All content
Risk Register

What to Track in an Internal Audit Risk Register

A field-by-field guide to recording risks, scoring exposure, tracking mitigations, and preparing clear evidence for an internal audit.

Last updated:
What to Track in an Internal Audit Risk Register

A risk register is more useful during an internal audit when every entry tells a complete, consistent story. An auditor should be able to understand the risk, see how you assessed it, identify who owns it, and review what you are doing about it.

The exact fields you need will depend on your organization and audit scope. The following structure gives compliance teams a practical starting point for creating records that are clear enough for management reviews and audit documentation.

Start with a consistent risk record

Consistency matters more than lengthy descriptions. If one team records detailed causes and controls while another enters only a short title, comparing risks becomes difficult.

Set a minimum standard for every entry. At a basic level, each risk should answer four questions:

  • What could happen?
  • Why could it happen?
  • What would the consequences be?
  • What is being done about it?

Use the same likelihood and impact scales across the register. Apply a common set of status labels to mitigation actions, and agree on how categories and owners should be recorded. This makes the register easier to review and reduces clarification work during an audit.

Step 1: Add risks and their supporting details

Start by defining each risk in specific terms. Avoid vague entries such as “compliance issue” or “system problem.” A useful risk statement describes an uncertain event and its potential effect.

For example, instead of “supplier risk,” you might record: “A critical supplier may fail to provide required documentation, causing a delay in the compliance review.”

For each risk, consider recording the following fields.

Risk title

Use a short, recognizable name. The title should help reviewers distinguish the risk in lists, reports, and the risk matrix. Keep the fuller explanation in the description.

Risk description

Explain what may happen and why it matters. Write for someone who does not work with the process every day. Avoid internal abbreviations unless you define them.

Category

Assign a category so reviewers can group related risks. Risk Register supports operational, financial, strategic, compliance, and custom categories. A stable category structure helps you identify concentration in a particular area.

Owner

Name the person responsible for monitoring and managing the risk. The owner should be close enough to the work to understand changes in exposure and follow up on actions.

Ownership does not necessarily mean that the person performs every mitigation task. It means that they are accountable for keeping the record current.

Causes

Record the conditions or events that could lead to the risk. Causes help an auditor understand whether your mitigation work addresses the source of the exposure rather than only its effects.

Consequences

Describe what could happen if the risk occurs. Depending on the risk, consequences could affect operations, finances, strategy, or compliance obligations. Keep them concrete and connected to the stated risk.

Existing controls

Document the controls already in place. Describe what the control does rather than entering only the name of a policy or procedure. This provides context for the score and helps reviewers understand the current response.

Step 2: Assess likelihood and impact

Once the record is clear, assess the risk using a consistent scoring system. Risk Register lets you rate likelihood and impact, then automatically calculates the composite risk score and priority level.

Likelihood rating

Likelihood describes how probable the risk is. Apply the same scale definitions across all entries. Your team should agree on what each rating means so that similar risks receive comparable assessments.

Base the rating on available evidence where possible. Relevant inputs may include previous incidents, control performance, process changes, or current operating conditions. Keep any supporting material required by your audit process outside or alongside the register as appropriate.

Impact rating

Impact describes the severity of the consequences if the risk occurs. Consider the areas relevant to your organization, such as financial loss, operational disruption, strategic effects, or compliance failures.

Do not reduce the rating simply because a risk is unlikely. Likelihood and impact are separate dimensions, which is why a low-probability event with severe consequences can still require attention.

Composite score and priority

The tool multiplies likelihood by impact to calculate the risk score. That gives you a repeatable way to compare entries and identify which risks need attention first.

The score supports judgment; it does not replace it. A compliance requirement, management concern, or change in circumstances may justify attention even when a risk does not have the highest numerical score.

Risk matrix position

Risk Register plots risks on a color-coded matrix based on their likelihood and impact ratings. The matrix highlights high-, medium-, and low-priority areas and makes clusters easier to spot.

During audit preparation, review whether the matrix matches your understanding of current exposure. Unexpected positions may indicate an outdated rating, an unclear scale, or inconsistent assessment between teams.

Step 3: Monitor mitigation and prepare reports

A risk record should show what happens after assessment. Risk Register lets you define mitigation actions for each risk and track their status over time.

Mitigation action

Describe the specific work intended to reduce likelihood, limit impact, or improve an existing control. Avoid broad actions such as “monitor closely.” A reviewer should be able to tell what will change when the action is completed.

A risk may have more than one mitigation action. Separate actions can make ownership and status easier to follow, particularly when different teams are involved.

Action status

Keep the status current. An outdated status can make an otherwise detailed register unreliable. Review open actions before an audit and confirm that the recorded state matches the actual work.

If an action is delayed or no longer appropriate, update the record rather than leaving the original plan unchanged. The register should reflect the current response to the risk.

Ongoing review

Risk assessment is not a one-time exercise. Review entries when controls change, new information becomes available, or mitigation work affects the exposure. Reassess likelihood and impact when the basis for the original score has changed.

Risk Register provides dashboard reports with summary statistics, risk distribution, and trend analysis. These views can help management and compliance teams examine the register as a whole rather than reviewing entries in isolation.

Reports and export

Generate summary reports for management reviews and export the risk register for stakeholder presentations or compliance documentation. Before exporting, check that descriptions, ownership, scores, and action statuses are complete and consistent.

A useful pre-audit review includes:

  • Checking for blank or unclear descriptions
  • Confirming that every risk has an owner
  • Reviewing unusually high or low scores
  • Checking the status of mitigation actions
  • Looking for duplicate or overlapping risks
  • Confirming that categories are used consistently
  • Reviewing the matrix for patterns or clusters

Common record-quality problems

Many audit questions come from incomplete records rather than the underlying risk decision. A clear register reduces avoidable follow-up.

Watch for entries that combine several unrelated risks in one record. These are difficult to score because each event may have a different likelihood, impact, owner, or mitigation plan. Split them when separate assessment would make the response clearer.

Also check for controls listed as mitigations without explaining what additional work is planned. Existing controls describe the current environment; mitigation actions describe what you intend to change or complete.

Finally, avoid changing scores without reviewing the supporting description. If the risk has become more or less likely, the record should still explain the event, causes, consequences, controls, and response in a way that supports the new assessment.

Frequently asked questions

How are risks scored in Risk Register?

You rate each risk by likelihood and impact. The tool multiplies those ratings to calculate a composite risk score and assign a priority level.

Can compliance teams use custom risk categories?

Yes. You can create and manage custom categories, as well as organize risks using operational, financial, strategic, or compliance categories.

What can I provide for an audit review?

You can generate summary reports and export the risk register for compliance documentation or stakeholder presentations. Dashboard reports also show summary statistics, risk distribution, and trend analysis.

A well-maintained register gives reviewers a clear path from identification to assessment and action. Use Risk Register to record risks, calculate scores, review the matrix, and prepare reports.

Risk Register

Get started for free — no signup required.

Open the app