D-WINGS Consulting LLP
GRC INSIGHTS

Building a Risk Register That Survives Contact With an Audit

D-WINGS Consulting LLP · 28 April 2026

Almost every organisation pursuing ISO/IEC 27001 or a similar framework builds a risk register at some point in the project. Far fewer keep it alive afterward — and an auditor can usually tell within the first ten minutes of review which category yours falls into.

The tell-tale signs of a register built only for the audit: risk ratings that haven’t changed since the original assessment; treatment plans with no owner, no target date, or an owner who left the organisation eighteen months ago; and risks that were “accepted” with no documented rationale or re-review date. None of this is necessarily dishonest — it’s what happens by default when a risk register is treated as a one-time deliverable rather than an operating tool.

What a living risk register actually requires:

Why this matters beyond the audit. A risk register that’s actually maintained is one of the few artefacts that gives leadership an honest, current view of where the organisation is exposed — which is the entire point of running an ISMS in the first place. A register that only gets opened once a year, right before the surveillance audit, tells you the certification is current but tells leadership almost nothing useful about actual risk posture in between.

The practical fix for most organisations isn’t a better spreadsheet — it’s a defined operating rhythm: who reviews the register, how often, what triggers an off-cycle update (a new penetration test finding, a new regulatory requirement, a significant infrastructure change), and who signs off that the review happened. That operating rhythm is usually the difference between a register that’s a compliance artefact and one that’s a governance tool.

Have a question on this?

Talk to an Expert