← Blog

Why your risk register is lying to you

Your risk register records what you typed, not what your evidence does. Here is why the heat map and the self-scored residual survive — and what an honest, evidence-backed register looks like instead.

The risk register is the most trusted document in the building, and most of it is fiction.

Not malicious fiction. Nobody sat down to deceive the board. The register lies the way a weather forecast from last month lies — it was a reasonable account of how someone felt about the world on the day they typed it, and it has been quietly diverging from reality ever since. The dangerous part is that it does not look like an opinion. It looks like a measurement. Rows, scores, a colour. The form of the thing borrows all the authority of evidence while carrying none of the obligation.

The register records assertions, not evidence

Open a typical register and read what is actually in each cell. A likelihood somebody chose. An impact somebody chose. A residual score somebody chose after asserting that a control they also described is working. Every number on the page is a self-report, and the document treats the self-report as the finding.

This is why a register is so hard to argue with. It is unfalsifiable by construction. There is no evidence attached that could turn out to be stale, no dependency that could turn out to be unowned, no assumption that could turn out to be wrong — because the register never claimed any of those things. It only claimed that, in someone's judgement, the residual was medium. You cannot disprove a feeling.

The heat map is worse than no map

The coloured grid deserves its own paragraph, because it is the part everyone trusts most and defends least.

In 2008 Tony Cox published What's Wrong with Risk Matrices? and demonstrated, formally, that the matrix can rank a quantitatively smaller risk above a larger one, that its categories compress wildly different exposures into the same square, and that — under the conditions he identifies — its rankings can be worse than random. Douglas Hubbard, in The Failure of Risk Management, made the companion point about the scores feeding the grid: ordinal scales — your 1-to-5s — add measurable noise, manufacture an illusion of communication between people who quietly mean different things by "likely", and carry no objective evidence that they improve on the unaided guess they were meant to discipline — while introducing error of their own.

The FAIR community makes the same case from the other side: risk is a measurable quantity — a distribution of probable loss — and the moment you are willing to express it that way, the coloured grid has nothing left to contribute. A heat map is not a simpler version of the analysis. It is what you reach for when you have declined to do one.

A method that produces a confident colour from two arbitrary guesses is not a measurement. It is a guess wearing the costume of one.

The heat map persists anyway, for the same reason the static green dashboard persists: it resolves discomfort. It takes a hard, contested, evidence-hungry question and returns a tidy amber square that lets everyone move on. That is precisely the property we refuse to ship.

Why the lie is comfortable

Be honest about the incentives. A register that can be curated by hand is a register that can be made to look better before a board meeting. A residual you score yourself is a residual you can improve without doing anything. A heat map is a slide that closes the agenda item. None of this requires bad faith — it only requires a tool that rewards the appearance of control over the fact of it. Most GRC tooling does exactly that, and calls it usability.

Your incidents already say what happened

Here is the part the register cannot survive: everything you would need to check it against, you already have. The register claims a treatment is working; the change record shows it stalled months ago. It claims a risk is accepted; the acceptance's own review window lapsed two quarters back. It claims a residual dropped from high to medium; the incident log shows the same control failing since. The register says what you typed. Your incidents say what happened — and in most organisations the two are never made to agree.

That reconciliation is the whole job. A register nobody checks against reality is not a control, it is a diary. The honest version runs the check continuously and says the disagreement out loud instead of smoothing it over.

What an honest register looks like

So we built the opposite, and we were strict about it.

Frank does risk — properly — but it does not borrow the incumbent's vocabulary. Risk is a read-only lens, not a document you maintain by hand. Each risk domain is computed from the obligations, commitments, decisions, debts, and assumptions already under assurance — you do not type it in, and there is no field to curate. It is derived from what is already true, or it does not appear at all.

Three things it refuses to do, on principle:

  • No heat map. Frank publishes posture with an expiry — Holds until YYYY-MM-DD — not a quadrant. Confidence is a window, not a colour.
  • No credit for a self-reported residual. A number you assigned yourself is an opinion, and Frank credits neither the number nor the optimism behind it. Only the evidence moves the posture.
  • No curating the register in the app. If you could hand-edit it, it would say what you typed again. It is computed from what you can prove, or it does not exist.

These are not gaps we are apologising for. They are the product.

The pay-off is that the register stops being a document and becomes a claim — it resolves to the same coverage assertion as everything else Frank publishes, with one named authority standing behind it, the evidence that earned it, the debts holding it down, and the date it stops being defensible. A regulator, an insurer, or your own board can check it instead of trusting it.

The test

Here is the only question worth asking of any register: what would have to be true for this to be wrong, and would the document tell me? If the answer is "nothing, because it is just what we think", you do not have a risk register. You have a record of how you felt on the day you typed it.

You can see what the honest version says about your own scope. Start with obligation visibility — it will not score you, certify you, or reassure you. It will tell you what your evidence actually does.