InspectionReport Logo
InspectionReport
TemplatesChecklistsPricing
Built in Estonia
Sign InBuild a report
Build a report
Back to templates

Risk Register Template Free Download

Risk Register Template Free Download

Free Risk Register Template — Download, Customize, and Use Today

Short answer: A risk register is a document that lists identified risks, their severity, and the actions you'll take to manage them. You can download a free template below — no email, no signup, no gated content. Just the template and a clear guide on using it, based on ISO 31000:2018 and HSE guidance.

Every project and workplace faces risks — from slips on a construction site to data breaches in an office. The difference between companies that handle those risks well and those that don't often comes down to one thing: having a proper risk register. It doesn't need to be fancy or expensive. A simple spreadsheet or a well-structured template does the job, as long as it captures the right information.

This guide gives you a free, ready-to-use risk register template, shows you exactly how to fill it out, and explains what regulations like ISO 31000 and HSE guidance say you should include.

What Is a Risk Register?

A risk register (sometimes called a risk log) is a document that tracks every identified risk affecting a project, operation, or organization. It's the single source of truth for your risk management efforts.

At its simplest, a risk register answers five questions:

  • What could go wrong?
  • How bad would it be?
  • How likely is it?
  • What are we doing about it?
  • Who's responsible?

The UK Health and Safety Executive (HSE) publishes free risk assessment templates that break this down further. According to their guidance, a proper record should capture: who might be harmed and how, what you're already doing to control the risks, what further action you need to take, who needs to carry out the action, and when the action is needed by. The HSE provides their template in both Word (.docx) and Open Document (.odt) formats on their website.

For organizations looking for a structured framework, ISO 31000:2018 is the international standard for risk management. It was published in February 2018 (Edition 2) and was last reviewed and confirmed in 2023 — so it's the current, active standard. ISO 31000 doesn't prescribe a specific template format, but it sets out principles and a process that any good risk register should follow: identifying, analyzing, evaluating, treating, monitoring, and communicating risks.

What to Include in a Risk Register Template

A good risk register template balances completeness with usability. You don't need twenty columns of data if nobody fills them in. Here's what the most effective templates include, based on common industry practice and ISO 31000 principles:

Core Fields

Field Purpose
Risk ID Unique identifier (e.g., R-001, R-002) for tracking
Risk Description What the risk is, in plain language
Risk Category Type — safety, financial, operational, reputational, compliance
Likelihood Probability rating (e.g., 1-5 or Rare-Likely-Almost Certain)
Impact Severity rating (e.g., 1-5 or Minor-Moderate-Catastrophic)
Risk Score Likelihood × Impact (the calculated risk level)
Existing Controls What you're already doing to manage this risk
Further Actions Additional steps needed
Owner Person responsible for managing this risk
Status Open, in progress, monitored, closed
Target Date When the action needs to be completed

Optional Fields for Advanced Registers

  • Risk trigger — what event or condition would activate this risk
  • Contingency plan — what you'll do if the risk materializes
  • Residual risk score — the score after controls are applied
  • Review date — when to reassess this risk
  • Linked risks — risks that are related or interdependent

ISO 31000 and the Risk Management Process

ISO 31000:2018 describes risk management as a cycle, not a one-time task. It breaks down into these steps:

  1. Establish the context — Understand the environment your organization operates in. What's the scope of your risk management effort? Who are the stakeholders?
  2. Risk identification — Find, recognize, and describe risks. Use techniques like brainstorming, checklists, SWOT analysis, or incident history.
  3. Risk analysis — Understand the nature and level of each risk. This is where you assign likelihood and impact ratings.
  4. Risk evaluation — Compare analysis results against your risk criteria. Decide which risks need treatment and which are acceptable.
  5. Risk treatment — Select and implement options to modify risks. Common options: avoid, remove, reduce, share, or accept the risk.
  6. Monitoring and review — Track risks and the effectiveness of treatments. Update the register as things change.
  7. Communication and consultation — Keep stakeholders informed throughout the process.

Your risk register is the document that lives at the center of this cycle. Every step feeds into it or draws from it.

Common Risk Register Mistakes (and How to Avoid Them)

Risk registers fail not because of the format, but because of how they're used. Here are the most common pitfalls:

1. Creating it once and never updating it. A risk register is a living document. If you build it at the start of a project and never touch it again, it becomes a historical artifact, not a management tool. Set regular review intervals — monthly for active projects, quarterly for operations.

2. Writing vague risk descriptions. "Safety issue" tells nobody anything useful. "Worker may fall from scaffolding over 2 meters when accessing the upper floor during roof repairs" — that's a useful description. Be specific about the hazard, who's exposed, and under what circumstances.

3. Confusing likelihood with impact. A broken paperclip has minimal impact no matter how likely it is. A catastrophic structural failure is rare but devastating. Rate them separately before calculating a combined score, or you'll end up with misleading priorities.

4. Listing risks but assigning no owners. If nobody is named as responsible, the risk falls through the cracks. Every entry needs a named owner — not a team, not a department, a person.

5. Over-complicating the template. Twenty columns and a 5×5 matrix with color coding might look thorough, but if your team dreads filling it in, it won't work. Start simple. Add complexity as you need it.

How to Use a Risk Register Template: Step by Step

Here's how to fill out a risk register for a real scenario — a construction company managing a building renovation project.

Step 1: Set up your register. Open the template. Fill in the project name, date, and who's maintaining the register. These details matter for audit trails.

Step 2: Identify risks with your team. Gather the project manager, site supervisor, and safety officer. Walk through the site together or review the project plan. List every risk you can think of. Don't filter yet — capture everything and prioritize later. Use past incident reports as a starting point.

Step 3: Assign categories. Group risks into categories: safety (slips, trips, falls from height), operational (equipment failure, material delays), financial (budget overruns, supplier insolvency), and compliance (permit lapses, regulatory changes).

Step 4: Rate likelihood and impact. Use a simple scale: 1 (rare/minor) to 5 (almost certain/catastrophic). Multiply them for a risk score. A risk scoring 15 or higher needs immediate action. Risks below 6 may only need monitoring.

Step 5: Document existing controls. What's already in place? Guardrails, training, PPE, warning signs, permits? Be honest — if there are no controls, say so. That's valuable information for the next step.

Step 6: Plan further actions. For each risk above your threshold, decide on additional controls. Assign an owner and a deadline.

Step 7: Review and update. Set a calendar reminder. Go back through the register monthly. Close risks that no longer apply, add new ones, and update scores as controls improve.

InspectionReport.app for Risk Register Management

You don't need expensive enterprise software to manage your risk register well. InspectionReport.app is a mobile-first inspection management platform that works for construction, safety, and quality teams.

Here's how it helps with risk register management:

  • Digital checklists — Turn your risk register template into a reusable digital form. Fill it out on site from a phone or tablet, even without internet.
  • Photo capture — Document hazards and controls with photos, annotated directly during inspections.
  • Real-time collaboration — Your whole team sees updates immediately. No more emailing spreadsheets around.
  • Report generation — Export completed risk registers as PDF, CSV, or Excel for sharing with stakeholders or regulators.
  • Signature capture — Get sign-off from responsible owners right in the app.
  • GPS tagging — Link risks to specific locations on site.
  • Audit trail — Every change to a risk entry is tracked and versioned.

Build and preview free. Export a finished PDF or Word report for €9.95, or go Unlimited at €29/month. Taxes included worldwide. The report builder — which lets you create custom templates — unlocks at €9.95.

The key difference between us and competitors like SafetyCulture: you can use the risk register template right now without creating an account or giving us your email. The template is free, it works, and it's yours.

FAQ

What's the difference between a risk register and a risk assessment?

A risk assessment is the process of identifying hazards and evaluating risks. A risk register is the document that records the results. You do the assessment, then record the outcomes in the register. The register also tracks ongoing actions, which a one-off assessment doesn't.

Does OSHA require a risk register?

OSHA (the US Occupational Safety and Health Administration) requires employers to conduct hazard assessments under standards like 29 CFR 1910 (General Industry) and 29 CFR 1926 (Construction). While OSHA doesn't mandate a specific risk register format, maintaining a documented record of identified hazards, controls, and corrective actions is considered best practice and helps demonstrate compliance during inspections.

Is ISO 31000 certification possible?

No. ISO 31000 is a guideline standard, not a certifiable one. You can be certified against ISO 9001 (quality management) or ISO 45001 (occupational health and safety), but ISO 31000 provides principles and a framework — it's meant to be adapted, not audited against.

Can I use a spreadsheet as a risk register?

Yes. Many organizations use Excel or Google Sheets for their risk register, especially when they're starting out. A well-structured spreadsheet with the fields listed above works fine. The main risk (pun intended) is version control — make sure only one person can edit at a time and save backups regularly.


Internal links to consider:

  • Free Inspection Checklist Templates
  • Construction Site Safety Inspection Guide
  • Digital Inspection Report Software

Automate this Template

Upload inspection photos, add notes, and AI drafts a professional report. Preview free.

Build from this templateBuild and preview free. Export once for €9.95.

Free template download

Blank PDF and editable Word files. No email required.

Download PDFDownload Word

Related templates

Manual Handling Risk AssessmentRisk Assessment Matrix TemplateRisk Assessment TemplateConfined Space Entry Permit ChecklistFall Protection Daily ChecklistPPE Inspection & Compliance Checklist
InspectionReport

AI-assisted inspection reporting tools for working inspectors.

Product

  • All Templates
  • Safety Checklists
  • Hazard Identifier
  • Pricing
  • Compare
  • SafetyCulture alternative

Popular

  • Forklift Inspection
  • MEWP Checklist
  • Fire Safety
  • Scaffolding

Resources

  • Safety Blog
  • Inspection report software
  • Daily Safety Guides
  • OSHA Compliance
  • Inspection Report App

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Security

© 2026 InspectionReport by Estads OÜ.