Night Mode LabsBlue Book
Examples

Example Risk Register

Use this example to calibrate risk language. Replace the example entries with evidence from the client environment.

Example entries

RiskImpactOwnerNext step
Critical services have no tested rollback pathFailed deployments may extend customer impactEngineering leadDocument current process and add rollback workflow
Production secrets are manually rotatedCredential leaks or outages are harder to containSecurity partnerInventory secrets and move pilot service to approved store
Alerts page on infrastructure symptoms onlyResponders may miss user-impacting failuresSRE leadDefine SLO burn alerts for critical workflow
Untagged cloud spend is above targetTeams cannot own or reduce cost driversFinance partnerEnforce required tags on new resources
Runbooks are stale for critical servicesIncident recovery depends on tribal knowledgeService ownersExercise and update top five runbooks

Risk quality checks

A good risk entry:

  • Describes consequence, not just condition.
  • Names the affected system or workflow.
  • Links to evidence.
  • Has an owner.
  • Has a next step.
  • Has a review date or decision needed.

Watchouts

  • Do not list every inconvenience as a risk.
  • Do not accept risks silently through inaction.
  • Do not leave severe risks without escalation.

On this page