Understanding the Risk Register

Created by Celia Johnston, Modified on Thu, Sep 17 at 1:09 PM by Celia Johnston

The Risk Register is the central repository for every risk your organization is tracking. This article explains how to navigate the Risk Register, read the Risk Matrix, and manage a risk's configuration.


What is the Risk Register?

The Risk Register is the centralized repository of every risk your organization is monitoring. Each entry displays the risk's description, its associated rules, and any linked violations or incidents.


From the Risk Register, you can:

  • View a visual representation of each risk's Likelihood × Impact score
  • View and configure the risks you want to monitor
  • Monitor and resolve active violations
  • Log real-world incidents
  • Review the full compliance history for each risk


Navigate the Risk Register

The Risk Register overview displays every risk currently being monitored, along with a total count at the top of the page.


ElementDescription
SearchSearch for a risk by name.
Risk Score filterUse the slider to filter risks by a Risk Score range (1–25).
Risk NameThe name and description of the risk.
Risk ScoreCalculated as Likelihood × Impact.
Open ViolationsThe number of violations currently open and requiring action for this risk.


Click Add a new risk to create a new entry, or click any Risk ID to open its full detailed view.


Read the Risk Matrix

The Risk Matrix, shown alongside the risk list, gives a visual overview of risk severity across your organization. It plots every risk based on two factors:

  1. Impact: Represented on the horizontal axis, from 1 (Negligible) to 5 (Catastrophic). Your organization sets this value under the risk's Configuration tab, choosing the level that best reflects how severe the consequences of this specific risk would be for your operations. This is not automatically calculated by Horizon.
  2. Likelihood: Represented on the vertical axis, from 1 (Rare) to 5 (Highly likely). This is calculated automatically by Horizon, on a scale from 1 (Rare) to 5 (Highly likely), based on the number of open violations linked to that risk. The more open violations a risk has, the higher its Likelihood score.


Each cell in the Risk Matrix is color-coded to reflect the overall severity of that Likelihood/Impact combination:

  • Green: Low
  • Yellow: Medium 
  • Orange: High
  • Red: Critical 


Severity increases as you move toward the top-right of the matrix, where both Likelihood and Impact are highest. A number inside a cell indicates how many risks currently fall into that Likelihood/Impact combination.


Use the Risk Matrix to quickly identify where the most severe risks are concentrated.


What's Inside a Risk Entry?

Each risk entry contains several tabs:

  • Active Violations: Displays all active violations linked to this risk. See [Managing Violations] for the full workflow.

  • Resolved Violations: Displays all resolved violations linked to this risk.

  • Incidents: A record of all real-world events logged against this risk. See [Logging Incidents] for instructions.

  • Rules: Displays the automated rules that determine when a violation is triggered for this risk. See [Rules] for details.

  • Log: A chronological record of all processing events, rule changes, and activity associated with this risk.

  • Configuration: Contains the risk's core setup details, which include: 


FieldDescription
IdentifierThe name of the risk.
DescriptionA summary of what this risk represents.
CategoryThe category this risk belongs to.
Impact LevelThe severity of this risk's potential consequences: Negligible, Marginal, Serious, Major, or Catastrophic.


Update a risk's configuration:

  1. Open the risk from the Risk Register.
  2. Select the Configuration tab.
  3. Make the required changes.
  4. Click Save.


Delete a Risk

Deleting a risk permanently removes it and all associated data.

  1. Open the risk from the Risk Register.
  2. Select the Configuration tab.
  3. Click Delete this risk.
  4. Confirm the deletion.


Note: This action is permanent and cannot be undone. All associated rules, violations, and incidents linked to this risk will also be deleted.


Frequently Asked Questions (FAQs)

What's an example of a risk entry?

  • Transport & Logistics: A "Wrong Class" risk might track drivers operating vehicles outside their licensed class. Its rule checks the Driver's Abstract verification for a Licence Class that doesn't match the vehicle type assigned. Each flagged driver adds an open violation, raising the risk's Likelihood. Given the potential for accidents and regulatory penalties, this risk might be configured with an Impact Level of Major.


  • Finance: A "Financial Distress" risk might track employees in financial distress who hold positions conducive to fraud. Its rule checks a Credit Report verification for a Credit Score below a defined threshold. Each flagged employee adds an open violation, raising the risk's Likelihood. Given the reputational and financial exposure involved, this risk might be configured with an Impact Level of Catastrophic.


How is Risk Score calculated?

Risk Score is calculated as Likelihood × Impact.


What do the colors on the Risk Matrix mean?

Each color represents a severity level: green for Low, yellow for Medium, orange for High, and red for Critical.


Can I filter risks by score?

Yes. Use the slider at the top of the Risk Register to filter risks within a specific Risk Score range.


What happens if I delete a risk?

The risk and all associated data, including its rules, violations, and incidents, are permanently deleted. This action cannot be undone.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article