Why a risk register is the right first artifact
The risk register is the most-requested artifact in an entry-level analyst portfolio because it forces the four skills an interviewer will grade you on in a single sheet: scoring a risk on a defensible scale, naming a control in the language the framework uses, attaching evidence that is findable later, and assigning an owner who can actually be emailed. Most candidates describe these skills in a cover letter; this artifact shows them. Aim for 8 to 10 rows for a fictional mid-sized SaaS company with one in-flight audit (SOC 2 Type II). Anything thinner looks unfinished; anything over fifteen starts to look padded.
Pick the fictional company deliberately. Two hundred employees, two regulated products — one US healthcare-adjacent, one payments-adjacent — and one new vendor with a security questionnaire in flight. That mix forces a couple of inherently cross-functional risks (vendor concentration, data residency) where the author has to make a judgment call the manager will ask about. A real-world register for a five-thousand-person enterprise is the wrong starting artifact: the control stack is too long and the scoring turns into copy-paste that does not show your thinking.
Row by row: what each cell should hold
- Risk title — one short noun phrase the security team already uses. 'Vendor concentration: payments processor' beats 'Processorpayment third-party dependency review'. If the title needs a full sentence to make sense, it is too vague.
- Risk description — two sentences. One for the scenario (the trigger), one for the impact (the consequence). If either sentence needs more than twenty-five words, the scenario has not been identified yet.
- Inherent likelihood (1–5) and inherent impact (1–5) — the score before any control is applied. Be conservative; reviewers test whether inherent scores reflect a worst-case-credible scenario rather than a modal one. An inherent of 4×4 = 16 is the threshold for a top-tier risk worth a separate remediation line.
- Control(s) referenced — name the control using the same wording as the framework you have chosen. Cite the NIST CSF 2.0 subcategory ID (e.g. PR.AC-1), the ISO 27001 Annex A control (e.g. A.5.15), or the SOC 2 common criterion. Free-form control names cannot be traced to evidence later.
- Residual likelihood and residual impact — the score after the control is applied. The delta between inherent and residual is the value the register delivers; if your delta is zero across most rows, the control mapping is decorative.
- Owner — a job title, not a person. Head of Platform Engineering beats Marcus from Infra, because an org change should not invalidate the risk. The owner field is also the routing key for the next quarter’s remediation review.
What surfaces in the review
The review pass is where most first drafts fall apart. A senior reviewer will mark any row that reads 'likelihood: medium, impact: high' as decorative — there is no scale behind it. They will mark any row whose residual equals its inherent as possibly invented. And they will mark any row that lists a control without a framework reference as untraceable to evidence during audit prep. The point of those marks is not pedantry: each one corresponds to a question a real auditor will ask during fieldwork, and the answer has to be findable in the register itself.
Two judgment calls come up in every register that a junior author will get asked about. The first is whether to score likelihood on a calendar-year window or on a sustained-traffic window — pick the latter and document the choice; calendar scores produce fake precision. The second is whether risks owned by a different team (legal, IT ops, the CFO’s organization) belong on your register at all — the answer is yes, but mark them as 'shared ownership' and route the draft through that team's lead before circulating. Both moves signal the cross-functional awareness that flags an analyst ready for promotion.
Next steps
- Open the framework primer at /courses/nist-csf-2-quickstart if you are scoring against NIST CSF 2.0 — the subcategory IDs you cite in the controls column need to match the published taxonomy.
- Read the ISO 27001 walkthrough at /courses/iso-27001 for the risk-scoring scale most risk councils actually apply; the Annex A control names are the ones auditors will recognize during spot-checks.
- Compare your draft against the published CSF guide at /guides/nist-csf-2-quickstart — the guide walks a fictional environment of the same shape the artifact is meant to model.
- Use the roadmap at /roadmap to layer the risk register into a portfolio alongside a vendor review and a single gap analysis once you have a draft you would defend in a review meeting.