Skip to content

board risk register

Board Risk Register: What the Board Should Track, Who Owns It, and When to Review

How a board keeps a short register of the risks it is overseeing — owner, board-declared severity, status, next review date, and the supporting document — and how Prepared Board keeps that register today without acting as ERM software or a risk score engine.

~8 minutes· Informational / How-to· Updated 2026-10-06· Markdown for your agent

Board Risk Register: What the Board Should Track, Who Owns It, and When to Review

Target keyword: board risk register
Intent: Informational / How-to
Last updated: 2026-10-06
Reading time: ~8 minutes


Who this guide is for

Chairs, audit and risk committee members, board secretaries, and investor directors who need to answer one question with evidence: "Which risks is this board overseeing, who owns each one, and when did the board last look at it?"

This is practice guidance, not legal advice. What a board must oversee depends on your industry, regulators, bylaws, and (for Delaware corporations) the duty of oversight case law summarized in the fiduciary hub. Ask counsel. A board risk register is a record of what the board chose to oversee, not proof that oversight was adequate.


What a board risk register is (and is not)

Management usually runs an enterprise risk management (ERM) program with dozens or hundreds of risks, likelihood and impact ratings, and controls. The board needs something smaller: the handful of risks it has decided to oversee directly, each with a named owner and a date the board will look again.

A board risk register is useful for three things:

  1. Showing oversight. A dated list of risks the board was watching, with the materials it reviewed, is the kind of record directors point to when someone later asks "what did the board know, and when?"
  2. Keeping reviews from slipping. A next review date turns "we should revisit runway" into a date someone can see has passed.
  3. Handing over cleanly. When a director or owner leaves, an owner column shows which risks no longer have anyone accountable.

It is not management's ERM system, not a heat map, and not an insurance or legal assessment. Treat severity as the label the board chose, not as a measured quantity.


How to build one in five steps

  1. Start with five to ten risks, not fifty. Pick the risks where a bad outcome would change the company's strategy, financing, or license to operate — customer concentration, cash runway, key-person dependency, cyber, a major regulatory exposure. Leave the long list with management.
  2. Name one owner per risk, from the board or its officers. The owner brings the update; it does not mean they personally manage the risk. An owner who is no longer on the board is a gap to fix, not a footnote.
  3. Use a simple severity label the board agrees on. Low / Medium / High is enough. Write down that it is the board's judgment, so no one mistakes it for a computed score.
  4. Set a status and a next review date. Open (actively discussed), Monitoring (watching between meetings), Closed (no longer overseen, kept for history). Every Open or Monitoring risk gets a date.
  5. Attach the material the board relied on. The concentration analysis, the runway model, the incident report — so the record shows what was in front of the board, not just that the topic came up.

Reading the register: what investors and audit committees look for

QuestionWhat the register should show
Which risks is the board overseeing right now?Open and Monitoring entries, each with an owner
Has anything slipped past its review date?Entries whose next review date has passed while still Open or Monitoring
Does every risk have an active owner?No entries owned by someone who has left the board
What did the board rely on?A linked document per entry where one exists
What has the board closed, and when?Closed entries kept with their history rather than deleted

Two mistakes show up again and again: a register that is just management's ERM list pasted in (so the board cannot tell what it is actually watching), and review dates that pass without anyone noticing until the next audit.


From signal to register

Risks rarely arrive labeled. They show up as an overdue action item, a contract nearing expiry, an open cyber incident, a director's term ending. A good habit is to scan what the board's own records already show before each meeting and decide, item by item, whether it belongs on the register, on the next agenda, on a watch list, or nowhere — and to write down the reason when the answer is "not relevant." The board pack guide covers getting the supporting material in front of directors in time.


How Prepared Board handles this today

Board risk register. /app/risk-register holds board-declared risks the board is overseeing: title, owner (member), board-declared severity (Low / Medium / High), status (Open / Monitoring / Closed), optional next review date, and optional same-board Document. The owner must be an ACTIVE board member. Chair, Admin, or Owner enables the register in Settings; Chair, Secretary, Admin, or Owner adds and edits; directors, the CEO, the CFO, and advisors can read it. Severity shows as "High (board-declared)" and so on, and saving a risk confirms "severity is chair-set, not a computed score." Copy for your agent copies the register as markdown.

Board Go cue. When an Open or Monitoring risk is past its next review date, Board Go on the board home shows a soft cue — "Board risk past board-declared next review" (or the count when there are several) — linking to the register.

Risk radar. /app/risk-radar gathers inside signals from this board's own records — including "Risk register — review date passed" and "Risk register — no active owner" — each linked to its source. Chair, Secretary, Admin, or Owner record the board's choice per item: Added to risk register, Discuss next meeting, Watch, or Not relevant (with a required reason). Choosing the register adds an Open entry with an active owner; every choice is audit-logged. Outside sources (regulators, advisories, peer disclosures) are planned, not live.

Where it shows up. A register strip appears on board proof and in the diligence snapshot. Investor directors and sponsors see Open / Monitoring / Closed counts, risks past their board-declared next review, and chair-set High-severity active risks per board on /app/portfolio — only for boards where they hold an ACTIVE membership and their role can open that board's register.

Honest limits:

  • Board-declared entries only. Not ERM software, not a risk score engine, and not insurance advice.
  • No computed scores. Prepared Board does not calculate residual risk scores, does not score likelihood or impact, and does not rank risks or boards. Severity and status are chair-set labels.
  • A past review date is a soft cue, not a finding. It means the board's own date passed — not that oversight failed.
  • No outreach. Nothing is emailed to owners; reminders are what you see in the app. Nothing is sent.

Check every product claim on this page against Facts or the machine-readable /agent-facts.json.


Try it: Northlight Robotics

Northlight Robotics is a seeded venture-backed demo board (not a real company). Risks and names below are demo data; the shared demo password is an evaluation login, not SSO.

Sign ina sample board (see /sample-decision) / password123 (Elena Voss, chair), or pick Northlight at Try a board
Open/app/risk-register
See"Customer concentration — Harbor Logistics MSA" — High (board-declared), Open, owner Theo Rankin, next review Sep 20, 2026, now past, so Board Go shows the review cue. "Series B cash runway / burn oversight" — Medium, Monitoring, owner Priya Natarajan, next review Nov 15, 2026. "Series B closing conditions (closed)" kept as history. A demo key-person risk whose owner left the board
Then open/app/risk-radar
SeeThe past-review risk and the risk with no active owner listed as inside signals, beside overdue actions and other records, each with the board's choice
Pack (public)/pack/demo-pack-northlight-q4

Board-type guides

Related guides


Conclusion

A board risk register earns its keep when every risk the board is watching has an owner, a date, and the material behind it — and when a passed date is visible before the meeting, not after. Sign in as the Northlight chair to see a past-review concentration risk on the register and the radar, and verify every claim on Facts.

Try a board → Northlight

Prepared Board is a board decision operating system — agendas, packs, decisions, and audit trails in one place — so fiduciary process is easier than the workaround. Verify product claims on Facts.

Learn about Prepared Board →

See it on a real record

Prepared is in an invite-only beta. See what a finished decision record looks like, or request a pilot for your board.

Cite this page: Prepared Board, "Board Risk Register: What the Board Should Track, Who Owns It, and When to Review," https://preparedboard.com/guides/board-risk-register (updated 2026-10-06). Anchor: #cite-this. Product claims are verified on /facts.