4.3 Risk Identification Methods and Risk Register Construction

Key Takeaways

  • Risk identification aims to uncover, recognize, and describe risks that could help or prevent an organization from achieving its objectives.
  • ISO 31000 requires identifying risk sources, causes, triggering events, and potential consequences across tangible and intangible domains.
  • Formal risk statements follow the structured tripartite syntax: 'Due to [cause/source], [event] may occur, leading to [consequence/impact]'.
  • A robust risk register acts as a dynamic repository, recording risk metadata, ownership, inherent/residual ratings, control effectiveness, and action tracking.
Last updated: July 2026

4.3 Risk Identification Methods and Risk Register Construction

Risk identification is the third step of the ISO 31000:2018 risk management process (and the first step of the core Risk Assessment phase, which encompasses identification, analysis, and evaluation). The ultimate objective of risk identification is to find, recognize, and describe risks that could help or prevent an organization from achieving its objectives.

If a risk is not identified at this stage, it cannot be analyzed, evaluated, or treated, leaving the organization exposed to unmanaged uncertainty.


1. Core Elements of ISO 31000 Risk Identification

ISO 31000 mandates that risk identification be comprehensive, systematic, and focused on both threat risks (downside loss) and opportunity risks (upside value creation). To describe a risk fully, the risk manager must identify four interconnected components:

  1. Risk Sources: Real-world elements, conditions, or drivers that individually or in combination have the intrinsic potential to give rise to risk (e.g., cyber threat actors, macroeconomic volatility, combustible materials, legacy IT systems).
  2. Causes / Drivers: Underlying root vulnerabilities, triggers, or operational flaws that enable a risk source to materialize into an active event (e.g., unpatched software, inadequate staff training, lack of redundant power supplies).
  3. Risk Events: The specific occurrence, incident, change of circumstances, or discovery of a situation (e.g., unauthorized database intrusion, factory fire, critical vendor insolvency).
  4. Consequences / Impacts: The outcome of a risk event affecting organizational objectives (e.g., financial loss, operational downtime, regulatory fines, reputational damage, personal injury).

2. Systematic Risk Identification Methods (IEC 31010 Integration)

ISO 31000 is complemented by IEC 31010:2019 (Risk Assessment Techniques), which provides detailed guidance on selecting and applying systematic risk identification tools. Identification methods fall into several broad categories:

A. Evidence-Based & Historical Methods

  • Historical Loss Data & Incident Reviews: Analyzing past operational incidents, near-miss logs, internal audit findings, and external industry loss databases.
  • Checklists: Standardized lists of common risks based on historical experience, regulatory codes, or industry benchmarks. Limitation: Can create blind spots for novel or emerging risks outside the checklist.

B. Team-Based & Exploratory Techniques

  • Brainstorming: Structured group discussions designed to generate a wide range of ideas without immediate criticism.
  • SWIFT (Structured What-If Technique): A facilitated team-based technique using standardized prompt phrases (e.g., 'What if...?', 'What happens when...?', 'Has anyone considered...?') to investigate process deviations.
  • Delphi Technique: An anonymous, iterative survey of independent experts designed to reach consensus on complex, uncertain risks without dominant group member influence.

C. Process & Diagnostic Techniques

  • HAZOP (Hazard and Operability Study): A highly structured parameter-based technique (using guide words such as No, More, Less, As Well As, Part Of, Reverse) used primarily in engineering, chemical, and industrial operations to identify process deviations.
  • Process Mapping & Value Chain Analysis: Tracing material, financial, and data flows through business processes to pinpoint single points of failure, bottleneck vulnerabilities, and handoff risks.

D. Inductive & Deductive Modeling Techniques

  • Failure Mode and Effects Analysis (FMEA): A bottom-up, step-by-step technique evaluating how individual components or sub-processes can fail, identifying the failure mode, effect, and cause.
  • Bow-Tie Analysis: A visual technique connecting root causes (on the left) through a central Top Event (in the middle) to consequences (on the right), mapping preventive controls and mitigating barriers.

E. Scenario-Based Methods

  • Scenario Analysis & Stress Testing: Developing plausible future stories (e.g., extreme geopolitical conflict, sudden pandemic, combined market-cyber shock) to evaluate how complex interactions of events impact strategic objectives.

3. Constructing Formal Risk Statements ('The Tripartite Rule')

A frequent failure in enterprise risk management is poor risk phrasing. Vague risk statements (e.g., 'Our risk is cybersecurity' or 'The risk is losing money') impair effective analysis and treatment because they confuse causes, events, and consequences.

ISO 31000 best practices dictate using the Tripartite Risk Syntax:

Standard Syntax: ’Due to [Existing Cause/Source], [Uncertain Event] may occur, leading to [Impact on Objective].’\text{Standard Syntax: } \text{'Due to [Existing Cause/Source], [Uncertain Event] may occur, leading to [Impact on Objective].'}

Comparing Flawed versus Standardized Risk Statements

Flawed Risk StatementPrimary FlawCorrect ISO 31000 Tripartite Statement
'Our risk is cloud security.'Confuses a domain/technology with a risk event.'Due to misconfigured cloud access controls (Cause), unauthorized third parties may breach our customer database (Event), leading to regulatory fines under GDPR and reputational damage (Consequence).'
'Failure of the legacy payment gateway.'Confuses a cause or incident with a full risk scenario.'Due to unmaintained legacy payment software (Cause), the core checkout system may experience prolonged downtime during peak sales (Event), leading to $2M in lost revenue (Consequence).'
'Losing $10 million in revenue.'Confuses the consequence with the risk event itself.'Due to new aggressive market entrants (Cause), customer churn may increase by 25% (Event), leading to a $10M decline in annual operating revenue (Consequence).'

4. Risk Register Architecture and Metadata Fields

The Risk Register (or Risk Log) is the primary operational tool used to record, track, and manage identified risks throughout their lifecycle. ISO 31000 requires the risk register to be a dynamic, continuously updated document rather than a static annual filing.

+---------------------------------------------------------------------------------------------------------+
|                                    ISO 31000 RISK REGISTER ARCHITECTURE                                 |
+---------+----------+--------------------+-------------+------------------+---------------+--------------+
| Risk ID | Category | Tripartite Statement| Risk Owner  | Inherent Rating  | Controls &    | Residual     |
|         |          | (Cause-Event-Impact)|             | (Likelihood x    | Effectiveness | Rating       |
|         |          |                    |             | Consequence)     |               | (L x C)      |
+---------+----------+--------------------+-------------+------------------+---------------+--------------+
| RSK-001 | Cyber    | Due to...          | Chief CISO  | 4 x 5 = 20 (Ext) | MFA (Effective)| 2 x 4 = 8 (Med) |
+---------+----------+--------------------+-------------+------------------+---------------+--------------+

Essential Risk Register Fields

  1. Risk Identifier: Unique alphanumeric code (e.g., RSK-FIN-003).
  2. Risk Category / Taxonomy: Classification tier (Strategic, Operational, Financial, Compliance, Cyber, Reputational).
  3. Tripartite Risk Description: Standardized Cause-Event-Consequence statement.
  4. Risk Owner: The specific individual (by role/title) accountable for monitoring the risk and executing treatment.
  5. Inherent Risk Score: Likelihood, Consequence, and total Inherent Risk Rating before considering any existing controls.
  6. Existing Controls Inventory: List of current preventive, detective, or corrective controls in place.
  7. Control Effectiveness Rating: Assessment of control design and operating effectiveness (e.g., Effective, Partially Effective, Ineffective).
  8. Residual Risk Score: Likelihood, Consequence, and total Residual Risk Rating remaining after accounting for existing controls.
  9. Risk Treatment Selection & Action Plan: Planned treatment option (Avoid, Share, Mitigate, Retain) and key milestones.
  10. Target Risk Level: Desired residual rating post-treatment completion.
  11. Review Frequency & Date: Last review timestamp and next mandatory audit date.

5. Organizational Risk Categorization and Taxonomy

To ensure comprehensive coverage during risk identification, organizations construct a Risk Breakdown Structure (RBS) or Risk Taxonomy. Categorization prevents teams from focusing exclusively on familiar operational risks while ignoring critical strategic or compliance exposures.

  • Strategic Risks: Risks arising from strategic decisions, macroeconomic shifts, industry disruption, or M&A activities.
  • Financial Risks: Credit default, liquidity shortages, interest rate fluctuations, currency risk, and capital structure vulnerability.
  • Operational Risks: Process execution failures, human errors, physical asset damage, health & safety incidents, and supply chain disruptions.
  • Compliance & Legal Risks: Regulatory non-compliance, statutory violations, contractual disputes, and litigation.
  • Technological & Cyber Risks: Data breaches, ransomware, legacy system failure, software bugs, and IT infrastructure outages.
  • Hazard & Environmental Risks: Natural disasters, pandemics, industrial accidents, and climate transition risks.

Real-World Implementation Example: Global Logistics Fleet

An international freight logistics carrier conducts risk identification prior to introducing autonomous delivery trucks:

  • Identification Technique: SWIFT workshop with fleet managers, safety engineers, software developers, and insurers.
  • Risk Identification Output:
    • Risk Source: Autonomous driving machine learning algorithms.
    • Cause: Sensor calibration degradation in adverse weather conditions.
    • Event: Vehicle sensor failure resulting in high-speed collision on a public highway.
    • Consequence: Loss of life, severe regulatory investigation, corporate liability lawsuits, and suspension of autonomous operations license.
  • Risk Register Entry: Assigned ID RSK-OPS-042, categorized under Operational & Safety Risk, owned by the Vice President of Fleet Operations, scored Inherent Risk 25 (Extreme), mapped existing Lidar redundancies, and recorded residual risk score of 10 (Medium).
Loading diagram...
ISO 31000 Risk Identification and Risk Register Architecture
Test Your Knowledge

Which of the following represents a correctly structured ISO 31000 risk statement using recommended tripartite syntax?

A
B
C
D
Test Your Knowledge

What is the functional distinction between a risk source and a risk event during risk identification?

A
B
C
D
Test Your Knowledge

What is the primary purpose of constructing and maintaining a formal Risk Register within an ISO 31000 risk management framework?

A
B
C
D