Risk Register
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
A structured, maintained log of identified quality or business risks, each with its assessed severity, probability, and detectability, the mitigation actions assigned, an accountable owner, and a current status — used to track and prioritize risk-management activity across a site, program, or product lifecycle.
A risk register is the ongoing tracking artifact that sits alongside individual risk-assessment tools such as FMEA: where a single risk assessment evaluates one process or change in depth, the register aggregates outputs across many assessments so leadership can see the site’s or program’s overall risk landscape in one place.
Entries typically include a risk description, the source assessment that identified it, a risk score or ranking, the mitigation or control action, an owner, a target closure date, and current status — open, mitigated, or accepted with rationale.
A well-maintained risk register is a common evidence source at management review and during inspections, because it demonstrates that quality risk management is an active, living process rather than a one-time exercise performed only when a specific decision required it.
- —Aggregates outputs from individual risk assessments (e.g. FMEA) into one tracked view
- —Each entry has severity/probability, a mitigation action, an owner, and a status
- —Distinct from a single risk assessment — it is the ongoing tracking mechanism
- —A common evidence source at management review and during inspections
ICH Q9(R1) Quality Risk Management; ISO 31000:2018 Risk Management
Frequently asked questions
What is Risk Register?
A structured, maintained log of identified quality or business risks, each with its assessed severity, probability, and detectability, the mitigation actions assigned, an accountable owner, and a current status — used to track and prioritize risk-management activity across a site, program, or product lifecycle.
Which regulations cover Risk Register?
ICH Q9(R1) Quality Risk Management; ISO 31000:2018 Risk Management