What it means
A risk register is a structured log of the risks facing a project, programme or organisation. Each entry typically records a description, an assessment of likelihood and impact, a named owner, the mitigation planned or under way, and a review date. It is the standard instrument through which governance bodies are meant to see trouble coming.
Why it matters more than its reputation
In organisations where open disagreement is expensive, the register is where reservations go to be recorded without being voiced. That makes it an unusually honest document, if anyone reads it that way. When a major commitment is up for approval, the register shows whether the risks were engaged or ritually documented: entries with specific triggers, funded mitigations and recent review dates signal the former; a wall of amber scored 3x3 with mitigations that read "monitor closely" signals the latter. The register also creates a comfortable illusion, that a risk with an owner and a row in a spreadsheet is a risk being managed. Parking is not mitigation.
How registers decay
Risks written vaguely, "delivery timescales may be challenging", so no action could ever follow from them. Scores negotiated downward before board packs are issued, because a red risk invites questions the team would rather not take. Registers updated the day before each steering meeting and untouched between. And the structural omission: the risk that the decision itself is wrong, the strategy, the vendor, the deal, almost never appears, because the register belongs to the team executing the decision, not to anyone questioning it.