A practical guide to risk management
Most business owners manage risk constantly without ever calling it that. You keep an eye on the customer who’s slow to pay. You worry about what happens if your best engineer leaves. You’ve got a rough idea of what would break if the systems went down on a Friday afternoon.
The problem is that when risk management lives entirely in your head, it’s inconsistent. You think about the risks that happen to be on your mind, not necessarily the ones that matter most. The point of a formal approach isn’t paperwork — it’s making sure the important risks don’t get crowded out by the loud ones.
This guide covers how to identify risks, keep a simple register, weigh likelihood against impact, decide what to do about each one, and keep the whole thing alive rather than filed.
Identifying what could go wrong
Start by getting risks out of people’s heads and onto a page. Ask the people doing the work — they know where things are fragile in a way the leadership team often doesn’t. To avoid staring at a blank sheet, walk through categories rather than trying to think of everything at once:
- Financial — customer concentration, late payment, cashflow gaps, cost increases.
- Operational — supplier failure, equipment breakdown, capacity limits.
- People — key-person dependency, recruitment, knowledge held by one person.
- Technology — system outage, data loss, cyber attack.
- Regulatory — obligations you might not be meeting, or rules that could change.
- Reputational — anything that would damage trust with customers.
Two habits improve this enormously. First, describe risks as events, not topics. “Cybersecurity” isn’t a risk; “a ransomware attack stops us trading for several days” is, and you can actually do something about it. Second, be honest. A register that only contains comfortable risks is worse than none, because it creates false confidence.
Building a simple risk register
A risk register is just a list of what could go wrong and what you’re doing about it. It does not need special software — a spreadsheet is fine, and often better, because people will actually open it. Each entry needs six columns and no more:
- The risk — described as an event, in plain language.
- Likelihood — how probable it is.
- Impact — how bad it would be.
- What we’re doing about it — the controls already in place or planned.
- Owner — the person accountable.
- Review date — when we look at this again.
Resist the urge to make it comprehensive. A register with fifteen real risks that people revisit beats one with a hundred that nobody reads. If yours has grown to the point where it’s exhausting, that’s a signal to prune, not to buy a bigger system.
Want a second opinion on the risks facing your business? We can introduce an independent specialist to review them with you.
Get StartedLikelihood versus impact
Once you’ve got a list, you need to work out where to spend your attention — you can’t treat everything equally, and pretending otherwise means treating nothing properly.
Score each risk on two axes. How likely is it? How much would it hurt? A simple low / medium / high on each is plenty; elaborate numerical scoring creates an illusion of precision without improving decisions. Combine the two and you get four broad groups:
- High likelihood, high impact — act now. These are the ones that keep you up at night, and rightly.
- Low likelihood, high impact — the ones businesses most often underrate. Rare doesn’t mean never, and “catastrophic” is worth planning for even at low odds.
- High likelihood, low impact — usually worth fixing simply because the nuisance adds up.
- Low likelihood, low impact — note it and move on.
The value here is less in the scores themselves than in the argument you have while assigning them. When two people rate the same risk very differently, you’ve found something worth discussing.
Mitigation and controls
For each risk that matters, you have four honest options, and it helps to name which one you’ve chosen:
- Reduce it — put controls in place that make it less likely or less damaging. Most risks land here.
- Transfer it — insurance, or a contract that places the risk with the party best placed to carry it.
- Avoid it — stop doing the thing that creates the risk. Sometimes the right answer, rarely the popular one.
- Accept it — decide the risk is tolerable and consciously live with it.
Accepting a risk deliberately is a perfectly legitimate decision and very different from ignoring one. The difference is that an accepted risk has been discussed, recorded, and can be revisited when circumstances change.
Be wary of controls that exist only on paper. A backup that’s never been restored isn’t a control — it’s a hope. This is where managed IT support earns its keep for a lot of businesses: tested backups, enforced access controls and monitored systems turn technology risks from vague worries into things that are genuinely handled.
Ownership
Every risk needs one named owner. Not a team, not “management” — a person, because shared ownership reliably becomes nobody’s.
The owner isn’t necessarily the person who does the mitigating work. They’re the person who notices if it isn’t getting done and says something. That distinction matters: ownership is about attention, not labour. It also needs to be someone with enough standing to actually make things happen — giving a risk to someone who can’t influence the outcome is just setting them up to fail.
Reviewing regularly
A risk register goes stale faster than almost any other document, because the business changes and the register doesn’t. A year-old register describes a business that no longer exists.
Build the review into something that already happens — a standing item on a monthly or quarterly leadership session works far better than a separate meeting nobody wants. Keep it brief and ask four questions:
- Has anything changed the likelihood or impact of what’s already listed?
- Are there new risks — from a new product, market, supplier or system?
- Have any risks genuinely gone away, so we can remove them?
- Did the actions we agreed last time actually happen?
That last question is where most registers quietly die, and it’s worth being blunt about it. A register that logs risks but never closes actions is a record of good intentions. Reviewing it as part of your wider governance routine keeps it honest, and means near misses feed back in while they’re still fresh.
Keeping it proportionate
Risk management shouldn’t consume the business it’s meant to protect. For most smaller firms, a short register, a few named owners, a quarterly half-hour and a willingness to be honest will do more than any amount of methodology.
How formal your approach needs to be depends heavily on your sector and any obligations you carry, and this guide is general information rather than legal or regulated advice. If you’d like an independent view of the risks in your business and whether your current approach is proportionate, get in touch. We’ll introduce a vetted compliance and governance specialist — we’re an introducer, not the adviser, so there’s no obligation and nothing for us to upsell.
FAQs
Common questions
Almost certainly not, at least to begin with. A spreadsheet with the risk, likelihood, impact, controls, owner and review date covers what most smaller businesses need. Software becomes useful when you have enough risks and enough people that a shared spreadsheet gets unwieldy — but plenty of businesses never reach that point.
Fewer than you'd think. A focused list that people genuinely revisit is far more valuable than an exhaustive one that nobody opens. If your register has grown so long that reviewing it feels like a chore, that's usually a sign to prune it down to the risks that would actually change a decision.
A risk is something that might happen; an issue is something that already has. Registers get muddled when the two are mixed together. If it's happened, it needs fixing now and belongs on an action list — the register is for what's still ahead of you.
Yes, as long as it's a decision rather than an oversight. Consciously accepting a risk — because mitigating it would cost more than the risk is worth — is a legitimate choice. What matters is that it was discussed, recorded, and gets revisited if circumstances change. That's very different from never having noticed it.
Related
Related services
Compliance & Governance
Health checks and risk reviews through an independent specialist introduction.
ExploreManaged IT Services
Backups, access controls and resilience that reduce your operational risk.
Explore Compliance & GovernanceHow to prepare for a compliance audit
What auditors look for, how to gather evidence, and the gaps that catch businesses out.
ReadReady when you are
Get a clear view of your risks
Tell us about your business and we’ll introduce an independent specialist to review your risks — free, and with no obligation.
Get Started