Skip to content
Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.
← Public templates

Compliance registers · Gixo Business

Risk Register & Heat Map Builder

Score inherent and residual risk, identify missing ownership and mitigation, and generate a 5×5 summary.

No accountNo AI callNothing storedDeterministic output
Illustrative preview of the Risk Register & Heat Map Builder output
Illustrative output preview. Your generated document reflects the fields you supply.

What is a risk register?

A risk register is the single list of the things that could stop a piece of work, scored so they can be ranked, each with a named owner and a stated mitigation. It exists so that every risk is either being managed by somebody or has been consciously accepted — not raised once in a meeting and lost.

A register is not a risk assessment. The assessment is the judgement you make about one hazard; the register is the live document that carries all of them, is reviewed on a date, and shows whether the mitigation actually moved the score. A row with no owner, or a high-scoring row with no mitigation, is unmanaged — which is why this builder flags those rows instead of quietly scoring them.

  • Risk — one sentence, in the form "X happens, causing Y".
  • Category — so related risks can be counted together.
  • Inherent likelihood and impact, 1-5 — the score before anything is done about it.
  • Owner — one named person, not a team.
  • Mitigation — what is actually being done, not what could be.
  • Residual likelihood and impact, 1-5 — the score expected once the mitigation is in place.
  • Review date — when the row is looked at again.

Risk register examples

Inherent 4 x 5 = 20 puts this row in the red band: likely, and severe if it lands. The mitigation does not change the impact — a missed cutover still delays the launch — so only the likelihood falls, to 2, and the residual is 10. That is the honest shape of most mitigations, and a register where residual impact drops with no explanation is usually wishful. The builder flags any row whose residual score is not lower than its inherent score, any row with no owner, and any row scoring 12 or more with no mitigation written down.

One risk, in the format the register accepts:

Integration vendor misses the API cutover date, delaying launch | Delivery | 4 | 5 | Priya Raman | Contract milestone at 60 days, with a weekly integration test from week 2 | 2 | 5 | 2026-10-01

The 5x5 risk matrix

Likelihood 1-5 multiplied by impact 1-5 gives 25 possible scores, and the register bands them from the inherent score: 15 and above red, 6 to 14 amber, 5 and below green. Each row reports its inherent score, its residual score and its band, and the summary counts how many rows sit in each — so the register answers "how exposed are we" without anyone eyeballing a grid.

Document inputs

Required gaps remain visible as [ ], so the downloaded handoff never silently hides unfinished work.

Header
Risk register
One row per line. Separate Risk · Category · Likelihood 1-5 · Impact 1-5 · Owner · Mitigation · Residual likelihood 1-5 · Residual impact 1-5 · Review date with | characters.

Need a different artifact?

Browse all 12 governed builders on the public template hub, or use the smaller checkers on the free tools hub.

Details

Risk Register & Heat Map Builder details

See the accepted inputs, generated sections, output formats, and important limits.
TopicDetailsWhat to know
Inputs4 fields across 2 groupsEvery field required by this template is shown before generation.
Required inputs4 required fieldsUnfilled required values remain visible instead of being silently invented.
Repeatable sections1 repeatable sectionsTemplates without a row field render each field once.
OutputsHTML, Markdown, embed snippet, and print-ready HTMLEvery output is generated from the same validated field values.
Do I need an account to use Risk Register & Heat Map Builder?

No. The builder runs without an account.

Does the builder invent missing information?

No. Required gaps remain visibly marked for review.

Is my document stored?

No. The public builder does not save the submitted field values.

Which formats can I download?

The public result supports HTML and Markdown downloads, an embed snippet, and print-to-PDF through the browser.

How do you score inherent vs residual risk?

Inherent is the score with nothing done about it: likelihood times impact, each rated 1 to 5. Residual is the score you expect once the mitigation named in that row is actually in place. Mitigations usually reduce likelihood; they reduce impact only when they change the consequence itself, such as a fallback supplier or insurance. A residual score that is not lower than its inherent score is flagged, because it means the mitigation is doing nothing.