WCapsuleM8

Risk Register

$19

Keep a project and business risk register — strategic, financial, operational and compliance risks scored on a 5×5 grid, inherent and residual, with the four responses and a board-ready report. Not a workplace safety assessment. Nothing is uploaded.

Version 1.0.0 · Updated Aug 6, 2026

Overview

Keep a project and business risk register — strategic, financial, operational and compliance risks scored on a 5×5 grid, inherent and residual, with the four responses and a board-ready report. Not a workplace safety assessment. Nothing is uploaded.

Frequently asked questions

How does the Risk Register licence work?

It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.

Can I try the Risk Register before buying?

Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.

Does my data stay private?

Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.

Does it work offline?

Yes. Once downloaded it runs completely offline in any modern browser — no internet connection, installation or plugins needed.

Do I need Excel or any other software?

No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.

How to use Risk Register

The complete in-tool guidance, reproduced here so you can read it before you download.

What this tool does

CM8-229 is a working risk register for a business, a programme or a project. You record each risk as a cause-event-consequence statement, score it on a 5×5 grid twice — once as if you did nothing, once with your controls in place — assign an owner, a response and a review date, and print a report fit for a board pack, a bank, an investor or an audit.

It is built for strategic, financial, operational, compliance, reputational, project, technology and people risks — losing your biggest customer, a currency swing, a ransomware attack, a regulation change. It is deliberately not a workplace health-and-safety risk assessment; that is a different document with a different purpose, covered below.

Everything runs inside this single file. There is no account, no upload and no network request of any kind, so your commercial exposures — the things you would least like a competitor to read — never leave the computer you are using.

Writing the risk statement

Most registers fail at the first field. "Cyber" is not a risk; it is a word. A usable risk statement has three parts:

  • Cause — the condition that exists today, stated as a fact.
  • Event — the thing that may happen because of it.
  • Consequence — what it would do to your objectives if it did.

The pattern is: because of [cause], [event] may occur, leading to [consequence].

Bad: "Risk of supplier problems." Nobody can score that, own it or mitigate it.

Good: "Because the main drive component comes from one supplier, a plant failure or insolvency at that supplier may occur, leading to a production stop within three weeks and late-delivery penalties." Now the likelihood question is concrete (how fragile is that supplier?), the impact question is concrete (what does three weeks of stoppage cost?), and the mitigations write themselves (second source, buffer stock, contract clauses).

If you cannot fill in all three parts, you have not yet understood the risk — which is worth knowing in itself. Park it with the best statement you can manage and sharpen it at the next review.

The 5×5 scales

Every risk is scored for likelihood and impact on a 1–5 scale. The words matter more than the numbers — two people using the same words will argue less than two people guessing what a "3" means.

  • Score — Likelihood — Impact
  • 1 — Rare — only in exceptional circumstances — Negligible — absorbed in normal running
  • 2 — Unlikely — could occur at some time — Minor — noticeable, but contained locally
  • 3 — Possible — might well occur at some time — Moderate — significant management effort to recover
  • 4 — Likely — will probably occur — Major — threatens an objective or a period's results
  • 5 — Almost certain — expected to occur — Severe — threatens the organisation or a whole programme

Adapt the impact wording to your own scale of pain — for one organisation "major" is a five-figure loss, for another it is eight. What matters is that everyone scoring risks uses the same definitions, and that likelihood is judged over a stated horizon (the next 12 months is the usual choice).

The tool buckets scores into four bands: Low 1–4, Moderate 5–9, High 10–14, Critical 15–25. The residual-profile chart is your heat map, flattened into a bar per band so it prints legibly.

Inherent and residual — why you score twice

Score = likelihood × impact (1 to 25) Risk reduction = inherent score − residual score

Inherent is the risk as if you did nothing — no controls, no insurance, no clever contracts. Residual is the risk with your current controls working as described. Scoring both, rather than just one, buys you three things:

  • It shows what your controls are worth. The reduction column in the movement table is the value of the money and effort you spend on mitigation. A control that moves nothing is a cost, not a control.
  • It stops the register flattering itself. A residual "4" looks calm until you see it started at 20 and the whole gap depends on one untested backup.
  • It tells you what happens if a control fails — the risk springs back toward its inherent score, not to zero.

The tool will not save a row whose residual score is higher than its inherent score — controls should reduce risk, so a residual above inherent is either a typo or a control that is making things worse, and either way it needs a second look. Equal scores are allowed: some risks genuinely have no effective control yet, and saying so honestly beats inventing a reduction.

The four responses

Every risk needs a decision, and there are only four:

  • Treat — act to reduce likelihood, impact or both. Qualify a second supplier; test the backups; document the design decisions. Most risks on most registers are treated. The tool insists a "treat" response has its mitigation written down — a treatment that exists only as an intention is a tolerate wearing a costume.
  • Tolerate — accept the residual risk and monitor it. The honest answer when the cost of further reduction exceeds the benefit, or the cause is a market condition you cannot change — a local skills shortage, for example. Tolerate is a decision, not a shrug: it needs an owner and a review date like everything else.
  • Transfer — move the financial consequence to someone else, through insurance, hedging, or contract terms. Insuring the warehouse, forward-buying currency. Note what transfer does not do: it moves money, not consequence — the insurer pays for the stock, but your customers still waited months.
  • Terminate — stop the activity that creates the risk. Exit the market, retire the product, decline the contract. Rare, and usually the sign of a register that reached the board.

Running the monthly review

A register that is written once and filed is decoration. The tool is built around a short recurring review — monthly for most organisations, fortnightly on a fast-moving project:

  1. Open the Reviews due table. Work through everything marked Overdue or Due soon — that is the agenda, pre-built. For each: has the likelihood or impact moved? Are the mitigations actually done? Set the next review date before moving on.
  2. Check the Risk movement table. Any row with a reduction of zero has controls that are not working or scores that were never honest. Any row where residual sits in High or Critical needs a decision recorded, not just a re-reading.
  3. Look at the residual profile. The question for the room is simple: are we comfortable carrying this shape? If Critical is not empty, who is doing what, by when?
  4. Add the new risks that surfaced since last time, as proper three-part statements, each with a named owner — one person, not a department. Close what is genuinely dead and mark as realised anything that actually happened; a realised risk is a lesson about how you score, so keep it visible rather than deleting it.

Twenty minutes of this every month is worth more than a beautiful register refreshed annually for the auditors.

This is not a health-and-safety risk assessment

The two documents share a word and a scoring habit, and nothing else. A workplace risk assessment examines specific hazards to people — machinery, chemicals, working at height — identifies who could be harmed and how, and records the physical control measures. In many countries it is a specific legal duty with its own required form and content.

A risk register — this tool — manages threats to the organisation's objectives: money, time, reputation, continuity, compliance. Its audience is management and the board, not the shop floor. Keeping them in one document serves both badly: safety hazards get buried among commercial worries, and the legal record gets muddled with strategy. If you need to assess hazards to people at work, use a dedicated risk assessment prepared to your local requirements; by all means record "a serious workplace accident" here as a business risk that points at it.

FAQ

How many risks should a register hold? Enough to be honest, few enough to be reviewed. For a small business or a single project, ten to twenty live risks is typical. A register of eighty is a filing exercise; nobody reviews eighty risks monthly.

Should likelihood consider a time horizon? Yes — score it over a stated period, usually the next 12 months, and use the same horizon for every risk. "Will the supplier ever fail?" and "might the supplier fail this year?" are different questions with different scores.

Who should own a risk? The person with the authority to spend money or change plans in response to it — one name, never a team. The owner is who the review asks "what changed?"

Can inherent and residual be equal? Yes. It means you currently have no effective control, which is a perfectly honest position for a new risk — and a prompt to decide whether to treat or tolerate it.

What does a realised risk mean for the register? The event happened. Manage the consequence as an issue, but keep the row: compare what happened with how it was scored, and let that calibrate the scores you give everything else.

Saving your work

Risks, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.

Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work. Reset asks twice, then erases everything this tool has stored. There is no undo. A risk register is commercially sensitive by nature — treat exports accordingly.

Accuracy & disclaimer

The arithmetic here is deliberately simple — likelihood times impact — and the tool does it faithfully. Everything that matters sits underneath the arithmetic: whether the risks on the register are the real ones, whether the scores reflect evidence or optimism, and whether the controls behind each residual score have ever been tested. A 5×5 score is structured judgement, not a probability estimate, and comparing scores between organisations — or between people using different scale definitions — means nothing.

A register does not manage risk; people do. This tool is a record-keeping and prioritisation aid, not risk-management advice, not a compliance document, and not a workplace health-and-safety risk assessment.

Build a register of processing activities: purpose, data subjects, data categories, lawful basis, retention, transfers and impact assessments, with a gap list and a printable report. Runs entirely in your browser — nothing is uploaded.

DownloadView

Record every gift and hospitality item given or received, test each one against your own approval and prohibition thresholds, and catch the cumulative annual total from a single counterparty that item-by-item checks always miss. Runs entirely in your browser — nothing is uploaded.

DownloadView

Log personal data breaches against the clock: hours from awareness to containment and to report, a likelihood-and-severity risk rating, deadline tracking and a printable register. Runs entirely in your browser. Nothing is uploaded.

DownloadView