The RoadmapPlanningRisk Management and Contingency Planning

Using a Risk Register: How-To Guide

A practical, in-depth guide to creating and using a risk register for UK small businesses—why it matters, how to set one up, what to include, and how to keep it effective.

7 minute read
Planning — Risk Management and Contingency Planning
✓ Verified against GOV.UK
Sarah Mitchell
Written by Sarah Mitchell
Editor-in-Chief · GuideToBusiness

Every UK small business faces risks—some obvious, others lurking in the background. A risk register isn’t just for big corporates; it’s a practical, vital tool that helps you spot, track, and manage threats before they become big (and expensive) problems. This guide walks you through exactly how to create, maintain, and use a risk register in your business, with real-world examples, UK-specific advice, and step-by-step instructions you won’t find anywhere else.

What is a Risk Register and Why Does It Matter for UK SMEs?

A risk register is a structured document that identifies, assesses, and tracks all the main risks facing your business. For UK small businesses, it’s more than a compliance exercise—it’s your early warning system, helping you manage everything from cash flow squeezes to data breaches, and even the impact of new government regulations. Having a risk register means you’re not just reacting to problems, but anticipating and preparing for them.

Many small business owners believe risk registers are only for large organisations or regulated industries, but that’s a dangerous misconception. Even the smallest business faces risks that could threaten survival, from a key supplier going bust to a cyberattack or a sudden change in employment law. The UK regulatory environment is constantly shifting, and the business landscape is volatile—COVID-19, Brexit, supply chain issues, and economic downturns have all shown how quickly risks can escalate. A risk register gives you a framework to stay ahead.

Creating a risk register also helps demonstrate to lenders, insurers, investors, and even clients that your business is well-managed and resilient. It’s a key part of contingency planning required by many insurers and is increasingly expected by banks (especially for loans or grants, such as those from the British Business Bank). The Federation of Small Businesses and the UK Government both recommend risk registers as best practice for all SMEs.

What counts as a 'risk'?

A risk is any event or circumstance—internal or external—that could harm your business's objectives, reputation, finances, operations, or compliance status. It doesn’t have to be likely to happen, just possible and with some impact.

Core Elements of an Effective Risk Register

A robust risk register isn’t just a list of worries. It’s a structured table with clear, actionable fields. At a minimum, every risk register for a UK small business should include: a unique risk ID, a description of the risk, the likelihood of occurrence, the potential impact, mitigating actions, a risk owner, current status, and review dates. Some add extra columns like 'risk category', 'trigger events', or 'financial exposure' for more detail.

The process starts with identifying risks specific to your business sector and operations. For example, a retailer might list supply chain disruption, while a digital agency would include data loss or GDPR breaches. You then estimate the likelihood (e.g., rare, possible, likely) and impact (minor, moderate, major, catastrophic). Assigning a risk owner is vital—they’re responsible for monitoring and managing that risk.

Mitigating actions are what you’ll do to reduce the risk or its consequences. For UK SMEs, this could include diversifying suppliers, improving cybersecurity, taking out relevant insurance, or updating employee contracts in line with new employment law. A good register will also show the current status (open, closed, escalating, etc.) and when each risk was last reviewed. This keeps the register fresh and actionable, not a forgotten spreadsheet.

FieldDescriptionUK SME Example
Risk IDUnique identifier for trackingR001
Risk DescriptionBrief but specific summarySupplier goes out of business
LikelihoodChance of occurrence (e.g., Low/Medium/High or 1-5 scale)Medium
ImpactPotential effect on business (Low/Medium/High or £ value)High – could halt operations
MitigationAction(s) to reduce risk or impactSource backup supplier
Risk OwnerPerson responsible for managing this riskOperations Manager
StatusCurrent state (Open, Closed, Escalating)Open
Review DateNext scheduled review01/07/2024

How to Build Your Risk Register: A Step-by-Step UK Guide

Building a useful risk register is not a one-off task—it’s an ongoing process. The initial setup takes some thought, but it pays off by making your business much more resilient. Here’s how to create a risk register tailored to your UK small business, whether you’re a limited company, partnership, or sole trader.

Start by gathering your team (even if that’s just you and a trusted adviser) to brainstorm every possible risk that could affect your business. Don’t censor yourself at this stage—think about financial, legal, operational, reputational, technological, environmental, and regulatory risks. Use recent news, sector guidance from the FSB, and HMRC/ICO/Health and Safety Executive updates for inspiration.

Once you’ve listed all potential risks, prioritise them. Not all risks are equal—some are highly unlikely but catastrophic, others are common but minor. Assign each risk a likelihood and impact rating, then decide on mitigation strategies. Document everything in your risk register template (Excel, Google Sheets, or dedicated software all work—what matters is that it’s accessible and updated regularly).

Creating and Managing a Risk Register for Your SME

1
Identify risks
Brainstorm all possible risks relevant to your business—use input from staff, sector bodies, recent incidents, and regulatory updates. Capture everything, even if it seems unlikely.
2
Describe each risk
Write a clear, specific description for each risk—avoid vague phrases like 'IT issues' and instead say 'Loss of customer data due to ransomware'.
3
Assess likelihood and impact
Score each risk for likelihood and impact, using a simple scale (e.g., 1-5 or Low/Medium/High). Be honest—don’t underplay unpleasant risks.
4
Identify mitigation actions
For every risk, list what you are doing (or could do) to reduce the chance or impact. This could be training, insurance, process changes, or technical solutions.
5
Assign owners and set review dates
Allocate each risk to a responsible person (risk owner) and specify when it will next be reviewed. Schedule regular reviews to keep the register live and useful.

UK-Specific Risks Every Small Business Should Consider

Some risks are unique to the UK business environment. For example, compliance with GDPR is non-negotiable—breaches mean heavy fines from the Information Commissioner’s Office. Late payment is a chronic issue: according to the FSB, over 50,000 UK SMEs close each year due to cash flow problems caused by slow-paying customers. Employment law changes (such as minimum wage increases and IR35 reforms) can catch businesses out, especially if you use contractors or have part-time staff. Employment law changes can catch businesses out, especially if you use contractors or have part-time staff.

Brexit has introduced new customs rules and tariffs, impacting businesses that import or export. If you trade internationally, currency fluctuations are a real risk—sterling’s value changes can have a big impact on costs and margins. Cybersecurity is another growing threat: the 2023 Cyber Security Breaches Survey found 32% of UK SMEs suffered a cyberattack in the previous 12 months, with phishing and ransomware the most common.

Other UK-specific risks include changes in VAT thresholds (£85,000 as of 2026), IR35 compliance for contractors, making tax digital, and sector-specific regulation (such as food safety for hospitality, or the Construction (Design and Management) Regulations for building firms). Environmental risks—like flooding or heatwaves—are also increasing, with the Environment Agency warning that 1 in 6 UK properties are at risk of flooding.

  • GDPR/data protection breaches (ICO enforcement and fines)
  • Late payment from UK clients/large suppliers
  • Employment law changes (minimum wage, sick pay, IR35)
  • Brexit-related customs, tariffs, and supply chain disruption
  • Cyberattacks and ransomware (ICO reporting duties)
  • VAT threshold changes and Making Tax Digital requirements
Late Payment Reality

FSB research (2023) shows that 1 in 3 UK small businesses have faced serious cash flow issues due to late payments, costing the sector an estimated £23.4 billion annually.

Prioritising and Scoring Risks: The Right Approach for UK SMEs

Not all risks are created equal. In the UK, regulatory bodies and insurers often expect you to use a simple but robust scoring system—usually a 1-5 scale for both likelihood and impact. Multiply the two to get a risk rating (e.g., Likelihood 4 x Impact 3 = Risk Score 12). This helps you focus on the risks that matter most, not just the ones that feel urgent.

For example, a GDPR breach might be low likelihood but catastrophic impact (high fine, reputational damage), while a staff sickness is more likely but lower impact. UK insurers and banks often ask to see your top 5-10 risks and what you’re doing about them. Colour-coded 'heat maps' are a handy way to visualise this—risks in the red zone need urgent attention, while greens are lower priority but still tracked.

It’s important to revisit your scoring regularly. The UK business environment changes fast—new legislation, cyber threats, or economic shocks can shift a risk from low to high overnight. Make it a habit to review your register monthly or quarterly, and after any big change (like a new contract, product launch, or regulation).

LikelihoodImpactScore (L x I)Priority Level
5 (Very Likely)5 (Catastrophic)25Critical – Immediate action
3 (Possible)4 (Major)12High – Monitor closely
2 (Unlikely)3 (Moderate)6Medium – Review regularly
1 (Rare)2 (Minor)2Low – Monitor/accept
Keep it simple

Don’t overcomplicate your scoring system. Use a 1-5 scale for each risk, and keep definitions clear—share them with your team so everyone is consistent.

Maintaining and Reviewing Your Risk Register

A risk register is only valuable if it’s kept up to date. Many UK businesses create one for a funding application or insurance renewal, then let it gather digital dust. That’s a missed opportunity and a compliance risk in itself. Best practice is to review your register regularly—at least quarterly, but monthly is better, especially during times of rapid change (like a new product launch or major regulatory update).

Assign clear responsibility for maintaining the register. This might be your office manager, operations lead, or even you as the business owner. Set calendar reminders and make the review part of your regular management meetings. This ensures that risks are actively managed, not just recorded. Update mitigation actions, risk scores, and statuses—close risks that are no longer relevant and add new ones as they emerge.

Regular reviews also help you spot patterns—recurring issues may signal a deeper problem in your processes or supply chain. Document changes and decisions: if you downgrade a risk, record why. This audit trail is valuable for insurers, lenders, and even the HMRC or HSE if you ever face an investigation.

  • Schedule regular risk register reviews (monthly/quarterly)
  • Update for new regulations, contracts, or incidents
  • Close risks only when fully resolved
  • Keep an audit trail of changes and decisions
  • Share updates with relevant staff/owners
Don’t let your register stagnate

A risk register that’s not updated is worse than useless—it creates false confidence. Review it regularly and make it a living document.

Making the Risk Register Work: Embedding Risk Management in Daily Operations

A risk register shouldn’t live in a drawer or a forgotten spreadsheet. For UK small businesses, the real value comes from embedding risk awareness into daily operations. This means talking about key risks at staff meetings, updating processes when new threats emerge, and linking risks to your business decisions. For example, if 'late payment' is a top risk, update your invoicing and credit control policy, and train staff to spot warning signs.

Use your risk register to inform insurance decisions—if your risk of stock theft is high, check your cover limits. If GDPR is a risk, ensure all staff are trained in data protection and incident reporting. Make risk management part of your onboarding process and regular training, especially for compliance-heavy areas like health and safety, or financial controls.

Many UK SMEs find it useful to create a simple dashboard or summary report from the register—this can be shared with your board, investors, or bank manager. It demonstrates professionalism, and in some sectors (like construction, healthcare, or financial services) it’s increasingly expected. Remember, risk management is an ongoing habit, not a one-off project.

  • Discuss top risks at management or team meetings
  • Link key risks to specific business processes and policies
  • Use the register to support insurance and lender discussions
  • Train staff regularly on their role in managing risks
  • Create a summary dashboard for quick updates

Practical Examples: Sample Risks and Mitigations for UK SMEs

To make this concrete, here are real-world examples of typical risks UK small businesses face—and practical mitigation strategies. Use these as inspiration, but tailor your register to your own sector and circumstances. HMRC, the ICO, and the HSE all publish examples relevant to different industries—check their guidance for sector-specific risks.

For example, a small manufacturer might list 'supplier insolvency' as a risk. Mitigation could include identifying alternative suppliers, negotiating longer payment terms, and regularly checking supplier credit ratings. A digital agency will have 'cybersecurity breach'—mitigations might include staff training, strong password policies, multi-factor authentication, and regular software updates.

In hospitality, 'food safety incident' would be high-risk—mitigations would be staff food hygiene training, regular audits, and strict supplier controls. For a consultancy, 'loss of key client' could be managed by diversifying the client base and maintaining a healthy sales pipeline. The important thing is to be specific—not just about the risk, but about what you’re actually doing to reduce it.

Risk DescriptionSector ExampleMitigation Action
Supplier insolvencyManufacturingDiversify suppliers; monitor credit ratings
GDPR/data breachDigital agencyStaff training; MFA; secure backups
Late paymentAll sectorsStrict credit control; invoice automation
Flood damageRetailerFlood insurance; premises risk assessment
Loss of key staffConsultancySuccession planning; cross-training

Common Mistakes and How to Avoid Them

Even well-intentioned UK small business owners fall into traps with risk registers. The most common mistake is making it a tick-box exercise—creating a register for a funding application, then never looking at it again. This means risks go unmanaged and new threats aren’t spotted. Another is being too vague: risks like 'IT problems' or 'staff issues' aren’t actionable. Be specific about what could happen, and what the impact would be.

Many businesses also ignore 'soft' risks—like reputational damage from a poor online review, or legal claims from misclassifying a contractor under IR35. Others overestimate their ability to absorb shocks, assuming that insurance will cover everything (it won’t—most policies have exclusions, excesses, and conditions).

Finally, failing to assign ownership means nobody is responsible for managing or monitoring the risk. This leads to drift and inaction. Assign a clear owner for each risk and review regularly—this is especially important for compliance risks (like GDPR, health and safety, or tax changes), where fines can be severe.

  • Not updating the register regularly
  • Being vague—use specific, actionable descriptions
  • Ignoring compliance and reputational risks
  • Relying solely on insurance as mitigation
  • Failing to assign risk owners
  • Not reviewing after major changes (e.g., new contracts, legislation)
Don’t ignore 'low likelihood, high impact' risks

Events like fire, flood, or data breach may seem unlikely, but their impact is catastrophic. Include and actively manage them in your register.

Choosing and Using Tools for Your Risk Register

You don’t need expensive software to run an effective risk register. Most UK SMEs use Excel, Google Sheets, or similar spreadsheet tools—they’re flexible, easy to update, and can be shared with your team. Templates are available from the FSB, ACAS, and sector bodies. For more complex needs (e.g., regulated sectors, multi-site operations), software like Risk Register+, Resolver, or even project management tools like Trello and Monday.com can help.

What matters most is that your risk register is easy to access, update, and review. Avoid overcomplicating things—start simple, and add complexity only if you outgrow your first system. Make sure your tool allows for version control and audit trails, especially if you need to demonstrate to insurers, auditors, or regulators that you’re managing risks actively.

If you handle sensitive data or financial information, ensure your risk register is stored securely—use strong passwords, access controls, and regular backups. This is especially important for GDPR compliance, as a data breach of your risk register itself could be reportable to the ICO.

Key Takeaways
  • A risk register is essential for UK SMEs. It helps you identify, prioritise, and manage business threats before they escalate.
  • Include core elements for each risk. Use clear fields: description, likelihood, impact, mitigation, owner, and review date—tailored to UK business realities.
  • Prioritise using a simple scoring system. Multiply likelihood and impact, and focus attention on risks in the 'red zone'.
  • Review and update regularly. Risk registers are living documents—quarterly reviews are a minimum, monthly is best.
  • Make risk management part of daily operations. Embed risk thinking into meetings, processes, and staff training for real impact.
  • Tailor your register to UK-specific threats. GDPR, late payment, employment law, Brexit, and cyber risks are all critical for UK SMEs.
  • Assign clear ownership for every risk. Accountability ensures risks don’t fall through the cracks.
  • Avoid common mistakes. Don’t let your register stagnate, and never treat it as a one-off exercise—its value is in ongoing, active use.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.