Risk register, a live record, not a filing cabinet
A risk register is the record of identified risks with their owner, assessed severity, treatment decision and review date. In third-party risk it is the authoritative list of what each vendor exposes you to and what is being done about it — distinct from a vendor register, which lists relationships rather than risks.
Two registers, often confused
A vendor register lists relationships: who the supplier is, what they provide, which business owner is accountable, what tier they sit in, when they were last assessed. A risk register lists exposures: this vendor holds this data with this weakness, rated this severity, owned by this person, treated this way, reviewed on this date.
Programmes that keep only the first can tell you everything about their suppliers except what is wrong with them. Programmes that keep only the second lose the population view — coverage, tiering, concentration — that only the vendor register can produce. Both are needed, and the link between them is the vendor record.
What a good entry holds
A description specific enough to act on — "no MFA on the administrative console used by their support staff", not "access control weaknesses". An inherent and a residual rating, so the effect of the controls is visible. A named owner who is a person, not a department. A treatment decision with a due date. And a review date that has been met.
The failure mode is age. Registers accumulate: entries are added, treated in principle, never closed, and after two years the document describes a programme that no longer exists. A register nobody trusts gets worked around, and the working-around is invisible — which is worse than the stale entries, because at least those are countable.
Common questions
What is the difference between a risk register and a vendor register?
What should a third-party risk register entry contain?
How often should a risk register be reviewed?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.