A practical framework for CEOs and general managers of not for profit organisation
Introduction
Leaders of not-for-profit (NFP) organisations recognise the importance of risk management.
However, for many organisations the document that should be the main resource for risk management and the single-source-of-truth, has become so unwieldy that it is now part of the problem rather than a useful tool.
The document we are referring to is the risk register.
The register should be a useful resource for prioritising and reporting on risks and developing strategies and plans informed by risk.
Unfortunately, in many organisations risk registers have become so cluttered with duplicated information that no one really wants to look at them. This makes it difficult to clearly understand the current state of risk.
The register becomes so cluttered that organising it feels overwhelming. You know there is useful data in there, somewhere, but how do you find it? Where do you start?
Understanding risk management concepts makes this task easier than it might seem.
Simplifying risk registers by focusing only on true risks, instead of a repetitive list of risk, related issues, makes the register more concise and easier to use. Additionally, this process of simplifying teaches the team about risk fundamentals, giving them the confidence to manage risk more effectively in the future using their own resources.
Focusing only on true risks can reduce the size of the risk register by 50 to 70%. The register becomes clearer, more usable and more aligned with the ISO 31000 risk management standard that Boards, regulators and insurers expect.
This paper outlines a proven, practical approach to streamlining risk registers and at the same time, upskilling your team in risk management.
The problem: when risk registers become a dumping ground for risk information
In many NFP organisations, the risk register has evolved into a repository where everything related to “risk” is recorded.
Sometimes this is an unintended consequence of team consultation, a feeling that everyone’s issue must be given the status of being its own risk.
But perhaps the main reason is a lack of understanding of how risk is defined under the professional standard ISO 31000.
This leads to risk registers not only including actual risks, but also various causes of risks, risk consequences and risk related issues.
The result is a risk register that is too long, repetitive and confusing, primarily because risk management terms that are different are used interchangeably.

Information clutter and overlap
When a risk register becomes a dumping ground for risk information the consequences are significant:
- Boards and executives lack a clear, consolidated view of organisational risk;
- Teams disengage from risk management;
- Critical and/or emerging risks may be obscured or overlooked; and
- Opportunities are missed to use risk management analysis to inform business improvements and innovation.
What a streamlined risk register does for your organisation
NFP leaders should aim for a risk register that supports using risk management as it was intended under ISO 31000: that is, to inform better decisions and improve the achievement of objectives, not just to avoid problems.
A practical framework for streamlining risk registers
Boards, managers and team members typically want more clarity regarding risks, but how to achieve this is not always apparent, particularly as people are busy and there can be a lack of access to professional education and training around risk management principles.
We recommend an approach that starts with considering what risk really is, then applying this insight to streamline the risk register. Involving teams in the register improvement process also contributes towards upskilling the team.
Re-define what counts as a risk
Without being too theoretical, the foundation of this approach is aligning with the ISO 31000 definition of risk, where risk is defined as ‘the effect of uncertainty on objectives’.
This means:
- Risk = the possibility that objectives might not be achieved
- Causes = why a risk might occur
- Events = what might happen – the point at which the risk turns from a possibility to a real impact
- Consequences = what happens if the risk occurs
Most risk registers unintentionally blend these risk management terms together, whereas separating these will reduce duplication and improve clarity.
Consolidate and de-clutter
When definitions are clear, risks can be systematically reviewed and consolidated.
Typically, this process reveals that:
- Multiple “risks” are different aspects of the same issue; and
- Multiple entries can be merged into a smaller number of well-defined risks.
The output is a significantly shorter, more focused risk register that highlights the key risks related to the organisation’s purpose and responsibilities.
Build internal capability
The process of improving risk registers in this way not only produces an improved risk management resource but also builds organisational capability through hands-on experience in applying risk management concepts.

Case study: Growing Pains

Community Services Organisation (Perth)
This case study is an amalgam of several NFPs we have assisted.
A Perth-based NFP had a risk register that had expanded significantly over time as the organisation grew in scale. Over a period of ten years the organisation had been successful in attracting new funding, expanding the range of services and increasing the size of the team.
As the organisation grew, information was progressively added to the risk register to address the increasing complexity of operations. Eventually, there was so much data in the risk register (and so much duplication) that it was difficult to achieve a single, clear view of the organisation’s risks, which is the purpose of the risk register.
This caused challenges across the organisation. It had become difficult to report to the Board on organisational level risks, and difficult for managers to assess operational risks at a team level.
This is a classic example of organisations becoming victims of their own success: operations expand but the governance does not keep up.
To address this, Horizon Point worked with the organisation’s leadership group to provide training to management on the concepts underpinning risk management, as reflected in a risk register. The training provided the basis for a short workshop where the risk register was consolidated and the number of risks reduced by approximately 50%. This was achieved through removing items which were better defined as causes, consequences, or events.
By focusing on a smaller number of risks that were significant to the organisation’s purpose, the duplication and confusion was resolved. The register became a useful tool at a strategic (e.g. informing the CEO or preparing Board reports) and operational level.
Why this approach works: the signal and the noise
In engineering there is the concept of ‘signal and noise’. The signal is the useful information a system generates – useful, for example, because it indicates whether a machine is running well, or running into trouble. The noise is all the distracting information around the signal, that makes it harder to notice the signal. This concept inspired the title of the best-selling book The Signal and the Noise (2012) by the political forecaster Nate Silver. The concept reminds us that the data alone cannot tell us what might happen, instead we need to identify what is important in a mass of information.
In this spirit, if you can clarify and simplify your organisation’s risk register then there is less noise, and the important signals about risk can be more clearly heard.
Simplification of risk registers is a de-cluttering exercise with strategic impact:
- It removes “noise” so decision-makers can see the real risks;
- It aligns practice with recognised standards (ISO 31000);
- Organisations have improved information resources (the risk register document) and a team with more confidence in applying risk management to operations and planning; and
- Organisations have a resource that assists with Board reporting, strategic planning, operational management and compliance.
Conclusion – a simplified risk register puts objectives in focus
Many leaders have experienced risk workshops that feel unproductive because there is competition to include every point people care about as its own risk. This can be a frustrating experience that stifles engagement and deters people from risk management. As a ‘cupboard’ that everything gets placed in, the longer this process goes on, the more the information clutter builds up, and the more off-putting the idea of improving the risk register becomes.
In any organisation, the more it is understood that risk is about the effect of uncertainty on objectives, the easier it is to focus the risk register on the main issues. A streamlined risk register is one that focuses on objectives first, and the factors that can make achieving them uncertain, rather than a list of problems.
This process makes identifying the necessary risk controls, and the improvements needed on these controls easier. It achieves the objective of creating a risk register that provides a clear picture of the current state of risk, what is being done to manage the risk and whether the controls are sufficient or require improvements.
A risk register that identifies only true risks in IS0 31000 terms is one that, by definition, is focused on what matters for operations, for strategy and for compliance.
The process of streamlining your risk register creates not only a better risk management resource, but also a more informed and confident team, who understand risk management fundamentals, and have learnt a versatile risk management approach that can be applied to most challenges facing the organisation.
Interested in taking action?
If you’d like to streamline your risk register and make it into a strategic asset while developing your team’s capacity in risk management, please get in touch to schedule a call: [email protected]
About Horizon Point
Horizon Point is a specialist consulting firm providing risk and project management advisory and training services, to enable organisational change and business improvements
Horizon Point was founded in 2022 by former senior public servant and policy adviser, Andrew Lee, and the team includes a panel of experienced consultants.
Horizon Point is an approved risk management advisory contractor under the WA Government’s Audit and Financial Advisory Services Procurement Panel CUAAFA2024 (Category D – Risk Advisory Services)
Services:
- Risk management
- Training in risk management fundamental concepts, issues and methods
- Risk register improvements
- Implementation support to strengthen risk management maturity throughout the organisation
- Improving reporting e.g. Key Risk Indicators
- Reviewing strategy through a risk framework lens to integrate risk and strategy
- Project management
- Training in project management fundamental concepts, issues and methods
- Independent project risk assessment
- Advisory support at all stages: planning, business case development, delivery, stage reviews, close-out, benefits-realisation
- Improving project reporting to management and Boards
- Project implementation
- Operational model review and planning
- Reviewing operational models and recommending improvements
- Developing business plans and strategies
About Andrew Lee
Andrew has over twenty years’ leadership experience including seven years at Senior Executive Service level in the Department of Transport (WA). Prior to joining the public service, he was a Ministerial Adviser (State) and Shadow Ministerial Adviser (Commonwealth).
Since 2020, Andrew has worked as a management consultant, specialising in project and risk management. His core work has been in national transport regulatory reform projects and risk management advisory and training for government, NFPs and highly-regulated industries.

