Free kit
Enterprise Risk Register Template (ISO 31000)
An editable enterprise risk register with example 5 × 5 scales, rating bands and a treatment plan, plus a risk appetite statement template — built around the ISO 31000 process.
An editable enterprise risk register built around the risk management process in ISO 31000:2018, with a companion template for the risk appetite statement that tells people how much risk is acceptable. Everything is laid out so that a risk is described properly, scored against criteria agreed in advance, given one owner and followed through to treatment and review.
What is inside
Enterprise Risk Register — guidance on the process and on writing a risk, example 5 × 5 likelihood and consequence scales, rating bands, a risk register with two worked examples (one strategic, one operational) and a risk treatment plan.
Risk Appetite Statement Template — a statement summary, appetite level definitions, an appetite-by-category grid covering six risk categories with wording to edit, escalation thresholds and a 10-point checklist for a sound statement.
Both documents as a designed, print-ready PDF and as an editable Word file.
Who it is for
Risk managers, quality and compliance managers, company secretaries, internal auditors, consultants and business owners who need a structured register — whether you are starting enterprise risk management from nothing or tidying up a spreadsheet that has grown without rules.
How to use it
Start with the criteria, not the risks: adapt the scales and bands, agree the appetite statement with top management, and only then run workshops to identify and score risks. Describe each risk as cause, event and consequence, link it to an objective and give it one owner. Treat what falls outside your criteria, and review the register at a set interval and whenever things change.
ISO 31000 is a guideline. It is not a certifiable standard, it does not prescribe a 5 × 5 matrix or any other scoring scheme, and using this template does not make an organisation compliant with anything. The scales, bands and example wording are starting points for you to adapt.
What is in the kit
- Enterprise Risk Register (PDF)Process guidance, example 5 × 5 likelihood and consequence scales, rating bands, a risk register with two worked examples and a treatment plan.706 KB
- Risk Appetite Statement Template (PDF)Statement summary, appetite level definitions, appetite by category with wording to edit, escalation thresholds and a 10-point checklist.738 KB
- Enterprise Risk Register (editable Word)The same document in Word, so you can adapt it and fill it in on screen.31 KB
- Risk Appetite Statement Template (editable Word)The same document in Word, so you can adapt it and fill it in on screen.31 KB
A look inside
The first pages of Enterprise Risk Register (PDF). The full document downloads from the list above.
Next step
Learn to use it properly — with a certificate
The documents tell you what to check. These courses teach you how to audit and implement it, online and at your own pace.
Questions people ask
Is the Enterprise Risk Register Template (ISO 31000) really free?
Yes. There is no payment and no trial. Tell us your name, work email and company once, and every document in the Free Zone is yours to download.
What format are the documents in?
This kit has 4 documents in PDF and DOCX format. The Word, Excel or PowerPoint files are fully editable, so you can adapt them to your organisation.
Can I use it inside my company?
Yes. The licence covers one organisation with unlimited internal use — print it, share it with colleagues and adapt it. Please do not resell it or republish it as your own.
Does this make us compliant with ISO 31000?
No document can do that on its own. It is a practical working tool to help you prepare, check and improve. Conformity with ISO 31000 is decided by an audit of your actual system, and the standard itself remains the authoritative text.
Do you offer training on this topic?
Yes. Skedmia runs online courses with certificates on the standards and topics these kits cover — the matching courses are listed on this page.
More from the Free Zone
FreeNewEditableCyber Security Risk Mitigation Checklist
80 controls in 10 risk areas, each with the reason it matters — plus a 5 × 5 cyber risk register template.
FreeNewEditableAWS Security Checklist
90 checks to review an AWS account — root user, IAM, network, S3 and databases, encryption, logging, detection and recovery.
FreeNewEditableIT Security Audit Checklist
120 audit checks across 12 control areas, plus an audit plan and findings log — ready for your next internal IT audit.


