Skip to content

Risk categories

For admins

The risk register’s column-of-truth for what kind of risk is this? is the categories taxonomy. Trust boards typically report risks against a fixed set — strategic, operational, financial, reputational, compliance — and the dashboards aggregate by category.

  • Name — sentence case. “Financial”, “Strategic”, not “Financial risks”.
  • Description — what counts. “Risks to the trust’s financial position — solvency, cash flow, fraud, audit findings.”
  • Display order — controls the order on the register’s category picker.
  • Colour — hex code. Used for the chip on every risk in this category.
  • Is active — flag. Inactive categories are hidden from new-risk pickers but historical risks keep their category.

Rarely. Once the board has reported against a set of categories for a year, changing them invalidates trend lines. Stick with what the board asks for in their annual report.

If you do need to split a category (e.g. financial into operational financial and strategic financial), prefer adding the new category rather than editing the existing one — historical risks keep their old labels and you don’t lose comparability.

The seeded set follows the standard trust risk taxonomy:

  • Strategic
  • Operational
  • Financial
  • Reputational
  • Compliance
  • Safeguarding (where the trust treats safeguarding separately from operational)
  • Cyber / IT (where IT risk warrants standalone visibility)

You can add trust-specific ones — Educational outcomes, DfE policy changes — but think twice before deleting any of the seeded ones.

  • The category’s colour propagates to every risk’s chip in lists and dashboards. Changing it after launch makes the eye relearn — pick colours deliberately.
  • Soft-delete is supported; don’t hard-delete. Risks referencing a deleted category would orphan.
  • The form doesn’t restrict which categories a risk owner can pick. Discipline of taxonomy is human, not enforced.