The confusion is understandable. Both documents deal with risk. Both are associated with the risk function. Both tend to appear on the list of things a new risk leader is expected to produce or inherit. But the work they do in an organisation is fundamentally different, and understanding that difference is the prerequisite for making either of them genuinely useful.
This post sets out what each document is, where each one fits, and how they work together, or fail to, in practice.
What a risk management plan actually is
Think of it as the rulebook. Before any risk is identified, assessed, or acted on, someone needs to have agreed how that will happen: what scale will be used to rate likelihood, who is responsible for owning a risk once it has been identified, what thresholds trigger escalation to the board, and how the function's work connects to the organisation's strategic objectives. The risk management plan is where those agreements are recorded.
In practical terms, a risk management plan typically covers:
- The objectives and scope of the risk management function.
- The risk appetite and tolerance thresholds the organisation has agreed.
- The methodology used to identify and rate risks, including the scales applied.
- Roles and responsibilities, covering who owns risks, who assesses controls, and who escalates.
- The reporting and review cycle, including what goes to the board and when.
- How risk management connects to strategic planning, project delivery, and operational decision-making.
The plan is also relatively stable. It does not change every quarter. You update it when the organisation's risk appetite shifts materially, when governance structures change, or when the methodology is revised following a review. For a full walk through of what goes into one and how to build it, see our guide on how to write a risk management plan.
What a risk register actually is
In most organisations, a risk register contains some combination of:
- Risk descriptions, including cause and consequence.
- Inherent and residual ratings, typically expressed across likelihood and consequence scales.
- Control descriptions and an assessment of their current effectiveness.
- Risk owners, meaning the people accountable for managing each risk.
- Actions underway, with owners and due dates.
- Review dates and the history of how ratings have changed.
That distinction matters in practice. A register that is updated once a quarter before the board pack goes out is not functioning as a management tool. It is functioning as a compliance artefact. The board receives a document that reflects the risk position as it existed three months ago, filtered through whatever time the risk team had available to update it. That is not risk management. It is risk reporting, and there is a meaningful difference between the two.
| Risk management plan | Risk register | |
|---|---|---|
| What it is | A governance document. The framework for how risk is managed. | An operational record. The live list of risks being managed. |
| Question it answers | How does risk management work here? | What are the current risks, and what are we doing about them? |
| How often it changes | Rarely. A stable, standing document. | Continually. A live working record. |
| Contains | Appetite, methodology, rating scales, ownership model, reporting cycle. | Risks, ratings, controls, owners, actions, review dates. |
| Role | Sets the rules. | Applies the rules. |
Where organisations go wrong
This happens because the register has been deployed without a clear framework behind it. There is no agreed risk appetite, so ratings are subjective and inconsistent across different parts of the organisation. There is no defined ownership model, so actions drift without consequence and overdue items accumulate without escalation. There is no methodology for assessing control effectiveness, so the controls column is populated with descriptions of what controls exist rather than any assessment of whether they are working. The register becomes a catalogue of risks rather than a tool for managing them.
The risk management plan exists to solve exactly these problems. Without it, the register has no authoritative basis for the decisions it represents. Ratings cannot be meaningfully compared. Ownership cannot be enforced. The function cannot demonstrate that its work is governed by consistent principles rather than individual judgement.
The second common failure is the opposite: the organisation has a detailed, well-structured risk management plan that exists largely as a policy document. It was written, approved, filed, and reviewed once a year at the same committee meeting. The register does not reflect the methodology described in the plan. The risk matrix in the plan is not the one being used. Risk owners listed in the plan have no idea they are listed there, because nobody told them. The two documents exist in parallel without connecting.
Both failures have the same root cause. The plan and the register were treated as separate products rather than two components of the same system.
How a risk management plan and risk register work together
The plan establishes what risk appetite means in this organisation, how risks are rated, who is accountable for managing them, and how the function reports. The register is where specific risks are identified, assessed, owned, and managed according to those rules. When both are working as intended, the register is a live expression of the framework the plan describes. Changes in the risk environment appear in the register. Ownership gaps surface as gaps in the register. Control failures show up as changes in residual ratings.
When both are working as intended, someone looking at any risk in the register should be able to answer four questions without leaving it: what are we trying to protect, what is the current level of exposure, what controls are we relying on, and what are we actively doing about the gaps? That chain from strategic objective to current confidence is what good risk management produces. The plan makes it possible. The register makes it visible.
In practice, this means the plan needs to be built with the register in mind. If the plan specifies a five-by-five risk matrix, the register needs to use it consistently. If the plan assigns risk ownership to a particular level of management, the register needs to reflect that. If the plan commits to quarterly reviews with monthly monitoring of high-rated risks, the register needs review dates and escalation flags that match. Every element of the plan should have a corresponding expression in how the register operates.
Do you need a risk management plan and a risk register?
A register without a plan behind it is a list. It describes risks but provides no framework for managing them consistently, no basis for comparing ratings across the organisation, and no mechanism for enforcing ownership or escalating inaction. It tells you what risks exist. It does not tell you what to do about them, or whether what is being done is adequate.
A plan without a live register is a policy statement with no operational reality. It describes an intention. It cannot tell you whether that intention is being carried out, whether controls are working, or whether the risk position is improving or deteriorating.
The question worth asking is not whether you have both documents, but whether the two are genuinely connected. Can you look at your risk register and see your organisation's risk appetite reflected in the ratings? Can the owner of a risk in the register point to the strategic objective that risk threatens? Can your board look at the register and understand, in clear terms, where assurance confidence is strongest and where it is weakest? Can anyone trace a line from a board-level concern through to the controls and actions that are managing it?
If the answer to any of those is no, the gap is usually not in the documents themselves. It is in the connection between them.
"The question worth asking is not whether you have both documents, but whether the two are genuinely connected."
What good looks like
The plan defines risk appetite and methodology. The register applies them. Reporting draws from the register to give decision-makers a current view of exposure, control confidence, and action status, framed in terms of the strategic objectives the organisation is trying to protect. A board member who reads the risk report should be able to connect every item back to something they care about strategically, understand the current confidence in the controls managing it, and know what is being done where confidence is low.
The connection that matters
A risk register you cannot trace back to a strategic objective is a list of concerns, not a risk management tool.
Frequently asked questions
What is the difference between a risk management plan and a risk register?
A risk management plan is a governance document that sets out how an organisation manages risk: its appetite, methodology, rating scales, ownership model, and reporting cycle. A risk register is an operational record of the specific risks identified, their ratings, the controls in place, and the actions underway. The plan describes how risk management works; the register records what is actually being managed. The plan is stable and changes rarely; the register is live and changes continually.
Do you need both a risk register and a risk management plan?
Yes, if you are managing risk systematically. A register without a plan is just a list, with no consistent basis for rating, ownership, or escalation. A plan without a live register is a policy statement with no operational reality. The two are designed to work as one system, and the value comes from the connection between them, not from having each document in isolation.
What is the difference between a risk register and a risk assessment?
A risk assessment is the activity of identifying and evaluating risks at a point in time. A risk register is the ongoing record that captures the output of those assessments and tracks how each risk, its controls, and its actions change over time. Assessments feed the register; the register is where their results live and are maintained.
Who is responsible for the risk register and the risk management plan?
The risk function typically owns both documents, the plan as the framework it maintains and the register as the live record it curates. But individual risks in the register should each have a named owner accountable for managing that risk and its actions, and the plan should define that ownership model so accountability is clear rather than assumed.
Clew is built around exactly this connection, the Golden Thread that runs from strategic objectives to material risks, to the critical controls managing them, to the actions in train where gaps exist. The plan's framework and the register's operational reality live in the same platform, not in separate documents on separate cycles. Risk and assurance teams in construction, government, healthcare, infrastructure, mining, and transport use Clew to make that connection real.
Explore Clew's risk management software →