The risk register
For the helpdesk teamThe risk register
Section titled “The risk register”The risk register is the trust’s catalogue of what could go wrong. Each entry has a likelihood, an impact, an owner, mitigations in place, and a review cadence.

It exists because (a) Ofsted asks; (b) governors expect it; (c) the trust runs better when the obvious risks have explicit mitigations rather than implicit hope.
What goes in the register
Section titled “What goes in the register”Risks of three flavours:
- Strategic — long-horizon, trust-level: pupil number decline, loss of a major partner, leadership transition
- Operational — day-to-day delivery: cyber attack, safeguarding incident, exam mark loss, building closure
- Compliance / regulatory — external obligations: KCSIE, GDPR, health & safety, ESFA reporting
Each risk has:
- Title + description
- Category — Strategic / Operational / Compliance / Reputational / Financial
- Likelihood — 1 (rare) to 5 (very likely)
- Impact — 1 (negligible) to 5 (severe)
- Score — likelihood × impact, drives RAG colour
- Owner — who’s accountable; usually a member of SLT
- Mitigations — one or more mitigation entries, each with a type (control / accept / transfer / avoid), description, and status
- Residual risk — score after mitigations (residual likelihood × residual impact)
- Review cadence — monthly / quarterly / half-yearly / annually
- Next review date
- Linked controls — see KCSIE controls
RAG scoring
Section titled “RAG scoring”The default thresholds (applied to the residual score where set, otherwise the inherent score):
| Score | Colour |
|---|---|
| 1–7 | Green |
| 8–14 | Amber |
| 15–25 | Red |
The register shows residual scores on the heat-map where they are set, so you can see whether mitigations have genuinely moved the needle.
What “good” looks like
Section titled “What “good” looks like”A healthy register has:
- 30-50 entries (too few = under-thinking; too many = unfocused)
- A mix of categories (a register that’s all-cyber misses safeguarding)
- Active mitigations on every Red item (not “we hope it doesn’t happen”)
- Honest review dates that aren’t all in the past
- Clear ownership — “the trust” is not an owner
Reviewing
Section titled “Reviewing”A risk that hasn’t been reviewed in its set cadence appears on the Overdue reviews dashboard. The owner gets an email reminder.
Don’t tick reviews off without actually reviewing — the auditor reads the audit log and notices when 47 risks were “reviewed” in 5 minutes by the same person.
Linking to the rest of the platform
Section titled “Linking to the rest of the platform”Risks can link to:
- Controls (KCSIE / framework-mapped)
- Tickets that materialise the risk
- Policies that cover the area
- Projects that address the risk
- Compliance schedules that mitigate
Building these links is what makes the register a working document instead of a yearly chore.