What Is a Risk Register? Definition, Purpose & Examples
Learn what a risk register is, why it matters, and how to use one effectively in your organization. Includes real-world examples and best practices.
Master enterprise risk management with expert guides, frameworks, and best practices.
Learn what a risk register is, why it matters, and how to use one effectively in your organization. Includes real-world examples and best practices.
Understand the difference between inherent and residual risk, and why tracking both matters for ERM.
Master risk scoring with likelihood and impact matrices. Includes examples and best practices.
Learn the 3 types of risk controls with examples. Build a balanced control framework for effective risk management.
Discover how risk registers support internal audit planning, execution, and follow-up for stronger governance.
Learn how risk management and compliance differ, and how to integrate them for stronger governance.
A step-by-step POPIA compliance checklist to help South African organisations meet their obligations under the Protection of Personal Information Act.
Risk appetite and risk tolerance sound similar but serve very different purposes. This guide explains both concepts and helps you avoid common mistakes.
A practical guide to risk heat maps — what they are, how to create one, and how to use them to communicate risk clearly to leadership.
Everything accountable institutions need to know about FICA compliance in 2026 — CDD, RMCP, PEP screening, and technology solutions.
How to build an enterprise risk management framework for African organisations — COSO ERM, ISO 31000, King IV alignment, and 6-step implementation.
How to build a POPIA-aligned data governance framework — roles, policies, data inventory, data quality, and breach response.
How to choose internal audit software in South Africa — IIA standards alignment, must-have features, King IV combined assurance, and evaluation criteria.
A practical comparison of CIA, CRISC, CISA, CGAP, and GRCP certifications for South African GRC professionals — with guidance on choosing based on your career goals.
Practical framework for managing vendor and supplier risk in South Africa — POPIA operator agreements, TPRM lifecycle, vendor risk assessment, and technology.
How automation transforms B-BBEE compliance management — scorecard tracking, supplier certificate management, verification preparation, and GRC integration.
A risk management policy is the document that turns risk management from an activity into a mandate. Here is what it contains and how to write one.
A risk appetite statement tells the organization how much risk it is willing to take to pursue its objectives. Here is how to build one that actually guides decisions.
A risk assessment is the engine of your risk program. Here is a practical, step-by-step process for running one from scope to documented output.
A risk treatment plan turns a list of risks into a set of committed actions with owners, deadlines, and measurable targets.
A controls register is the inventory of everything your organization relies on to keep risk in check, and the evidence that it actually works.
A board risk report gives directors the one view they need: are our biggest risks within appetite, and are they moving in the right direction?
A good risk workshop turns scattered opinions into a scored, owned set of risks in a single session. Here is exactly how to run one.
Combined assurance coordinates everyone who provides assurance so the board gets one coherent picture, with less duplication and fewer gaps.
A compliance register turns a wall of regulations into a tracked, owned, and auditable list of obligations. Here is how to build one that works.
Regulatory obligation mapping turns dense legislation into a structured library of discrete, ownable requirements. Here is how it works.
A compliance policy states what your organization commits to and why. Here is what it contains and how to keep it credible.
A compliance gap analysis measures the distance between what regulations require and what you actually do, then turns that distance into a remediation plan.
An inspection is not a test you cram for. It is a snapshot of how you already operate. Here is what to expect and how to be ready.
Compliance evidence is the proof that your controls actually work. Without it, even a well-run program collapses under audit scrutiny.
A board compliance report is not a data dump. It is a decision tool. Learn the sections, the framing, and the discipline that make directors trust it.
A missed filing deadline is one of the most avoidable compliance failures there is. A compliance calendar is how disciplined teams make sure it never happens.
Stop auditing on a fixed rotation and start directing audit effort where risk actually lives. This guide shows you how to build a risk-based internal audit plan.
The audit charter is the single document that grants internal audit its authority, defines its scope, and protects its independence. Here is what belongs in one.
From the engagement letter to the closing meeting, here is what an internal audit actually involves, step by step, with a realistic timeline.
A good audit finding does more than point out a problem. It makes the case for action. Here is the structure, the severity scale, and a worked example.
Agreeing a fix is not the same as fixing the problem. A follow-up audit verifies remediation actually happened, and actually works.
The audit universe is the complete map of everything internal audit could examine, and the foundation of a credible, risk-based audit plan.
A control only reduces risk if it is both well designed and actually working. Control effectiveness is how you prove which.
An internal audit report is only as valuable as it is clear. Here is exactly what goes into one and how to write it for the people who will act on it.
An incident register turns scattered tickets, emails and war-room notes into a single, auditable record of what went wrong and what you did about it. Here is how to build one.
Fixing a symptom feels like progress until the same incident comes back. Root cause analysis finds the underlying reason so your corrective actions actually stick.
A good incident report does more than record what happened. It explains, for the right audience, why it happened and what changes because of it.
Good incident management is not about heroics during a crisis. It is a calm, repeatable lifecycle with clear roles, timeframes, and learning built in.
An incident that teaches you nothing is just damage. A good post-incident review turns it into a permanent improvement. Here is exactly how to run one.
POTRAZ registration, data subject rights, cybercrime provisions and enforcement penalties explained.
Meet your obligations under Kenya's Data Protection Act, including ODPC registration, DPIAs and penalties.
Meet your obligations under the Mauritius Data Protection Act, with a focus on FSC requirements for financial services.
A practical guide to building and running an enterprise risk management programme.
DPO requirements, breach notification and NDPC enforcement, in a checklist you can work through.
PDPC requirements, DPO appointment and breach notification under Tanzania's PDPA 2023.
What compliance means, why it matters, the key regulations to know and how to build a programme from scratch.
Why an integrated approach to governance, risk management and compliance matters for organisations across Africa.
A beginner-friendly explanation of the ISO 31000 risk management standard.
What risk management frameworks are, why they matter, the major ones compared and how to implement one step by step.