Skip to content

People risk register

A people risk register records the organisational risks to a plan in the same form as any other risk: what could happen, its likelihood and impact, who owns it, what mitigation exists and when it will be reviewed. Most corporate registers cover financial, operational and regulatory risk and treat this category as a footnote.

A risk register is the standard instrument of corporate risk management, and the organisation is the risk class it usually omits.

Why it matters when the plan changes

Risks that are not on a register are not reviewed, do not have owners and do not receive mitigation budget. Putting organisational exposure into the same format as every other risk class, the format governance codes already assign to the board under audit, risk and internal control, is what makes it governable: it becomes a line with a name against it rather than a concern someone raises occasionally.

The tension is that people risks resist the format. Likelihood and impact are hard to quantify, the mitigation is often a difficult conversation rather than a control, and naming a risk that involves a named individual raises real confidentiality questions. An honest register would mark such exposure blind rather than green, since a system that can say it cannot see something is the only kind that can honestly claim clear sight elsewhere. Those difficulties explain why the category is skipped; none of them makes the exposure smaller.

In practice

A board reviews a register of thirty risks covering currency, supply, cyber and regulatory exposure. The plan's largest dependency is a single commercial director who holds four key relationships personally. It appears nowhere, because nobody could decide how to write it down without naming him.

Evidence

What it cannot tell you

A people risk register only tells you what has been named. It cannot detect the risks that are too politically sensitive to write down, and putting a risk into likelihood-and-impact terms does not by itself supply a plausible way to measure or mitigate it. Absence from the register is not evidence of absence of exposure.

Questions

A people risk register, like any risk register, Wikipedia (2026) notes, records identified risks, their assessment and their treatment. On the people list: decisions with no owner, dependencies with no sequence, roles whose demands outgrew their mandate, concentrations in one person, and capacity exhausted by competing changes.

By describing the arrangement rather than the individual: this decision rests on one role with no alternative, or this plan depends on a relationship held in one place. That is accurate, actionable and avoids turning a governance document into a personnel file.

They resist quantification, their mitigations are conversations rather than controls, and writing them down feels like writing about individuals. Each is a real difficulty. None reduces the exposure, and the absence means the largest risks to many plans are never formally reviewed.

The same body that owns every risk class. The UK Corporate Governance Code (2024), issued by the Financial Reporting Council, places audit, risk and internal control with the board. Placing a people risk register with HR instead removes it from the forum where risk appetite and mitigation budget are decided.

On the same cycle as other risk categories, and additionally whenever the plan materially changes what the organisation has to do. A register reviewed only annually describes a set of exposures that a single operating-model change is capable of making entirely obsolete.