Most boards have one. Fewer could say how the last new risk reached it. This guide sets out what a risk register should include, how scoring and risk appetite work, what charity, academy, school and care regulators require, and where the register quietly goes out of date.
What a risk register is, and the rule behind it
A risk register is a written schedule of the risks an organisation faces, with each risk's likelihood and impact, the controls in place, the risk that remains and the person responsible for it. CC26 describes the register as one way of codifying a charity's risk management: it "schedules gross risks and their assessment, the controls in place and the net risks, and can identify responsibilities, monitoring procedures and follow up action required".
No single UK statute requires every charity, school or care provider to keep a document called a risk register. The duty is to manage risk and, for some organisations, to report on it. CC26 says charity trustees "should regularly review and assess the risks faced by their charity in all areas of its work and plan for the management of those risks". The exception is academy trusts: the Academy Trust Handbook says "the trust must maintain a risk register".
The phrase has two other senses. Project teams often keep a risk register for a single project, and the Cabinet Office publishes the National Risk Register 2026, which "outlines the most serious risks facing the United Kingdom". This guide is about the organisation-wide register that trustees, governors or a provider's directors own.
What a risk register should include
The model register in Annex 1 of CC26 has ten columns:
- Risk area and risk identified – what could happen, written as an event rather than a topic.
- Likelihood of occurrence, with its score.
- Severity of impact, with its score.
- Overall or gross risk – the combined score before controls.
- Control procedure – what is already in place.
- Retained or net risk – what remains once the controls work.
- Monitoring process – how the board will know the controls are working.
- Responsibility – the named risk owner.
- Further action required, with who and by when.
- Date of review.
Two more columns earn their place. A risk category shows whether the board is only looking at money: CC26's categories are governance, operational, financial, external, and compliance with law and regulation. And a cause and consequence makes the description usable. HM Treasury's Orange Book defines risk as "the effect of uncertainty on objectives", usually expressed in terms of causes, potential events and their consequences. "Buildings" is a heading; "the boiler fails in winter because it is past its expected life, and sessions are cancelled" is a risk someone can own.
An illustrative worked example for a small charity running a day centre with volunteers, scored likelihood × impact on scales of 1 to 5, before controls (gross) and after them (net):
- Heating failure at the day centre (operational). Cause: a boiler past its expected life. Potential impact: winter sessions cancelled for older members. Gross 4 × 3 = 12. Controls: annual service, a hire-heater arrangement, a replacement quote. Net 6. Owner: operations manager. Review: quarterly.
- A volunteer's DBS recheck is missed (compliance). Cause: recheck dates, set by the charity's own policy, kept in one person's diary. Potential impact: harm to a member, a serious incident report, damage to reputation. Gross 3 × 5 = 15. Controls: recheck dates in a shared register, a monthly exception report to the safeguarding lead. Net 5. Owner: volunteer coordinator. Review: every board meeting.
- Loss of the largest grant (financial). Cause: the funder's programme ends in March. Potential impact: a third of staff costs unfunded. Gross 3 × 4 = 12. Controls: reserves policy, two new bids, a costed contingency plan. Net 8. Owner: chief executive and treasurer. Review: quarterly.
- Board lacks finance skills (governance). Cause: the treasurer steps down at the AGM. Potential impact: weak scrutiny of budget and reserves. Gross 2 × 4 = 8. Controls: a skills audit, targeted recruitment. Net 4. Owner: chair. Review: annually.
A school risk register has the same shape with different rows: the roof, a falling roll, a safeguarding lapse, a cyber incident. A care provider's adds falls, medicines errors, infection control and staffing. Keep the register to what the board needs to see; the risk assessment for a trip or a hoist sits underneath it.
Scoring: likelihood, impact, the heat map and risk appetite
A common method scores each risk on two five-point scales and multiplies them. CC26 scores likelihood from remote (1) to highly probable (5) and impact from insignificant (1) to extreme or catastrophic (5), and describes the method from its earlier guidance, in which "the impact score is usually multiplied by the score for likelihood" and the product used to rank the major risks.
The grid of those scores is the risk matrix, usually coloured as a heat map. CC26 also offers a version that weights impact more heavily, scoring likelihood times impact plus impact again (xy+y), with red for 15 or more, yellow for 8 to 14, and blue or green for 7 or less. Its reason: a very high impact, very low likelihood risk is now accepted by many as more important than a very likely one with an insignificant impact, yet simple multiplication scores them the same.
Score each risk twice: controls reduce the gross score to a net one. CC26 says trustees "need to form a view as to the acceptability of the net risk that remains after management".
The net score means something only against a risk appetite. The Orange Book describes appetite as the nature and extent of the principal risks an organisation "is willing to take to achieve its objectives". CC26 puts it in charity terms: a charity with sound reserves could take on a riskier project than one in financial difficulty, and trustees "need to let their managers know the boundaries and limits set by their risk policies".
For the response to each risk, CC26 gives four basic strategies:
- Transfer or share the financial consequences, usually through insurance or outsourcing.
- Avoid it, by not taking up a contract or by stopping the activity.
- Manage or mitigate it with controls.
- Accept it as a risk that cannot be avoided if the activity is to continue.
What charities, academy trusts, schools and care providers must do
Charities in England and Wales. A charity whose accounts must by law be audited has to include a risk statement in its trustees' annual report. Regulation 40 of the Charities (Accounts and Reports) Regulations 2008 requires "a statement as to whether the charity trustees have given consideration to the major risks to which the charity is exposed and satisfied themselves that systems or procedures are established in order to manage those risks". Under the Charity Commission's threshold changes at a glance, for financial years ending on or after 30 September 2026 an audit is required where income is over £1,500,000, or income is over £500,000 and assets are over £5,000,000.
Below the audit threshold the statement is good practice: CC26 says trustees of smaller charities "are encouraged to make a risk management statement as a matter of good practice". Charitable companies other than small companies must also include a strategic review describing "the principal risks and uncertainties facing the company".
Academy trusts. The Academy Trust Handbook 2026, effective from 1 October 2026, requires a register by name. The trust must maintain a risk register; overall responsibility for risk management, "including ultimate oversight of the risk register", must stay with the board of trustees, drawing on advice from the audit and risk committee; the board should review the register frequently and must conduct a full review at least annually; and risk management covers the trust's full operations, "not only financial risks". The trust must establish an audit and risk committee, which should meet at least three times a year and must "review the ratings and responses on the risk register to inform the programme of work" for internal scrutiny.
Maintained schools in England. The DfE's Maintained schools: governance guide does not require a document called a risk register. It says an effective governing body manages risk by overseeing a whole school approach, "having a risk management framework for identifying, managing and recording risks and incidents", making sure risk assessments are in place, and reviewing all risks regularly, including those tied to the school improvement plan. A register is the plainest way to show that recording.
Care providers. Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires a provider registered with CQC in England to have systems or processes that enable it to "assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk". It does not use the words risk register. CQC's guidance on Regulation 17 says risks "must be escalated within the organisation or to a relevant external body as appropriate" and that identified risks "must be continually monitored and appropriate action taken where a risk has increased". A provider-level register, reviewed by the board or owner, is direct evidence of both.

Who owns the register, and how often the board reviews it
The board owns it. CC26 says the responsibility for the management and control of a charity "rests with the trustee body", but trustees need not do every part themselves: in all but the smallest charities, elements are delegated to staff or advisers, and trustees stay involved enough to make the risk statement "with reasonable confidence".
Each risk also needs an owner below the board, who runs the controls and reports on them. In CC26's examples the owners are the trustees and treasurer for investments, and the fundraising manager and chief executive for fundraising. A risk owned by "all staff" is owned by nobody.
On frequency, CC26 says annual monitoring by trustees supplemented by interim reports "is likely to be sufficient for most charities where operating conditions are stable", and that more frequent monitoring might be advisable depending on the risk profile. The Academy Trust Handbook is firmer: the board should review the register frequently and must review all of it at least annually.
What makes the review real is what reaches it. CC26 says a successful process ensures that "new risks are properly reported and evaluated" and that "trustees are provided with relevant and timely interim reports". Minute each review: which risks changed score and why, which were added or closed, and the decisions the board took.
The risk that was raised in the group chat and never reached the register
The register rarely fails in its columns. It fails at its input. The first sign of most risks is not a form or an agenda item but a message. "The boiler's leaking again." "Just noticed Sam's DBS recheck is overdue." "Has anyone heard from the council about next year's grant?" A photo of water across the hall floor, sent to the staff or trustees' WhatsApp group at nine in the evening.
Each of those is risk identification, in the sense CC26 means when it asks that new risks are properly reported. Most are dealt with on the spot, and most never reach the register, because the register is updated from a meeting and the warning was posted in a group chat.
It matters most after something has gone wrong. After a flood, a safeguarding incident or a lost contract, the question a regulator, insurer or tribunal asks is what the organisation knew and when. If the first warning sits on the personal phones of a caretaker, a trustee and a manager who has since left, the organisation cannot show that it knew, or that it acted. An end-to-end-encrypted consumer group lives on its members' handsets, so the organisation has no copy of its own to produce.
ComplyChat is one answer to that second half: a channel your organisation owns, where everyone added is told the channel is on the record, messages are recorded on the server as they are sent, and on paid plans, once your Microsoft 365 tenant is connected, the lasting record files into your own Microsoft 365 under your own retention rules. It is not a risk register, a risk management system or an incident log, and it will not score a risk or remind anyone to review one. If new risks already reach your register through a route everyone uses, you do not need it for this.
A question for your next board, governing body or audit and risk committee meeting: of the last five risks first raised in a message rather than at a meeting, how many are on the register, with the date the organisation first knew?
Questions people ask
Is it a legal requirement to have a risk register?
There is no general UK legal requirement to keep a document called a risk register; the duties are to manage risk and, for some organisations, to report on it. Academy trusts are the exception: the Academy Trust Handbook 2026 says the trust "must maintain a risk register". A charity in England and Wales whose accounts must by law be audited must include a risk statement in its trustees' annual report, and a CQC-registered provider in England must have systems to "assess, monitor and mitigate the risks" under Regulation 17.
What is a risk register in the UK?
In UK governance, a risk register is a board's schedule of the organisation's main risks, each scored for likelihood and impact, with its controls, owner, remaining risk and review date. It is different from the Cabinet Office's National Risk Register, which covers the most serious risks facing the country.
What should be included in a risk register?
For each risk: the risk identified, its likelihood and impact scores, the gross risk, the controls, the net risk, the monitoring process, the owner, further actions and a review date. Those are the ten columns of the model register in Annex 1 of CC26.
What is the difference between a risk register and a risk matrix?
A risk matrix is the grid used to score a risk, with likelihood on one axis and impact on the other; a risk register is the list of risks that records each score alongside the controls, owner and actions. CC26 shows the matrix as a five-by-five heat map and the register as a separate template in Annex 1.
Can you provide an example of a risk register?
Yes. CC26's Annex 1 records unsatisfactory fundraising as probable (4) and major (4), a gross risk of high (20), controlled by financial appraisal of new projects, benchmarking of returns and budget reporting, leaving a net risk of medium owned by the fundraising manager and chief executive.
Where to read the official guidance
For charities, start with Charities and risk management (CC26). Academy trusts should read parts 2 and 3 of the Academy Trust Handbook 2026; maintained schools, section 2.5 of the governance guide; care providers, CQC's Regulation 17 guidance. HM Treasury's Orange Book, written for central government, explains risk appetite.
Quotations are from those documents as published on 28 September 2026; CC26 was last updated on 16 September 2026. This guide is a practical summary for boards in England and Wales, not legal or financial advice.
We build ComplyChat for the work conversations organisations need to keep. A risk register is only as current as the route by which new risks reach it, and that route is usually a message. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting record in its own Microsoft 365.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- National Risk Register 2026 gov.uk
- Orange Book gov.uk
- Regulation 40 of the Charities (Accounts and Reports) Regulations 2008 legislation.gov.uk
- Threshold changes at a glance gov.uk
- Academy Trust Handbook 2026 gov.uk
- Maintained schools: governance guide gov.uk
- Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
- CQC's guidance on Regulation 17 cqc.org.uk
- Charities and risk management (CC26) gov.uk


