Quality Systems

Risk Register

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

A structured, maintained log of identified quality or business risks, each with its assessed severity, probability, and detectability, the mitigation actions assigned, an accountable owner, and a current status — used to track and prioritize risk-management activity across a site, program, or product lifecycle.

A risk register is the ongoing tracking artifact that sits alongside individual risk-assessment tools such as FMEA: where a single risk assessment evaluates one process or change in depth, the register aggregates outputs across many assessments so leadership can see the site’s or program’s overall risk landscape in one place.

Entries typically include a risk description, the source assessment that identified it, a risk score or ranking, the mitigation or control action, an owner, a target closure date, and current status — open, mitigated, or accepted with rationale.

A well-maintained risk register is a common evidence source at management review and during inspections, because it demonstrates that quality risk management is an active, living process rather than a one-time exercise performed only when a specific decision required it.

KEY POINTS
  • Aggregates outputs from individual risk assessments (e.g. FMEA) into one tracked view
  • Each entry has severity/probability, a mitigation action, an owner, and a status
  • Distinct from a single risk assessment — it is the ongoing tracking mechanism
  • A common evidence source at management review and during inspections
REGULATORY BASIS

ICH Q9(R1) Quality Risk Management; ISO 31000:2018 Risk Management

Frequently asked questions

What is Risk Register?

A structured, maintained log of identified quality or business risks, each with its assessed severity, probability, and detectability, the mitigation actions assigned, an accountable owner, and a current status — used to track and prioritize risk-management activity across a site, program, or product lifecycle.

Which regulations cover Risk Register?

ICH Q9(R1) Quality Risk Management; ISO 31000:2018 Risk Management