Nonprofit Risk Register Template
Nonprofit Risk Register Template
There are a number of approaches and frameworks for developing an organisation’s Risk Management System and Risk Register. This document
reflects the framework recommended by the Charities Regulator, though any non-profit may find it useful. This document is intended for guidance
only and all organisations should develop their own Risk Management System and Risk Register.
Introduction
1. Governance (G)
2. Strategic (S)
3. Compliance (legal & regulatory) (C)
4. Operational (O)
5. Financial (F)
6. Environmental or External (E)
7. Reputational (R)
Each risk on the register is given a brief description of the potential risk for the organisation and the potential impact if the risk was to occur. Each risk is also assigned a Risk
Owner who has oversight responsibility for monitoring the risk and the implementation/ review of the steps to be taken to mitigate the likelihood of the risk occurring or if it
does occur, the impact on the organisation. The monitoring frequency is specified and the risk owner needs to ensure that this monitoring occurs.
Each of the risks are assessed in terms of (1) likelihood of the risk occurring on a scale of 1 – 5 where 1 is very unlikely and 5 is very likely; (2) the impact for the Organisation
if the risk was to happen also rated on a scale of 1 -5 and (3) the controls in place or steps to be taken to mitigate the risk. The controls are rated of a scale of 1 to 3 where 1 it
is felt that the controls are very effective and 3 an assessment that the controls or steps are not very strong and/or likely to be effective in preventing the risk or the mitigating
its impact if it did occur. The risk score is determined by multiplying the risk impact by the risk likelihood by the effectiveness of the controls. (Likelihood X Impact) X Controls.
The following traffic light system is used on a risk register to highlight / prioritise risk:
Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating
F1 Dependency on a Cash flow and CEO Identify major Annual review of the risk by the 3 4 2 24
limited number of budget impact of funding/income source Risk Committee reporting to the
income/funding loss of income dependencies board. The review will assess;
sources source Implement adequate
Adequacy of reserves to
reserves policy
sustain an income shock
Opportunities for income
diversification or to develop
additional income sources
Risk Register
Risk Description of Description of Risk Owner Steps to Mitigate Monitoring Frequency Likelihood Impact Controls Risk
No Potential Risk Potential Impact (1-5) (1-5) (1-3) Rating
work performance
and motivation
G3 Quality of Inadequate Chair Assessed as part of Annual review of the risk by
reporting to information resulting annual board the Risk Committee reporting
Board (accuracy, in poor quality evaluation process. to the board of
timeliness & decision making Positive responses adequacy/effectiveness of
relevance) Failure of board to from board members the information provided to
fulfil its control on quality the board.
functions
Board becomes
remote and ill
informed
Risk Category: Strategic
S1 The Organisation The organisation Board Develop and monitor Annual review of this risk by
lacks an drifts with no clear 3-year strategic plan the Strategy, Committee
appropriate objectives, priorities which sets out the reporting to the board of
strategic direction or plans key aims, objectives adequacy/ effectiveness of
or focus that is in Issues are and targets of the the mitigation steps to
tune with the addressed piecemeal Organisation manage/minimise this risk
evolving needs with no strategic Regularly review (at
and business reference / context least every 5 years)
/operating Difficult decisions are the Organisation’s
environment avoided or put on the vision and
long finger constitution Review
Needs of of Constitution
beneficiaries not fully Develop and monitor
addressed annual operational/
Financial business plans
management CEO's report to the
difficulties Board mapped
Loss of reputation against strategic
aims and objectives
S2 The Organisation Dramatic loss of Board Review the Annual review of the risk by
does not have income up to closure experience of the the Risk Committee reporting
the flexibility or of some parts of all Covid-19 pandemic to the board of
the sustainability operations of the and assess what adequacy/effectiveness of
to survive a Organisation worked well and the mitigation steps to
major what should be done manage/minimise this risk.
Remoteness of organisation
senior managers structure, and the
/staff from allocation of
operational activities responsibilities and
Uncertainly or lack of time
clarity as to roles and
duties
Decisions made at
an inappropriate
level of excessive
bureaucracy
Decision bottlenecks
due to too many
decisions being
taken by one or two
individuals
Uneven workloads
Risk Category: Compliance (Legal or Regulatory)
C1 Compliance with Fines, penalties or CEO Identify key legal and CEO to submit a legal &
legislation and censure from licensing regulatory regulatory compliance report
regulations or activity regulators requirements that to the board annually.
appropriate to the Loss of licence to apply to the
activities, size undertake a particular Organisation Risk Committee to regularly
and structure of activity CEO submits a review and assess the risk
the charity Employee or compliance report register & mitigation steps to
beneficiary take action annual to the board report to the board
for negligence Allocate
Suffer damage to our responsibility for key
reputation compliance All compliance reports/
procedures concerns received from the
Put in place a CRA, funders or regulators to
process for be brought to the attention of
compliance the board.
monitoring and
reporting to the
board overseen by
the Risk Committee
Maintenance and
regular review of the
Organisation’s risk
register overseen by
the Risk Committee
Prepare for
compliance visits
Review compliance
reports /concerns
from regulators,
inspectors, auditors
and staff when
received take
appropriate action to
address issues/
concerns
C2 Regulatory and Regulatory action CEO Review and agree CEO to confirm to the board
funder reporting taken against the compliance annually that all regulatory
requirements are Organisation procedures and and funder reporting
not adequately Suffer damage to our allocation of staff requirements have been met
met reputation responsibilities
Negative impact on All compliance reports/
future funding concerns received from the
CRA, and any other funders
or regulators to be brought to
the attention of the board.
Implement and
periodically test the
data back-up
procedures and
security measures
Review insurance
cover at least once
every 3 years
Review/update
disaster recovery
plan at least once
every 3 years
O2 Poor Health & Staff injury CEO Comply with the law Annual review of the risk and
Safety Service liability and regulations assessment of the mitigation
Ability to operate all Get our external steps by the Risk Committee
or some of our safety advisors to reporting to the board
services curtailed or review and update
suspended our safety plan
Injury to Resident Train staff and safety
Member staff, visitors officer
and the public Put in place
monitoring and
reporting procedures
O3 Poor staff Employment CEO Review regularly the Annual review of the risk and
performance, disputes effectiveness and assessment of the mitigation
morale or attitude High staff turnover quality of our steps by the Risk Committee
rates recruitment process reporting to the board
Health & Safety Ensure that all new
issues staff receive a
Claims for injury, structured induction
stress, harassment, training
unfair dismissal Adhere to the
Equal opportunity & Organisation’s
diversity issues policies for checking
Adequacy of staff references, job
training descriptions,
Low morale contracts of
employment,
Strategic selection of
markets segments
that we wish to target
and serve.
Explore, assess and
regularly
opportunities for
collaboration,
partnership, joint
ventures or mergers
Risk Category: Reputational
R1 Adverse publicity Loss of funder Risk Monitor complaints Annual review of the risk by
generated by the confidence or Committee received (both the Risk Committee reporting
Organisation funding internal and external) to the board
Loss of influence Agree and regularly
Impact on staff review a crisis
morale management
Loss of confidence strategy for handling
by service users adverse publicity
including
consistency of key
messages and
nominated
spokesperson
R2 Poor service Customer/Beneficiary CEO Agree quality control Annual review of the risk by
provision leading complaints procedures the Risk Committee reporting
to poor customer Loss of fee income Monitor complaints to the board
satisfaction Loss of new and service user
business feedback
Suffer damage to our Enhance and
reputation innovate services
and systems
Conduct regular
service satisfaction
surveys
R3 Changes to Availability of Risk Monitor proposed Annual review of the risk by
Government contract and grant Committee legal and regulatory the Risk Committee reporting
policy that have funding to the board
The matrix for assessing impact, likelihood and effectiveness of existing controls
A scale of 1 to 5 is used for Likelihood and Impact, and 1 to 3 is used for the effectiveness of existing Controls, according to the following matrix:
The risk score is determined by multiplying the risk impact by the risk likelihood by the effectiveness of the controls.