Skip to content

The risk register

For the helpdesk team

The risk register is the trust’s catalogue of what could go wrong. Each entry has a likelihood, an impact, an owner, mitigations in place, and a review cadence.

Risk register — the heat-map shows the distribution of residual scores across the 5×5 likelihood/impact matrix

It exists because (a) Ofsted asks; (b) governors expect it; (c) the trust runs better when the obvious risks have explicit mitigations rather than implicit hope.

Risks of three flavours:

  1. Strategic — long-horizon, trust-level: pupil number decline, loss of a major partner, leadership transition
  2. Operational — day-to-day delivery: cyber attack, safeguarding incident, exam mark loss, building closure
  3. Compliance / regulatory — external obligations: KCSIE, GDPR, health & safety, ESFA reporting

Each risk has:

  • Title + description
  • Category — Strategic / Operational / Compliance / Reputational / Financial
  • Likelihood — 1 (rare) to 5 (very likely)
  • Impact — 1 (negligible) to 5 (severe)
  • Score — likelihood × impact, drives RAG colour
  • Owner — who’s accountable; usually a member of SLT
  • Mitigations — one or more mitigation entries, each with a type (control / accept / transfer / avoid), description, and status
  • Residual risk — score after mitigations (residual likelihood × residual impact)
  • Review cadence — monthly / quarterly / half-yearly / annually
  • Next review date
  • Linked controls — see KCSIE controls

The default thresholds (applied to the residual score where set, otherwise the inherent score):

ScoreColour
1–7Green
8–14Amber
15–25Red

The register shows residual scores on the heat-map where they are set, so you can see whether mitigations have genuinely moved the needle.

A healthy register has:

  • 30-50 entries (too few = under-thinking; too many = unfocused)
  • A mix of categories (a register that’s all-cyber misses safeguarding)
  • Active mitigations on every Red item (not “we hope it doesn’t happen”)
  • Honest review dates that aren’t all in the past
  • Clear ownership — “the trust” is not an owner

A risk that hasn’t been reviewed in its set cadence appears on the Overdue reviews dashboard. The owner gets an email reminder.

Don’t tick reviews off without actually reviewing — the auditor reads the audit log and notices when 47 risks were “reviewed” in 5 minutes by the same person.

Risks can link to:

  • Controls (KCSIE / framework-mapped)
  • Tickets that materialise the risk
  • Policies that cover the area
  • Projects that address the risk
  • Compliance schedules that mitigate

Building these links is what makes the register a working document instead of a yearly chore.