Creating an HR Risk Register That Supports Better Decisions
An HR risk register helps leaders decide which people-related uncertainties need action, monitoring or acceptance. It should not become a catalogue of everything that could possibly go wrong.
Define risk in decision terms
Describe the uncertain event, cause and consequence. “Attrition” is a topic; “loss of the only certified engineer before a replacement is ready could stop statutory inspections” is an actionable risk statement. Identify the objectives, employees or operations affected.
Gather risks from several sources
Use workforce plans, incidents, audits, employee concerns, litigation themes, vacancies, succession gaps, vendor dependencies and upcoming business changes. Involve operations, finance, legal, safety and information-security owners where relevant. HR should coordinate people risks, not claim ownership of every cause.
Assess consistently
Define likelihood and impact scales with concrete anchors. Consider employee harm, legal exposure, operational disruption, financial effect and reputation. Record evidence and uncertainty. A simple matrix supports prioritisation but does not calculate truth.
Record existing controls
Distinguish a control that is designed from one that operates reliably. Note the owner, frequency and evidence. A policy is not an effective control if nobody understands or follows it. Assess residual risk after credible controls, not after intended controls.
Choose a treatment
Avoid the activity, reduce likelihood or impact, transfer part of the exposure, prepare contingency or formally accept it within authority. Every action needs an owner and date. Vague entries such as “monitor closely” should name the trigger and decision.
Protect sensitive information
Do not place employee diagnoses, allegations or identifiable case details in a widely shared register. Use aggregated or coded descriptions and keep case records in the appropriate restricted system. Set access and retention rules.
Use indicators carefully
A critical-role vacancy, overdue investigation, excessive overtime or failed payroll control may warn that exposure is changing. Define thresholds as prompts for review, not automatic conclusions. Pair indicators with responsible interpretation.
Review at the right rhythm
High risks may need frequent owner updates; stable lower risks need less. Review after incidents, restructures, acquisitions, system changes and new legal obligations. Close a risk only when exposure has ended or has been formally accepted—not because the action date passed.
Connect to enterprise governance
Escalate material risks into the organisation’s wider risk process using comparable language and ratings. Record decisions, dependencies and accepted residual risk. Leaders should challenge whether resources match the stated priority.
Example risk entry
A useful entry might state: “If two payroll reviewers leave before the new control process is documented and tested, incorrect salary payments could affect employees and create rework.” Existing controls, remaining gaps, interim backup, recruitment action, training dates and a continuity trigger can then be assigned. This is more actionable than “payroll risk—high”.
Distinguish issues from risks
An event that has already happened is an issue and needs immediate management; uncertainty about its future consequence may also create a risk. Keep the link visible without using the register as a substitute for incident, grievance or investigation records.
Challenge scoring bias
Visible or recent events can receive inflated ratings while slow-moving capability, conduct or compliance risks are ignored. Use cross-functional review, evidence and comparable scenarios. Do not average fundamentally different impacts into a comfortable middle score when one dimension could be severe.
A strong register makes uncertainty discussable and action visible. Its value lies in decisions and controls, not the number of rows maintained.