Risk Register Accuracy
Ninety-Three Entries. Zero Closed in Eighteen Months. Not a Risk Picture. An Archive.
6 min read · 4 July 2026 · Compliance
A technology company's vendor risk register had grown substantially over three years of TPRM programme maturation. Each assessment cycle added findings to the register. The register showed all findings in one of three states: open (remediation not started), in remediation (vendor has acknowledged and begun addressing), or accepted (formally accepted with business owner sign-off). During a governance review, the CISO asked for the current high-priority open items requiring immediate attention. The risk team filtered the register to high-priority open items: forty-seven entries. Asked how many of those had been on the register for more than six months, the answer was thirty-one. More than twelve months: nineteen. More than eighteen months: eleven. Asked how many had been closed , fully remediated and removed from the register , in the last twelve months, the answer was zero. The register had never had a closing process. Items were added when assessments found issues. Items were updated when vendors reported remediation progress. Items were accepted when business owners signed off. Nothing had ever been formally closed and removed. The register accurately documented every finding that had ever been added since the programme started. It did not accurately represent the current vendor risk landscape.
What is the Risk Register Accuracy Problem, Really?
A risk register is the authoritative inventory of identified risks that are currently being managed , the active risk landscape that governance processes use to prioritise remediation, allocate resources, and report to leadership. Risk register accuracy is the degree to which the register reflects the current risk environment rather than the historical record of all risks ever identified. An accurate risk register grows when new risks are identified and shrinks when risks are remediated, accepted with appropriate review, or overtaken by circumstances that have changed the risk profile. A register that only grows is not accurately maintaining the current risk picture , it is accumulating findings without validating their continued relevance.
The closure process gap is the structural failure that produces registers that grow without shrinking. Risk registers have well-defined addition processes , assessment findings are documented, categorised, and added through defined workflows. Most risk registers have poorly defined or entirely absent closure processes , the criteria for confirming a risk is remediated and removing it from the active register, the evidence required for closure confirmation, and the governance approval required before a finding is closed. Without a defined closure process, findings accumulate indefinitely regardless of whether the underlying risk has been addressed.
The status inflation problem is the second accuracy failure mode. Findings that have been in 'in remediation' status for six, twelve, or eighteen months without verified progress have either genuinely stalled or are being reported as in progress without meaningful advancement. In either case, the 'in remediation' status provides a misleading picture , it implies active remediation is occurring while the finding has actually become a long-term acceptance disguised as ongoing work. Genuine 'in remediation' status requires periodic validation that remediation is progressing, not just that the vendor has acknowledged the finding.
- No closure process , findings added without a defined process for removing them when remediated
- Status inflation , findings in 'in remediation' status for extended periods without verified progress
- Historical archive confusion , register mixing current active risks with remediated, stale, and overtaken entries
- No evidence-based closure , vendors reporting remediation without evidence verification before closure
- Register size obscuring priority , growing entry count making genuinely current high-priority items harder to identify
Why this matters
Risk register accuracy matters for TPRM because the register is the primary tool for governance decision-making , prioritising remediation resources, monitoring high-risk items, and reporting current risk to leadership. A register that mixes current active risks with stale entries and status-inflated findings produces governance decisions based on an inaccurate risk picture. Leadership who review a register with forty-seven high-priority open items may be appropriately alarmed , but if nineteen of those items have been open for more than a year and eleven for more than eighteen months, the alarm is partially justified and partially a consequence of register accumulation rather than active high-priority risk.
The remediation SLA accountability gap is the direct operational consequence. When findings in the risk register have no SLA for remediation and no defined consequences for prolonged open status, the register becomes a repository where findings accumulate without governance pressure to address them. A vendor who acknowledges a finding and enters 'in remediation' status has met their minimum governance obligation , they can remain in that status indefinitely without a defined accountability mechanism that escalates when remediation timelines are not met.
Where most teams get this wrong
The most consistent failure is not designing a closure process when the risk register is established. Addition processes are designed at programme inception. Closure processes are discovered to be missing months or years later when the register has grown to a size that obscures its utility as a current risk picture.
- No closure process designed when register was established
- Evidence-based closure not required , vendor self-reporting accepted for status updates
- No SLA for remediation , findings open indefinitely without escalation
- Status updates accepted without progress validation
- Register review not including current-relevance assessment
What good looks like
Mature risk register programmes define closure criteria at programme inception , what evidence is required to close a finding, who approves closure, and how often in-remediation findings are validated for genuine progress.
- Defined closure criteria , what evidence is required and who approves before a finding is removed
- Remediation SLAs , maximum time in remediation before escalation
- Periodic in-remediation validation , evidence of progress required at defined intervals for findings in remediation
- Current-relevance review , periodic review of aged findings to determine whether the underlying risk is still current
- Register hygiene metrics , tracking open duration, closure rate, and remediation SLA performance
Tooling
GRC Platforms , ServiceNow GRC, Archer, MetricStream
GRC platforms with risk register management capabilities support closure workflows , defining evidence requirements, routing closure approvals, and tracking remediation SLA performance. For TPRM practitioners, asking whether the vendor's GRC platform enforces evidence-based closure with governance approval provides a specific register accuracy question.
TPRM Platforms with Remediation Tracking , ProcessUnity, Prevalent
TPRM platforms with remediation tracking features monitor vendor remediation progress , flagging findings that have not advanced beyond initial acknowledgment and escalating findings that have exceeded remediation SLAs. For TPRM practitioners, using TPRM platform remediation tracking rather than manual register updates provides automated SLA monitoring and escalation.
Governance challenges
The governance challenge with risk register accuracy is the closure evidence investment. Closing a finding requires evidence that the underlying risk has been addressed , which requires either accepting vendor self-reporting (low evidence quality) or conducting verification (higher evidence quality but resource intensive). The balance between closure evidence requirements and closure process efficiency determines whether the closure process is used or bypassed.
- Define closure criteria and evidence requirements now , if not already defined
- Set remediation SLAs for all open findings , maximum time in each status before escalation
- Require evidence-based closure , vendor evidence of remediation reviewed before closure
- Conduct periodic register reviews for current-relevance , aged findings assessed for continued applicability
- Track closure rate as a programme health metric alongside finding addition rate
If you are a small team
Filter your risk register to findings that have been in any status for more than twelve months. For each one, ask two questions: is the underlying risk still relevant today , has anything changed that has addressed or transformed the risk? And for findings in remediation: what evidence has been received that remediation is genuinely progressing? Those two questions will separate genuinely current open risks from register accumulation. The findings that survive both questions are the ones that genuinely require current governance attention.
- Filter register to findings older than twelve months and assess current relevance
- Request evidence for all in-remediation findings older than six months
- Define closure criteria and implement a closure process
- Set remediation SLAs for all open findings
What to require
Ask directly:
"For findings that have been in remediation status for more than six months, can you provide evidence of remediation progress , specifically, what has been completed since the finding was acknowledged and what remains to be done with a target completion date?"
Expect as evidence
- Evidence of completed remediation steps for long-duration findings
- Remaining remediation steps with target completion dates
- Root cause for delay if remediation is behind schedule
- Escalation acknowledgment if remediation has stalled
A vendor with findings in remediation status for more than six months should be asked for progress evidence and a completion timeline. 'In remediation' describes a status. The evidence describes whether the status is accurate.
How to evidence it
- Register closure process documentation
- Remediation SLA tracking records
- Evidence-based closure records
- Aged finding current-relevance review records
Key Takeaway
A risk register that grows without shrinking is an archive, not a risk picture. Ninety-three entries added over three years with zero closures reflects a programme that has consistently identified risks and consistently failed to complete the governance cycle that starts with identification and ends with verified remediation and formal closure. The addition process works. The closure process does not exist. A current risk picture requires both , findings added when identified and removed when remediated with evidence. The findings that are genuinely current open risks deserve governance attention. The findings that have been in remediation for eighteen months deserve either escalation or honest reclassification. Design the closure process now.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association