Many businesses keep a risk register. Risks are listed, rated for likelihood and consequence, coloured red, amber or green, and given an owner. The list is reviewed every month or quarter. Yet the same risks sit there for a year, the planned actions are never funded, and when one of them finally happens, everyone agrees it was “on the register”. The business had a record of its worries, but nothing in that record changed what anyone did.
A simple test shows whether a register is working: what decision did last month’s review change? If nobody can name one, the register is an archive. That is not usually caused by poor administration. It is caused by structure. A list of risks with ratings cannot show how a risk would actually happen, which defences stand in the way, whether those defences depend on each other, or which of them is weakest today. Without that, there is nothing specific to act on, only a rating that moved from 15 to 12 because someone felt better.
This article explains how to turn a register into a working management tool: how to describe risks so they point to action, how to set early warning signals and triggers before pressure arrives, how to use a simple barrier diagram for the few risks that could seriously harm the business, and how to make sure owners can actually act. It is general information. Specific obligations, such as work health and safety duties, may apply regardless of what your register says; your state’s safety regulator and an adviser can help with those.
A record is not a control
Risk management earns its keep in one way only: by changing what the business does. That might be a different purchase, a different sequence of work, a changed contract, a backup arrangement or a conscious decision to accept a risk. If a year of risk reviews produced no different decisions, the process consumed time and produced paper.
Four common misreadings keep registers inert:
- Naming a risk is managing it. Identifying a risk does not change its likelihood or its consequence.
- A rating is information. A rating compresses two uncertain estimates into one number, then treats it as comparable across very different risks. It helps sort a long list. It rarely tells you what to do, or how much to spend. Two risks rated 15 may need completely different responses.
- An owner is enough. A named owner who cannot get money, change a plan or escalate a decision is looking after information, not managing exposure.
- A shorter register means more control. Risks may have been merged, closed early or turned into issues. A shorter list can hide rising exposure.
Describe risks so they point to action
A useful risk description links three things: cause, event and consequence. “Because our main powder-coating supplier has had two quality failures this year, there is a chance that a large batch will fail inspection, causing rework, late delivery and possible penalties under our builder contracts.”
That description suggests what could be done: check the supplier’s process, qualify a second supplier, change incoming inspection, hold more stock, change the specification or accept the exposure knowingly. “Supplier risk: high” suggests nothing.
Writing risks this way also helps separate genuine risks from things that are not:
- An issue is already happening and needs resolving now.
- A concern (“staff morale”) is too vague to act on until its cause and consequence are named.
- An impact (“cost overrun”) is a consequence of something else; the real risk is the cause behind it.
It also helps to group risks by area, such as commercial, technical, supplier, people, cash and external, so that attention does not cluster around the most familiar worries while unfamiliar ones go unrecorded.
Every response needs resources and a trigger
A response is not complete because an action appears in a column. A working response has:
- an owner with authority to act or to get a decision quickly;
- resources and time set aside in the budget and the schedule;
- a trigger or review point that says when it must happen;
- an expected effect on likelihood or consequence;
- any new risks the response creates;
- a fallback where the consequence is serious.
Every response costs something: money, time, flexibility, attention or a benefit given up. The pricing your risk controls article covers how to put a price on that and compare it with the protection bought.
Warning signals and triggers
Many risks are reviewed repeatedly without anything changing. The rating creeps from medium to high, the comment column grows, the status turns red, and the team is still debating what to do, because the response was never designed while there were plenty of options.
The purpose of early warning is to move the decision earlier, while responses are cheaper and easier to reverse. That needs three pieces, agreed in advance:
- A leading indicator: a measure that changes before the bad outcome, and that is connected to how the risk would actually happen. Supplier response times, a rising defect count, turnover in a critical team, the number of unresolved customer queries or a machine’s temperature trend are often more useful than a late-delivery count that only moves once the damage is done.
- A trigger: a defined point at which a specific action or escalation happens. Triggers stop people reinterpreting evidence once money has been spent and optimism has set in. “If two consecutive batches fail incoming inspection, we place the next order with the second supplier” is a trigger. “Monitor closely” is not.
- A ready response: the money, people, supplier arrangements, permissions and communication needed to act. If these do not exist, the contingency is an aspiration. A backup supplier who has never been asked to quote is not a backup.
Triggers should not be applied blindly. Indicators can be noisy, and circumstances change. Allow documented judgement to override a trigger, but require the reason to be written down.
| Element | Weak version | Working version |
|---|---|---|
| Indicator | Late deliveries this month | Supplier’s average reply time to purchase orders |
| Trigger | “Watch closely” | Reply time over five days for two weeks running |
| Response | “Find alternative supplier” | Alternative supplier already approved, prices on file, owner can place an order |
| Owner | Operations | A named person who can spend up to an agreed amount without further approval |
Bow-tie diagrams for the risks that matter most
For the small number of risks that could stop the business, injure people or destroy a major asset, a list is not enough. A bow-tie diagram is a simple, widely used way to show how a risk would actually happen.
At the centre is one event: the moment control is lost. “Cool room loses temperature.” “Fire in the spray booth.” “Main server fails during a trading day.” To the left are the causes, and between each cause and the event sit preventive barriers: the things that stop the event occurring. To the right are the consequences, and between the event and each consequence sit mitigating barriers: the things that limit the harm once the event has happened.
Drawing one forces four things a register does not:
- It separates prevention from mitigation. Many businesses discover they have invested almost entirely in prevention and have very little on the right-hand side. That is comfortable until prevention fails, which is the only time the right-hand side matters.
- It makes each barrier specific. A barrier must be something someone does, maintains or checks. “Follow procedures” does not survive the drawing. “Pre-start check by a trained operator, recorded and reviewed weekly” does.
- It exposes shared dependencies. If three barriers rely on the same person, the same power supply, the same software or the same inspection, the layers are not independent. The well-known Swiss cheese model of accidents, associated with the psychologist James Reason, makes the point that layered defences protect you only when their weaknesses are in different places.
- It shows degradation. Each barrier can be marked as working, degraded or missing. “Two preventive barriers are degraded” is a specific, actionable statement. A rating that moved from 15 to 12 is not.
Bow-ties take time. They need a session with the people who actually do the work, not only whoever keeps the register. Use them where the consequence is severe, the event is credible and the business currently believes it is well protected. That last condition matters most, because confidence is where untested assumptions and shared dependencies accumulate. Leave everything else on the list.
Five questions for each bow-tie
- Which barriers are currently degraded, and what would it cost to restore them? Express the answer as a decision to fund or not fund, not as an observation.
- Do any two barriers share a dependency? If they do, the count of barriers overstates the protection.
- Is the right-hand side real? If the event happened this week, what would actually limit the damage, and has it ever been tested?
- Who checks each barrier, and when did they last do so? A barrier nobody verifies is a claim.
- What would we need to see to accept this risk knowingly? Not every risk needs more treatment. Deliberate acceptance, written down with the reasoning, is a legitimate answer.
When a risk becomes an issue
When a risk actually happens, it becomes an issue that needs resolving. That should change how it is handled: immediate assessment, decision options, a person accountable for action and escalation where the consequences are large.
It should also trigger learning. Was the response carried out? Was the trigger missed? Was the assessment wrong? Or was the event outside anything the business had considered? Each answer leads to a different improvement. And closing the issue should not automatically close the risk; the event may leave a continuing exposure behind it.
Look across the whole business
Individual registers rarely show concentration. Several jobs, products or customers may depend on the same supplier, the same specialist, the same machine or the same approval. Each may treat the dependency as tolerable, while the combined exposure is not. A market shock, a cyber incident or a key person leaving may hit several areas at once.
So group risks by shared cause and shared constraint, not just by rating. Some risks need responses beyond any one job’s authority, such as changing the order of work, funding a backup, diversifying a supplier or declining a new commitment. The mapping dependencies across your projects article covers how to find these shared links.
A worked example
This is an illustration. A small catering and prepared-meals business keeps a register with 34 risks. Its highest-rated entry is “Cool room failure: likelihood 3, consequence 5, rating 15, owner: kitchen manager, action: maintain equipment”. It has been on the register for two years.
The owner and the kitchen team draw a bow-tie for the event “cool room loses temperature overnight”.
Causes and preventive barriers:
- Compressor failure: a quarterly service contract (working).
- Door left ajar at close: a door alarm (degraded: the battery had been removed because it was “too sensitive”).
- Power outage: none.
Consequences and mitigating barriers:
- Spoiled stock: a temperature sensor that sends a text message to the owner (working, but untested at night).
- Unable to fill next-day orders: none, beyond “ring around”.
- Food safety breach if spoiled product is used: a written disposal procedure (working, but staff on the early shift had not been trained).
Two findings stand out. First, the temperature sensor and its text alerts run through the same internet router as everything else, which loses power in an outage. One of the three listed causes would disable the main mitigating barrier at the same time. Second, there is no real plan for the most expensive consequence: missing a day’s orders for regular aged-care and childcare customers.
The business makes four changes, each with an owner and a cost:
- The door alarm battery is replaced and the alarm adjusted rather than disabled.
- The sensor is moved onto a small battery backup with a mobile data connection, so it still works during an outage.
- A neighbouring commercial kitchen agrees in writing to provide emergency cool room space, and the business keeps its contact details and access arrangements in the kitchen manual.
- Early-shift staff are trained on the disposal procedure.
It also adds a leading indicator. The service technician points out that the cool room’s recovery time after the door is opened is a good early sign of compressor wear. The trigger: if recovery takes more than twenty minutes on three days in a week, the technician is called before the next service visit.
The register entry now reads differently. Instead of “maintain equipment”, it shows four barriers with their status, a named person checking each one and the date it was last tested. At the next review, the question is not whether the rating should be 12 or 15, but whether every barrier is still working.
How this applies to a small Australian business
A small business does not need risk software or a long register to manage risk well. Practical steps:
- Keep the register short. Twenty well-written risks are more useful than a hundred vague ones.
- Write each risk as cause, event and consequence.
- Give each important risk an owner who can act, including an agreed amount they can spend without asking.
- Add a leading indicator and a trigger for the risks that matter most.
- Check that contingencies are real: that backup suppliers, spare equipment and emergency arrangements actually exist.
- Draw a bow-tie for the two or three events that could stop the business or hurt someone.
- Report barrier status, not just ratings.
- Look for shared dependencies across jobs, products and customers.
- Check legal duties separately. Work health and safety, food safety, environmental and other laws may require specific controls. Your state or territory regulator publishes guidance, and an adviser can help.
Signals worth watching
- Ratings that worsen over several reviews while no decision changes.
- Risks that have sat on the register for more than a year with the same action.
- Actions such as “monitor” or “follow procedures” with no trigger or barrier behind them.
- Owners who would need someone else’s approval to do anything.
- Contingencies nobody has tested.
- Several risks that depend on the same person, supplier or system.
Common mistakes
- Treating the register as the system. The register is a record; the system is the decisions it produces.
- Relying on ratings to decide what to do and how much to spend.
- Naming owners without giving them authority or resources.
- Using lagging measures only, so warnings arrive after the damage.
- Counting barriers without checking whether they are independent.
- Investing only in prevention and leaving nothing to limit harm if prevention fails.
- Closing a risk when it becomes an issue, and losing the lesson.
Frequently asked questions
How many risks should a small business register have? As many as the business can genuinely manage, which is often fewer than twenty. If a risk will never be discussed or acted on, it probably does not need a line.
How often should we review it? Match the review to how quickly each risk can change. A supplier failure may need a weekly signal; a lease expiry may need a yearly check. Triggers do much of the work between reviews.
Do we need software for bow-ties? No. A whiteboard or a sheet of paper is enough. What matters is having the people who do the work in the room.
What is the difference between a risk owner and an action owner? The risk owner is accountable for the overall exposure and decides whether it is acceptable. Action owners carry out particular responses. In a small business they are often the same person, which is fine as long as they have the authority to act.
Should we include opportunities? Yes, where they matter. The same structure works for favourable possibilities: what would cause them, how would you know they were emerging, and who would act.
Questions to ask
- What decision did our last risk review change?
- Which of our top risks could we describe as cause, event and consequence?
- Which risks have a leading indicator and an agreed trigger?
- Which contingencies have actually been tested?
- For our two or three most serious risks, which barriers are degraded or share a dependency?
- Can each risk owner act without waiting for permission?
Bringing it together
A risk register is useful as a common record, but its value depends on the system around it. Describe risks as cause, event and consequence so the description points to action. Give each important risk a leading indicator, a trigger and a response that is ready to use, and an owner who can act. For the few events that could seriously harm the business, draw a bow-tie, check which barriers are degraded and whether any of them share a weakness. Look across the business for risks that cluster around the same supplier, person or system. The aim is not a longer or more colourful list. It is a business that sees trouble earlier and responds while it still has options.
Source: KEVOS notes, drawing on teaching material on risk identification, triggers and contingency planning, the bow-tie method of barrier analysis and James Reason’s Swiss cheese model of accident causation. Examples in this article are illustrations. This article is general information, not legal or safety advice.