KITE 2025 New Product Award — Local IT | SACEEC

How Do You Monitor Risks Over Time? A Practical Process

Identifying risks is the easy part. This is the repeatable process that keeps your register current instead of letting it die after the kickoff.

Free PDF GuideDownload this guide as a PDF

Most risk registers are born in a burst of energy and then quietly die. Six months after the workshop, the scores are stale, the owners have moved on, and nobody trusts the document. Monitoring is the discipline that keeps a register alive: a repeatable loop of reviewing, measuring, and reassessing so the register reflects reality rather than a snapshot of the past. This tutorial gives you a concrete process you can put in place this quarter.

Watch: how to monitor risks over time with review cycles and KRIs Watch: How to monitor risks over time (short tutorial)
i

What You'll Achieve

By the end of this tutorial you will have a working monitoring routine: review cycles tuned to each risk level, key risk indicators with defined thresholds, a method for spotting trends, trigger-based reviews for sudden change, and a reassessment habit that keeps likelihood and impact scores honest over time.

Why Monitoring Matters

Risk is not static. A supplier that was rock-solid last year may now be in financial distress; a control that worked may have decayed; a new regulation may have raised the stakes. Without monitoring, your risk register drifts from reality, and decisions get made on outdated information. Monitoring closes that gap by continuously asking three questions: Has anything changed? Are our controls still working? Are our scores still right?

Prerequisites

  • An existing risk register with scored risks and named owners
  • Agreed likelihood and impact scales so reassessments stay consistent
  • A way to store history, so you can see how each risk has changed over time

Step 1: Set Review Cycles by Risk Level

Not every risk deserves the same attention. The first move is to tie review frequency to risk level, so your effort flows to where it matters. A critical risk reviewed once a year is negligence; a low risk reviewed weekly is wasted effort.

Risk Level Review Frequency Who Reviews
Critical (20-25) Monthly, or more often Risk owner plus executive oversight
High (12-19) Monthly to quarterly Risk owner and risk function
Medium (6-11) Quarterly Risk owner
Low (1-5) Annually Risk owner

Put these cadences in a calendar and assign each review to a named person. A review that depends on someone remembering will not happen. Schedule recurring reminders against each risk's next-review date.

i

Pro Tip

Stagger reviews across the quarter rather than dumping them all into one week. Reviewing five risks a week keeps the work sustainable and the register continuously fresh, instead of creating a once-a-quarter panic where everything is rushed.

Want the full framework with worked examples?

Step 2: Define Key Risk Indicators and Thresholds

Scheduled reviews tell you to look; key risk indicators (KRIs) tell you what is actually moving between reviews. A KRI is a measurable metric that acts as an early-warning signal for a specific risk. The art is choosing indicators that genuinely move ahead of the risk, not after it has already materialised.

For each significant risk, define one or two KRIs and set thresholds that classify the current reading as green, amber, or red:

Risk Key Risk Indicator Green Amber Red
Cyber breach Unpatched critical vulnerabilities 0 1-3 4+
Key person loss Roles with no documented backup 0 1-2 3+
Supplier failure On-time delivery rate Above 98% 95-98% Below 95%
Compliance breach Overdue obligations 0 1-2 3+

Define what happens when a threshold is crossed before it is crossed. An amber reading might trigger a note to the owner; a red reading should trigger an immediate review and possible escalation. Linking KRIs to your obligation tracking means some indicators update themselves.

!

Important

A KRI you do not measure is worse than no KRI at all, because it creates false comfort. Only define indicators you can actually capture on a regular basis with reliable data. Three measured KRIs beat twenty aspirational ones.

Step 3: Analyse Trends, Not Just Snapshots

A single reading tells you where a risk is; a trend tells you where it is heading. The direction of travel is often more important than the current value. A risk sitting at "high" but steadily improving needs a different response than one at "medium" but deteriorating fast.

To make trend analysis possible, you must store history. Every time a risk is reviewed or rescored, keep the previous values rather than overwriting them. Then look for:

  • Score movement: Is the residual risk score rising or falling over successive reviews?
  • KRI direction: Are indicators trending toward red even while still green today?
  • Action burn-down: Are treatment actions being completed, or piling up overdue?
  • Recurrence: Are the same incidents or near-misses showing up repeatedly?
Example

Catching a risk before it bites

The supplier on-time delivery KRI reads green at 99% one month, 97% the next, then 95.5%. No single reading is alarming, but the trend is unmistakably downward. The owner investigates, discovers the supplier has lost a key production line, and arranges a backup source, weeks before a missed delivery would have hit a customer. The snapshot looked fine; the trend told the real story.

Step 4: Run Trigger-Based Reviews

Scheduled reviews and KRIs handle the steady state, but some changes demand an immediate, unscheduled review regardless of where you are in the cycle. Define a short list of triggers that automatically pull a risk back onto the table:

  • An incident or near-miss related to the risk occurs
  • A control fails or an audit finds it ineffective
  • A KRI crosses into red
  • A major change lands, such as a new system, new market, reorganisation, or acquisition
  • New regulation or a regulatory enforcement action in your sector
  • A risk materialises elsewhere in the industry

Trigger-based reviews are what separate a responsive risk function from a calendar-driven one. They ensure the register reflects events as they happen, not just at the next scheduled checkpoint. Major changes should also prompt a fresh risk assessment or a focused risk workshop for the affected area.

Step 5: Reassess Likelihood and Impact

At each review, do not simply confirm the old score by reflex. Deliberately re-ask the two scoring questions in light of what has changed since last time:

  1. Has likelihood changed? New threats, more exposure, or a degraded control push it up; a successful new control pushes it down.
  2. Has impact changed? Business growth, new dependencies, or higher penalties can raise impact even if likelihood is steady.
  3. Has the control environment changed? Revisit whether residual risk is still where you thought, given control performance since the last review. If you are unsure of the distinction, revisit inherent versus residual risk.
  4. Record the new score and the reason. Always capture why the score changed, so the history tells a story rather than showing unexplained jumps.

Resist two opposite temptations: rubber-stamping every score as unchanged because review is tedious, and over-reacting to a single bad month by spiking a score. Anchor reassessments to the agreed scales and the trend, not the mood of the day.

Step 6: Build a Monitoring Dashboard

A dashboard turns the register from a document people open occasionally into a live picture they glance at often. You do not need expensive tooling to start. Even a well-structured summary view delivers most of the value. Useful elements include:

  • Risk heat map: Current risks plotted on a likelihood-impact grid, colour-coded by level.
  • Movement indicators: Arrows showing which risks rose, fell, or held since last period.
  • KRI status board: Each indicator's current green / amber / red reading.
  • Overdue items: Reviews and treatment actions past their due date.
  • Top risks: The handful that leadership should focus on now.

The dashboard is also the raw material for upward reporting. A good monitoring dashboard makes assembling a board risk report a matter of curation rather than a scramble, and it gives internal audit a clear, current view to work from.

i

Pro Tip

Make the dashboard show movement, not just the current state. A static heat map answers "where are we?"; a heat map with trend arrows answers the far more useful question "where are we heading?", which is what leadership actually wants to know.

Step 7: Keep the Register Alive

The whole point of monitoring is to prevent register decay. A few habits make the difference between a living register and a shelf-ware document:

  • Tie reviews to a named owner and a date, and chase overdue ones visibly.
  • Retire dead risks deliberately rather than letting them clutter the view, recording why each was closed.
  • Add emerging risks as they surface, so the register grows with the business.
  • Connect risks, controls, and actions so a change in one is visible in the others (see linking risks, controls, and actions).
  • Report regularly, because a register that feeds visible reporting stays maintained, while one nobody looks at rots.

Common Mistakes to Avoid

1. Treating monitoring as an annual event

An annual refresh is not monitoring. Risk moves continuously, so your review cadence and KRIs must run between the big set-piece reviews.

2. KRIs nobody measures

Indicators that are never actually captured create false comfort. Only define KRIs you can measure reliably, and measure them on schedule.

3. Overwriting history

If each review erases the previous score, you lose the trend, the single most valuable signal. Always preserve the history.

4. Rubber-stamping scores

Confirming "no change" without genuinely re-asking the scoring questions defeats the purpose. Reassess deliberately every time.

5. No trigger process

Relying only on the calendar means major changes go unreviewed until the next scheduled date. Define triggers that pull risks back onto the table immediately.

6. Monitoring without reporting

A register that feeds no report tends to die. Wire monitoring outputs into regular reporting so the work stays visible and valued.

Key Takeaways

Summary

  • Tie review frequency to risk level so effort flows to the risks that matter most
  • Define a small number of measurable KRIs with green, amber, and red thresholds
  • Analyse trends, not just snapshots, because direction of travel often matters more than the current value
  • Use trigger-based reviews so incidents, control failures, and major changes pull risks back immediately
  • Reassess likelihood and impact deliberately at each review and record why scores changed
  • A dashboard and regular reporting keep the register alive instead of letting it decay into shelf-ware

Frequently Asked Questions

How often should risks be reviewed?

Tie frequency to risk level: critical risks monthly or more often, high risks monthly to quarterly, medium risks quarterly, and low risks annually. On top of the schedule, run trigger-based reviews whenever an incident, control failure, or major change occurs, regardless of where you are in the cycle.

What is a key risk indicator (KRI)?

A key risk indicator is a measurable metric that acts as an early-warning signal for a specific risk. One example is the number of unpatched critical vulnerabilities for cyber risk. Good KRIs move ahead of the risk, so a deteriorating reading gives you time to act before the risk materialises. Set green, amber, and red thresholds for each.

Why does trend analysis matter more than a single reading?

A snapshot tells you where a risk is; a trend tells you where it is heading. A risk that is still green but steadily worsening often needs attention before one that is amber but stable. Storing the history of scores and KRIs is what makes trend analysis possible, so never overwrite previous values.

When should I rescore a risk?

Reassess likelihood and impact at every scheduled review, and immediately when a trigger fires. Ask whether likelihood, impact, or the control environment has genuinely changed, anchor your judgement to the agreed scoring scales, and record the reason for any change so the history remains meaningful.

Do I need special software to monitor risks?

No. You can start with a well-structured spreadsheet, scheduled reminders, and a simple dashboard view. As the programme matures, dedicated risk tooling helps by automating reminders, preserving history, calculating trends, and generating dashboards and reports, which removes much of the manual upkeep that causes registers to decay.

How do I stop my risk register from going stale?

Assign every review to a named owner with a date, chase overdue items visibly, retire dead risks and add emerging ones, and, most importantly, wire the register into regular reporting. A register that feeds a board risk report or dashboard stays maintained, because people notice when it is wrong.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.