Skip to content
Compliance

Risk Register Software: Excel vs Microsoft Lists vs a Dedicated Platform

Choose Excel for a small, stable register, Microsoft Lists for shared records, and a dedicated risk platform when linked evidence and treatment workflows become difficult to maintain.

Yellow warning triangle with a black exclamation mark on a yellow and white graphic background.
Illustrative stock image. Illustration by kreatikar on Pixabay.

Author

Fig Group

Published

Read time

7 min read

Share

A spreadsheet can be a sensible starting point. A shared list can improve collaboration. Dedicated risk software becomes useful when relationships, approvals, reminders and evidence are taking more effort to maintain than the register itself. The right choice depends on how often risks change and how many people need to act on them.

This guide is published by Fig Group. It compares approaches to running a register rather than presenting an independently tested ranking of vendors.

Section 01

Start with the decision the register needs to support

A director asks whether to approve a new supplier. An IT manager needs to prioritise remediation. An MSP needs to explain why one customer requires attention this week. Each needs a different view of the same underlying facts.

A useful risk record describes a plausible event, the conditions that make it possible and its business consequences. “Cybersecurity” is a category. “An unavailable identity provider prevents staff accessing the customer support system” is a scenario someone can investigate and manage.

For each scenario, record an accountable owner, the assessment date, existing controls, the reasoning behind the score and the next decision or action. A register with attractive charts but no clear responsibility will still require someone to chase work by email.

Section 02

Compare the three main approaches

Swipe across the table to view all columns.

ApproachWhen it fitsWhat to examine carefully
SpreadsheetA small, stable register maintained by a clearly identified ownerVersion control, permissions, reminders, linked evidence and change history
Microsoft Lists or another shared work-management toolSeveral contributors need a common view and straightforward assignmentsRisk-specific scoring, acceptance authority, relationships and reporting effort
Dedicated risk platformRisks connect to assets, suppliers, incidents, controls and multiple treatment actionsConfiguration effort, usable workflows, export quality and ongoing cost

Microsoft Lists supports rules and Power Automate workflows. Compare the configuration and maintenance needed for your risk process rather than assuming it cannot provide reminders or automation.

Do not assume that a dedicated platform is automatically the economical option. If a spreadsheet already supports a reliable monthly review of ten risks, the immediate improvement may be better descriptions and ownership. Conversely, a hundred risks managed through disconnected action trackers can create enough coordination work to justify a platform even before an audit.

Section 03

Assess scoring and treatment separately

Inherent risk is the assessment before the controls being considered. Current residual risk reflects controls already operating. Target risk is the intended position after planned treatment. Keep all three distinct. A treatment marked “planned” should not silently reduce the current score. Someone needs to establish that the control is implemented and explain why it changes the assessment.

Where teams use a likelihood-and-impact matrix, require definitions for each band. Two people selecting “high” using different assumptions have not produced comparable assessments. Retain the rationale alongside the number, including uncertainty and the limits of available evidence.

NIST's risk assessment guide treats maintaining assessments as part of the process. That supports a useful buying question: how will this register remain current after its initial population?

Section 04

Worked example: an unavailable appointment system

The following completed record is fictional. It illustrates a decision process, not a Fig Group customer result or a prescribed scoring method.

Swipe across the table to view all columns.

Record fieldCompleted example
Reference and scenarioR-014: a supplier outage prevents the consultancy accessing appointments for a full working day, causing missed appointments and rebooking work
Accountable ownerOperations manager
Existing controlsSupplier support arrangement; a restricted, encrypted booking export refreshed before each working day; a documented telephone fallback
Assessment basisOver the next 12 months, likelihood is 3 (plausible, with recent supplier interruptions); impact is 4 (major disruption: more than half a working day lost)
Current residual assessment3 × 4 = 12: existing controls have not yet demonstrated an effective fallback
Treatment AIT lead to verify that the export is complete and accessible without the supplier or normal sign-in service by 2 October 2026; retain the access and completeness test
Treatment BOperations manager to exercise telephone booking and later reconciliation by 9 October 2026; retain elapsed time, missed bookings and reconciliation results
Target after successful treatmentLikelihood 3 × impact 2 = 6, if evidence shows the fallback limits disruption to under two hours
Review outcomeThe exercise fails because the export omits appointment contact details. Current score stays at 12; the IT lead corrects the export and a repeat exercise is due on 16 October 2026

For this illustrative five-point scale, likelihood runs from 1 (rare) to 5 (almost certain) within the stated year. Impact runs from 1 (minor disruption under 30 minutes) to 5 (critical loss of service beyond one working day); bands 2, 3 and 4 represent under two hours, two to four hours, and more than four hours up to one working day respectively. Other consequences, such as safety or confidentiality, require their own defined criteria. The numbers support prioritisation; they are not probabilities or financial-loss estimates.

The outage likelihood remains unchanged because the treatments improve the consultancy's fallback, not the supplier's reliability. The lower target impact is conditional on a successful exercise. A future target must never be presented as today's achieved position.

In a product demonstration, create this record, assign both actions and attach the failed result. Change one deadline and inspect the history. The selection test is whether another reviewer can reconstruct the decision and outstanding work without a separate email explanation.

Section 05

Check acceptance, expiry and review

Some risks will be accepted. The register should help distinguish a formal decision by an authorised person from a treatment action that simply ran out of time. Look for a decision reason, approval history, review date and any conditions attached to acceptance.

Ask what happens when a review is overdue or the accepted conditions change. Can a supplier incident bring the risk back for attention? Can an owner be replaced without losing earlier decisions? Are overdue actions visible separately from high risk scores?

These details matter because a low-scoring risk with no active owner can be less well managed than a high-scoring risk with funded treatment and explicit oversight.

Section 06

Budget for migration and operation

Include the licence, setup, data cleaning, training, integrations and reporting effort. Request an export sample before signing. A CSV containing only the headline risk fields may omit the attachments, action history and decisions that made the system valuable.

Pilot with a representative set of records: an accepted risk, an overdue treatment, a supplier dependency and a risk linked to an incident. Agree which existing spreadsheet becomes read-only and when. Running two editable registers indefinitely creates competing versions of the truth.

Preserve original risk IDs, reconcile imported counts and sample owners, treatments and attachments before cutover. Keep the previous register read-only with a named archive owner.

Section 07

Where Fig Group fits

Fig Group connects risk records with operational context such as assets, suppliers, incidents and policies. Its risk-action workflow records owners, due dates and an audit history. That makes it relevant when you want the register to support ongoing work as well as reporting.

Use a demonstration to examine your own acceptance rules, review cadence and evidence needs. Ask which functions and integrations are available for your proposed package. For an MSP, also explore how customer permissions affect portfolio visibility through Fig Group risk management for MSPs.

Section 08

A practical selection checklist

  • Can an owner understand the risk without decoding internal shorthand?
  • Can one risk have several independently owned treatments?
  • Can you distinguish completed work from verified risk reduction?
  • Can reviewers see earlier decisions and the evidence used?
  • Can the system expose overdue reviews and expiring acceptance?
  • Can you export the relationships and history you need?

Choose the least complicated approach that reliably supports those decisions. If your current register depends on one person remembering every deadline, that is a concrete requirement to bring to a Fig Group demonstration.

About the author

Fig Group

Security, risk and compliance guidance

Practical buying guides and workflow explainers from Fig Group. Our articles connect software selection with the responsibilities, decisions and evidence involved in running security and compliance programmes.