How mature is your risk management?
Take the Free AssessmentTake Assessment

Risk Management

Risk Management Plan vs Risk Register: The Difference

Keith Ricketts-Clew-GRC

Keith Ricketts

August 2, 2026
Time to read: 9 minutes

Summarize this article with:

ClaudeChatGPTGoogle GeminiPerplexityGrok
2
Documents that do completely different jobs
4
Questions every risk in the register should answer
1
Connection that makes both worth keeping
Didn't have time to read - TL;DR
3 key takeaways
1
The plan is the rulebook; the register is the record. The plan describes how risk management works here. The register captures the specific risks you are managing right now.
2
One without the other does not work. A register with no plan is just a list. A plan with no live register is a policy statement with no operational reality.
3
The value is in the connection. What matters is not whether you have both documents, but whether each risk traces back to the objective it threatens.
If you have spent any time working through risk documentation, you have probably seen risk management plan and risk register used interchangeably, or worse, used as though one replaces the other. They do not. A risk management plan and a risk register are distinct documents that serve different purposes at different levels of the risk management system. Conflating them, or treating one as sufficient without the other, is one of the more common structural mistakes organisations make in the early stages of building a risk function.

The confusion is understandable. Both documents deal with risk. Both are associated with the risk function. Both tend to appear on the list of things a new risk leader is expected to produce or inherit. But the work they do in an organisation is fundamentally different, and understanding that difference is the prerequisite for making either of them genuinely useful.

This post sets out what each document is, where each one fits, and how they work together, or fail to, in practice.

What a risk management plan actually is

A risk management plan is a governance document. It describes how your organisation intends to identify, assess, treat, monitor, and report on risk. It is the framework document, the one that answers the question of how risk management works here, not what the current risks are.

Think of it as the rulebook. Before any risk is identified, assessed, or acted on, someone needs to have agreed how that will happen: what scale will be used to rate likelihood, who is responsible for owning a risk once it has been identified, what thresholds trigger escalation to the board, and how the function's work connects to the organisation's strategic objectives. The risk management plan is where those agreements are recorded.

In practical terms, a risk management plan typically covers:
  • The objectives and scope of the risk management function.
  • The risk appetite and tolerance thresholds the organisation has agreed.
  • The methodology used to identify and rate risks, including the scales applied.
  • Roles and responsibilities, covering who owns risks, who assesses controls, and who escalates.
  • The reporting and review cycle, including what goes to the board and when.
  • How risk management connects to strategic planning, project delivery, and operational decision-making.
A well-constructed risk management plan is not long. It is clear, specific to the organisation, and written so that a new risk leader, a senior manager in operations, or a board member can read it and understand what the function is designed to do and how it works. If yours runs to forty pages of policy language that nobody reads, it is probably doing more harm than good. Length signals effort; clarity signals thought.

The plan is also relatively stable. It does not change every quarter. You update it when the organisation's risk appetite shifts materially, when governance structures change, or when the methodology is revised following a review. For a full walk through of what goes into one and how to build it, see our guide on how to write a risk management plan.

What a risk register actually is

A risk register is an operational record. It captures the specific risks the organisation has identified, how each has been assessed, what controls are in place, and what actions are being taken to manage exposure. Where the plan describes the how, the register records the what: these are the risks, these are the controls, this is the current status.

In most organisations, a risk register contains some combination of:
  • Risk descriptions, including cause and consequence.
  • Inherent and residual ratings, typically expressed across likelihood and consequence scales.
  • Control descriptions and an assessment of their current effectiveness.
  • Risk owners, meaning the people accountable for managing each risk.
  • Actions underway, with owners and due dates.
  • Review dates and the history of how ratings have changed.
The register is live. Unlike the plan, it should be changing regularly, updated when the risk landscape shifts, when controls are tested and found wanting, when new threats emerge or existing ones are resolved. It is a working record of the organisation's current risk position, not a snapshot taken at a point in time and left to age.

That distinction matters in practice. A register that is updated once a quarter before the board pack goes out is not functioning as a management tool. It is functioning as a compliance artefact. The board receives a document that reflects the risk position as it existed three months ago, filtered through whatever time the risk team had available to update it. That is not risk management. It is risk reporting, and there is a meaningful difference between the two.
Risk management planRisk register
What it isA governance document. The framework for how risk is managed.An operational record. The live list of risks being managed.
Question it answersHow does risk management work here?What are the current risks, and what are we doing about them?
How often it changesRarely. A stable, standing document.Continually. A live working record.
ContainsAppetite, methodology, rating scales, ownership model, reporting cycle.Risks, ratings, controls, owners, actions, review dates.
RoleSets the rules.Applies the rules.

Where organisations go wrong

The most common failure is treating the register as the whole of risk management. The organisation builds a register, populates it with risks, rates them, and reports on it. Twelve months later, the register has grown considerably, the ratings have barely moved, and nobody can tell you with any confidence what the function has actually contributed to the organisation's performance or decision-making.

This happens because the register has been deployed without a clear framework behind it. There is no agreed risk appetite, so ratings are subjective and inconsistent across different parts of the organisation. There is no defined ownership model, so actions drift without consequence and overdue items accumulate without escalation. There is no methodology for assessing control effectiveness, so the controls column is populated with descriptions of what controls exist rather than any assessment of whether they are working. The register becomes a catalogue of risks rather than a tool for managing them.

The risk management plan exists to solve exactly these problems. Without it, the register has no authoritative basis for the decisions it represents. Ratings cannot be meaningfully compared. Ownership cannot be enforced. The function cannot demonstrate that its work is governed by consistent principles rather than individual judgement.

The second common failure is the opposite: the organisation has a detailed, well-structured risk management plan that exists largely as a policy document. It was written, approved, filed, and reviewed once a year at the same committee meeting. The register does not reflect the methodology described in the plan. The risk matrix in the plan is not the one being used. Risk owners listed in the plan have no idea they are listed there, because nobody told them. The two documents exist in parallel without connecting.

Both failures have the same root cause. The plan and the register were treated as separate products rather than two components of the same system.

How a risk management plan and risk register work together

Think of the plan and the register as operating at different levels of the same system. The plan sets the rules; the register is where the rules are applied.

The plan establishes what risk appetite means in this organisation, how risks are rated, who is accountable for managing them, and how the function reports. The register is where specific risks are identified, assessed, owned, and managed according to those rules. When both are working as intended, the register is a live expression of the framework the plan describes. Changes in the risk environment appear in the register. Ownership gaps surface as gaps in the register. Control failures show up as changes in residual ratings.

When both are working as intended, someone looking at any risk in the register should be able to answer four questions without leaving it: what are we trying to protect, what is the current level of exposure, what controls are we relying on, and what are we actively doing about the gaps? That chain from strategic objective to current confidence is what good risk management produces. The plan makes it possible. The register makes it visible.

In practice, this means the plan needs to be built with the register in mind. If the plan specifies a five-by-five risk matrix, the register needs to use it consistently. If the plan assigns risk ownership to a particular level of management, the register needs to reflect that. If the plan commits to quarterly reviews with monthly monitoring of high-rated risks, the register needs review dates and escalation flags that match. Every element of the plan should have a corresponding expression in how the register operates.

Do you need a risk management plan and a risk register?

Yes, if you are managing risk in any systematic way. No, if what you actually have is a list of risks that gets updated before governance meetings and then set aside.

A register without a plan behind it is a list. It describes risks but provides no framework for managing them consistently, no basis for comparing ratings across the organisation, and no mechanism for enforcing ownership or escalating inaction. It tells you what risks exist. It does not tell you what to do about them, or whether what is being done is adequate.

A plan without a live register is a policy statement with no operational reality. It describes an intention. It cannot tell you whether that intention is being carried out, whether controls are working, or whether the risk position is improving or deteriorating.

The question worth asking is not whether you have both documents, but whether the two are genuinely connected. Can you look at your risk register and see your organisation's risk appetite reflected in the ratings? Can the owner of a risk in the register point to the strategic objective that risk threatens? Can your board look at the register and understand, in clear terms, where assurance confidence is strongest and where it is weakest? Can anyone trace a line from a board-level concern through to the controls and actions that are managing it?

If the answer to any of those is no, the gap is usually not in the documents themselves. It is in the connection between them.

"The question worth asking is not whether you have both documents, but whether the two are genuinely connected."

What good looks like

In organisations where risk management is working well, the plan and the register are not separate documents managed by separate people on separate cycles. They form a connected system where the framework defined in the plan is consistently expressed in the register, and the register is actively used to inform decisions rather than to satisfy reporting obligations.

The plan defines risk appetite and methodology. The register applies them. Reporting draws from the register to give decision-makers a current view of exposure, control confidence, and action status, framed in terms of the strategic objectives the organisation is trying to protect. A board member who reads the risk report should be able to connect every item back to something they care about strategically, understand the current confidence in the controls managing it, and know what is being done where confidence is low.

The connection that matters

A risk register you cannot trace back to a strategic objective is a list of concerns, not a risk management tool.

That level of connectivity is what transforms risk management from a governance exercise into something that genuinely supports how the organisation makes decisions and manages performance. The two documents are the foundation. The connection between them is what makes them work.

Frequently asked questions

A risk management plan is a governance document that sets out how an organisation manages risk: its appetite, methodology, rating scales, ownership model, and reporting cycle. A risk register is an operational record of the specific risks identified, their ratings, the controls in place, and the actions underway. The plan describes how risk management works; the register records what is actually being managed. The plan is stable and changes rarely; the register is live and changes continually.

Yes, if you are managing risk systematically. A register without a plan is just a list, with no consistent basis for rating, ownership, or escalation. A plan without a live register is a policy statement with no operational reality. The two are designed to work as one system, and the value comes from the connection between them, not from having each document in isolation.

A risk assessment is the activity of identifying and evaluating risks at a point in time. A risk register is the ongoing record that captures the output of those assessments and tracks how each risk, its controls, and its actions change over time. Assessments feed the register; the register is where their results live and are maintained.

The risk function typically owns both documents, the plan as the framework it maintains and the register as the live record it curates. But individual risks in the register should each have a named owner accountable for managing that risk and its actions, and the plan should define that ownership model so accountability is clear rather than assumed.

Clew-Logo

Clew is built around exactly this connection, the Golden Thread that runs from strategic objectives to material risks, to the critical controls managing them, to the actions in train where gaps exist. The plan's framework and the register's operational reality live in the same platform, not in separate documents on separate cycles. Risk and assurance teams in construction, government, healthcare, infrastructure, mining, and transport use Clew to make that connection real.

Explore Clew's risk management software →
Keith Ricketts-Clew-GRC

Meet the author

Keith Ricketts

VP Of Marketing

25 years with global software vendors in Cyber Security, Risk and ERP. Blends strategic marketing, agility and a proven record of results.
Connect on LinkedIn

In this article

How mature is your risk management?

Take the free assessment and get a personalised report in minutes.
Take the assessment