spokesperson
R2 Poor service  Customer/Beneficiary CEO  Agree quality control Annual review of the risk by
provision leading complaints procedures the Risk Committee reporting
to poor customer  Loss of fee income  Monitor complaints to the board
satisfaction  Loss of new and service user
business feedback
 Suffer damage to our  Enhance and
reputation innovate services
and systems
 Conduct regular
service satisfaction
surveys
R3 Changes to  Availability of Risk  Monitor proposed Annual review of the risk by
Government contract and grant Committee legal and regulatory the Risk Committee reporting
policy that have funding to the board

Sample Completed Risk Register 12


Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating

an adverse  Impact of general changes (e.g.


impact on the legislation or Charities Act)
Organisation or regulation on  Participate in
the wider sector activities undertaken relevant umbrella
by the Organisation /membership bodies
 Role of the C&V  Lobby government in
sector undermined/ relation to relevant
unvalued issues that impact on
the sector

List of High Rated Risks

Risk No Copy risk from above

Risk No Copy risk from above

The matrix for assessing impact, likelihood and effectiveness of existing controls

Each risk is scored in terms of:


* likelihood i.e. the probability of future occurrence, how likely the risk it is that the risk will occur and how frequently it has occurred in the past.
* impact i.e. the impact on the organisation and external stakeholders if the risk occurs.
* effectiveness of existing controls i.e. given the controls which are currently in place, how effective are they at mitigating the risk.

A scale of 1 to 5 is used for Likelihood and Impact, and 1 to 3 is used for the effectiveness of existing Controls, according to the following matrix:

Likelihood Impact Controls


Scale of 1 - 5 Scale of 1 – 5 Scale of 1 - 3
1 = Rarely, if ever 1 = No significant impact 1 = Controls highly effective
2 = Possible 2 = Minor impact 2 = Controls effective, but could be improved
3 = Likely 3 = Significant but containable impact 3 = No controls / controls are ineffective
4 = Very Likely 4 = High impact
5 = Unavoidable / already occurring 5 = Extremely detrimental impact

The risk score is determined by multiplying the risk impact by the risk likelihood by the effectiveness of the controls.

Sample Completed Risk Register 13

You might also like