Risk Register

A risk register is a logged inventory of specific vendor risks. Definition, use in margin drift work, and how it differs from a findings log.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Risk Register

A risk register is a structured log that names each identified risk, its likely cause, its potential cost, and who owns fixing it. Finance and procurement teams keep one to track exposure that has not yet become a loss. In vendor spend management, a risk register lists contract terms, vendor behaviors, and billing patterns that could produce margin drift before an audit confirms they have.

1. What is a risk register?

A risk register is a logged inventory of specific, named risks, each with a description, a likely cause, an estimated exposure, an owner, and a status. It is a working document, not a report. In vendor and contract management, it typically covers billing terms, renewal dates, and clauses that could produce overcharges if left unchecked, distinct from a list of confirmed findings.

The register format is consistent across finance, procurement, and operations: one row per risk, columns for description, cause, exposure, owner, and status. What changes by department is the content of the rows.

For vendor spend, a register line names a mechanism: a rate card that has not been refreshed, a rebate clause with an ambiguous trigger, a not-to-exceed cap with no monitoring in place. Each of those is a condition, not yet a loss.

2. How does a risk register differ from an audit findings log?

A findings log records confirmed problems an audit already located and quantified. A risk register records conditions that could produce a problem, whether or not one has occurred yet. The register is forward-looking and often written before any invoice is reviewed; the findings log is retrospective and written after review is complete.

Both can reference the same contract clause at different stages of the same work.

A register line for a volume tier clause might read: contract has three pricing tiers, no process confirms which tier applies at invoice time. That is a risk. A findings log entry for the same vendor, after review, would state the dollar amount billed at the wrong tier.

Teams that skip the register step and go straight to findings tend to miss risks that have not yet produced a countable loss.

3. What belongs on a vendor risk register?

A vendor risk register lists contract mechanisms that could generate billing error if unmonitored: rate cards without a refresh cycle, rebate clauses with unclear triggers, not-to-exceed caps with no alert, index escalation clauses tied to a benchmark nobody checks, and minimum commitment terms nobody tracks against actual volume. Each line names the mechanism and the category of spend it sits in, not a vendor's overall risk score.

Good register lines are specific enough that a reader without contract access understands the exposure in one sentence.

They often map to a known drift pattern, such as a rebate gap, a volume tier misapplication, or index escalation misapplied, and to the spend category it affects, such as a freight and 3PL audit or a maintenance and repair audit.

4. Who owns a risk register and how often is it reviewed?

Ownership sits with whoever controls the underlying decision: procurement for contract terms, AP for billing controls, a controller for the consolidated view. Review cadence should match how fast the underlying condition changes. A rate card risk might need quarterly review; a renewal-date risk needs review only near the renewal.

A register with no owner or no review date is a document, not a control.

Assigning an owner is what separates a register from a list. An owner is accountable for closing the line, escalating it, or documenting why it stays open.

A register with stale entries loses credibility faster than an empty one, because readers stop trusting any line on it.

For the wider pattern this sits inside, start with the margin drift guide.

5. Frequently Asked Questions (People Also Ask)

Is a risk register the same as a risk assessment?

No. A risk assessment is the analysis exercise that identifies and scores risks. The risk register is the resulting document, the log where those scored risks are recorded, assigned an owner, and tracked to closure.

How is a risk register different from a contract compliance checklist?

A checklist confirms a set of standard clauses are present in a contract. A risk register tracks specific, live exposures, including ones a checklist would not catch, such as a clause that exists but has no monitoring process behind it.

Does a risk register need a dollar value for every line?

An estimated exposure helps with prioritization, but a line without a firm number is still worth logging. Some risks, like an unmonitored renewal date, matter more for timing than for a specific dollar figure.

Who should maintain the risk register for vendor contracts?

Typically procurement or AP maintains the working document, with a controller reviewing it periodically. The owner of each line should be whoever can act on it directly, not a shared or unassigned role.

What happens to a risk register line once it is confirmed as an actual loss?

It moves off the register and into a findings log or recovery tracker, since it is no longer a potential exposure but a quantified one. The register line can be closed with a reference to where the confirmed finding now lives.

Can a risk register replace a periodic audit?

No. A register tracks known and suspected exposures; it depends on someone identifying the risk in the first place. A periodic audit, such as a freight and 3PL audit, can surface risks the register never had a line for.

How many risks should a vendor risk register typically contain?

There is no fixed count. The right size depends on the number of active vendor contracts and the complexity of their pricing terms, not a target number to hit.

Should every vendor have a risk register line, even low-spend ones?

Not necessarily. A register is more useful when it is limited to vendors and clauses with meaningful exposure, since a register padded with immaterial lines is harder to review and act on.

1. What is a risk register?

A risk register is a logged inventory of specific, named risks, each with a description, a likely cause, an estimated exposure, an owner, and a status. It is a working document, not a report. In vendor and contract management, it typically covers billing terms, renewal dates, and clauses that could produce overcharges if left unchecked, distinct from a list of confirmed findings. The register format is consistent across finance, procurement, and operations: one row per risk, columns for description, cause, exposure, owner, and status. What changes by department is the content of the rows. For vendor spend, a register line names a mechanism: [a rate card](/glossary/rate-card) that has not been refreshed, a rebate clause with an ambiguous trigger, a [not-to-exceed cap](/glossary/not-to-exceed-overrun) with no monitoring in place. Each of those is a condition, not yet a loss.

2. How does a risk register differ from an audit findings log?

A findings log records confirmed problems an audit already located and quantified. A risk register records conditions that could produce a problem, whether or not one has occurred yet. The register is forward-looking and often written before any invoice is reviewed; the findings log is retrospective and written after review is complete. Both can reference the same contract clause at different stages of the same work. A register line for a volume tier clause might read: contract has three pricing tiers, no process confirms which tier applies at invoice time. That is a risk. A findings log entry for the same vendor, after review, would state the dollar amount billed at the wrong tier. Teams that skip the register step and go straight to findings tend to miss risks that have not yet produced a countable loss.

3. What belongs on a vendor risk register?

A vendor risk register lists contract mechanisms that could generate billing error if unmonitored: rate cards without a refresh cycle, rebate clauses with unclear triggers, not-to-exceed caps with no alert, index escalation clauses tied to a benchmark nobody checks, and minimum commitment terms nobody tracks against actual volume. Each line names the mechanism and the category of spend it sits in, not a vendor's overall risk score. Good register lines are specific enough that a reader without contract access understands the exposure in one sentence. They often map to a known drift pattern, such as [a rebate gap](/glossary/rebate-gap), [a volume tier misapplication](/glossary/volume-tier-misapplication), or [index escalation misapplied](/glossary/index-escalation-misapplied), and to the spend category it affects, such as [a freight and 3PL audit](/glossary/freight-and-3pl-audit) or a maintenance and repair audit.

4. Who owns a risk register and how often is it reviewed?

Ownership sits with whoever controls the underlying decision: procurement for contract terms, AP for billing controls, a controller for the consolidated view. Review cadence should match how fast the underlying condition changes. A rate card risk might need quarterly review; a renewal-date risk needs review only near the renewal. A register with no owner or no review date is a document, not a control. Assigning an owner is what separates a register from a list. An owner is accountable for closing the line, escalating it, or documenting why it stays open. A register with stale entries loses credibility faster than an empty one, because readers stop trusting any line on it. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

Questions & Answers

Is a risk register the same as a risk assessment?

No. A risk assessment is the analysis exercise that identifies and scores risks. The risk register is the resulting document, the log where those scored risks are recorded, assigned an owner, and tracked to closure.

How is a risk register different from a contract compliance checklist?

A checklist confirms a set of standard clauses are present in a contract. A risk register tracks specific, live exposures, including ones a checklist would not catch, such as a clause that exists but has no monitoring process behind it.

Does a risk register need a dollar value for every line?

An estimated exposure helps with prioritization, but a line without a firm number is still worth logging. Some risks, like an unmonitored renewal date, matter more for timing than for a specific dollar figure.

Who should maintain the risk register for vendor contracts?

Typically procurement or AP maintains the working document, with a controller reviewing it periodically. The owner of each line should be whoever can act on it directly, not a shared or unassigned role.

What happens to a risk register line once it is confirmed as an actual loss?

It moves off the register and into a findings log or recovery tracker, since it is no longer a potential exposure but a quantified one. The register line can be closed with a reference to where the confirmed finding now lives.

Margin Drift Resources