Unlogged risks stay outside the process
Incident reviews often uncover a risk that someone had already noticed. Someone mentioned it in a hallway, an email thread, or a meeting that ran long. Then it never made it into a governed system. No entry, no score, no owner.
A risk register records what the organization captured, not everything that could go wrong. The risks already owned, scored, and reviewed are visible. The ones that never made it into the register can still blindside you.
Many registers document known risks and omit risks that people noticed but never logged. You cannot see or measure that exposure, let alone explain why nobody acted.
Improve risk intake before adding more analysis
A team can analyze registered risks well and still miss material risks at intake. Heat maps, scoring models, and quarterly reviews cover the risks already on the list.
Capture fails for ordinary reasons. The risk surfaced outside the register, the person who noticed it did not own the register, or everyone assumed somebody else had logged it. The risk stays in a chat, slide, or inbox where the governance process cannot reach it.
Improve intake so the rest of the risk process works from a more complete record.
Scattered registers hide the combined view
A risk logged in a place nobody governs is barely logged at all. Many organizations have a spreadsheet per team, a tracker per project, and a list in someone's notes. Each looks reasonable on its own. Together they make it hard to know whether the combined view is complete.
PwC's Global Risk Survey 2023, based on 3,910 business and risk leaders across 67 territories, identified a top-performing 5% of organizations as Risk Pioneers. PwC describes that group as underpinned by strategic enterprise-wide resilience and a human-led, tech-powered approach. Connecting risk signals across the enterprise makes that resilience easier than leaving them in isolated pockets.
When risk data is scattered, you cannot answer simple questions without a hunt. What is our top exposure this quarter? Who owns it? Has anything changed? Which control, audit finding, supplier issue, or regulatory change created it? A single governed risk register makes those answers a lookup.
Capture risk signals from operational work
Feed the risk register from operational work. Candidate risks can come from contract exceptions, regulatory changes, assessment gaps, incidents, audit findings, vendor reviews, and policy deviations. Each entry should preserve the source that created it.
The contract with an unusual liability cap, the new rule that changes a control, and the failed assessment item can reach an owner without waiting for a quarterly workshop. People still decide materiality. This matters for regulated work too: DORA governs ICT risk, incidents, testing, and ICT third-party dependencies, while NIS2 assigns cybersecurity risk-management responsibilities to management bodies.
Risk frameworks depend on complete intake
The frameworks already assume the risk has been identified before the rest of the process can work. ISO 31000 provides general risk-management guidance. COSO ERM's Performance component includes identifying risks that affect strategy and business objectives, assessing severity, prioritizing risks, selecting responses, and developing a portfolio view. ISO/IEC 27005 makes the information-security version concrete: identify and describe risks, identify risk owners, analyze and evaluate risks, prioritize them for treatment, and document risk assessment and treatment results.
That logic is not subtle. You cannot evaluate a risk you never named. You cannot treat one you never recorded. You cannot report on one that lives only in someone's memory. ISO/IEC 27001 certification work depends on this because risk assessment, risk treatment, control selection, and the Statement of Applicability need traceable inputs. NIST CSF 2.0 points the same direction from a governance angle: identify assets, risks, roles, responsibilities, and improvement actions before pretending the program is managed.
The frameworks are not the problem. The intake is. If risks are landing in scattered channels instead of one governed register, you have a serious process running on incomplete input. Garbage in, confident out.
One governed source of truth for material risk
Close capture gaps by giving every material risk one obvious place to land. Logging should be easier than leaving the risk in a chat, slide, or inbox.
Sorena SSOT, our Single Source of Truth, keeps risks, controls, policies, and evidence in one governed store instead of a dozen spreadsheets. A risk noticed anywhere in the business can go to the same place, get an owner and a score, and stay visible to everyone who should see it. Nothing depends on the right person copying the right cell into the right tab.
The Sorena risk management workspace uses that store to govern each risk. Every entry carries its owner, status, history, and links to the controls and evidence that address it. Changes are recorded, so the register stays current without relying on memory.
A complete register is also an audit-ready one
Consistent capture also supports the audit trail. One governed register can record who logged the risk, when, who owns it, what treatment was chosen, and what changed.
A scattered model requires the team to reconstruct that history from memory and email. The work is slow and error-prone. A single governed register removes the reconstruction step.
Humans decide what matters, how to treat it, and how much risk to accept. The system records the risk, tracks it, and keeps the evidence trail so those decisions rest on a more complete picture.
Record material risks as soon as they surface
Give every material risk one governed place to land as soon as someone notices it. Record the source, assign an owner, score it, and keep the history so the team can decide how to treat it.
Frequently asked questions
Why do risks that cause incidents so often turn out to be already known?+
Because knowing about a risk and capturing it are different things. Someone may notice the risk, mention it once, and never log it in a governed place. Without an entry, it is never scored, owned, or tracked, so nobody acts. The failure is often capture, not intelligence.
Isn't a mature risk framework like ISO 31000 or COSO ERM enough to catch this?+
Only if intake works. ISO 31000, COSO ERM, and [ISO/IEC 27005](/artifacts/global/iso-27005) all depend on identified risks before assessment, prioritization, treatment, monitoring, and reporting can work. If risks are scattered across spreadsheets and chats instead of one governed register, you have a sophisticated process running on incomplete input. Fixing capture is what makes the framework deliver.
How does a single source of truth reduce unlogged risk?+
It gives material risks one obvious place to land, so logging is easier than not logging. In Sorena SSOT, risks, controls, policies, and evidence live in one governed store with owners, scores, and a recorded history. A risk noticed anywhere in the business can go to the same place and stay visible to everyone who should see it.
Sources
- PwC, Global Risk Survey 2023 (3,910 leaders across 67 territories)https://www.pwc.com/gx/en/issues/risk-regulation/global-risk-survey.html?ref=sorena.io
- ISO 31000, Risk management guidelineshttps://www.iso.org/iso-31000-risk-management.html?ref=sorena.io
- ISO/IEC 27005:2022, Information security risk managementhttps://www.iso.org/standard/75281.html?ref=sorena.io
- COSO, Enterprise Risk Management: Integrating with Strategy and Performancehttps://www.coso.org/guidance-erm?ref=sorena.io


