A risk register earns its place only if somebody makes decisions from it. Most do not, for predictable reasons.
Write risks as sentences
A risk is not "phishing". It is a sentence with a cause, an event and a consequence: an employee enters credentials on a phishing page, an attacker signs in to the finance system and initiates payments, costing up to £X before detection. Written this way, the controls and the owner become obvious.
Score for comparison, not precision
Likelihood and impact scales are a way of ranking things against each other. Treat a score as an argument, record the reasoning, and re-score when the reasoning changes. Multiplying two invented numbers to three decimal places does not add rigour.
Give every risk an owner who can act
The owner is the person who can accept the risk or fund the fix — a business owner, not the security team. Security maintains the register; it does not own the risks.
Treatment is a decision with a date
Each risk ends in one of four places: treat, transfer, tolerate or terminate. Tolerating is a legitimate answer when recorded, signed and given a review date. An untreated risk with no decision is just a note.
Keep it small
Fifty live risks is a programme. Five hundred is a filing system. Aggregate the detail into themes and keep the register to what leadership can genuinely consider.