Overview
A risk register is a central record used by institutions to document identified risks, assess their likelihood and impact, assign ownership, record mitigating controls, and track review dates and actions. For theological institutions this supports student protection, academic quality, governance and continuity of ministry activities.
This template is purposefully simple so boards, senior leaders and quality teams can adopt and maintain it as part of routine risk management and internal audit cycles.
How to use this template
- Identify risks: Gather inputs from governance, academic leaders, finance, student services and compliance. Consider strategic, operational, financial, reputational, regulatory and student-safety risks.
- Describe clearly: Write a concise risk statement describing cause, event and consequence.
- Assess: Score likelihood and impact using a simple 1–5 scale to create a priority score.
- Assign ownership: Allocate an owner responsible for mitigation, monitoring and reporting.
- Record controls: Note existing mitigations, additional actions required, deadlines and resources.
- Review cycle: Schedule periodic reviews (quarterly or biannually) and update status and residual risk.
Risk register columns (recommended)
- Risk ID — unique reference.
- Risk category — e.g., academic, student welfare, financial, IT, compliance, reputational.
- Risk statement — concise description of potential event and consequence.
- Likelihood (1–5) and Impact (1–5).
- Risk score — likelihood × impact.
- Existing controls — what reduces likelihood or impact now.
- Additional actions required — owner, due date and resource notes.
- Residual risk rating — post-mitigation assessment.
- Status and next review date.
Prioritisation and reporting
Use the risk score to prioritise actions. High-scoring risks should be reported to the governing body with an action plan and timeline. Medium risks require active monitoring and delegated management. Low risks should be recorded and reviewed periodically.
Embed the register within governance papers and internal audit to ensure oversight, and link specific risks to the institution's strategic objectives and student-protection arrangements.
Example risk entries (brief)
- Academic continuity: prolonged staff shortage leading to missed teaching — likelihood 3 × impact 4 = 12. Controls: interim staffing plan; cross-training; contingency delivery via online modules. Owner: Academic Dean.
- Student welfare: insufficient safeguarding training — likelihood 2 × impact 5 = 10. Controls: mandatory annual safeguarding training; student reporting process. Owner: Student Services.
Integration with quality systems
The risk register is most effective when integrated with the institution's quality assurance, policies, programme reviews and incident reporting. Link risk actions to policy reviews, staff development and budget planning so risk mitigation is resourced and measurable.
Retention, confidentiality and publication
Maintain the register as an internal governance record. Sensitive entries (e.g., individual safeguarding incidents or legal disputes) must be redacted before any wider circulation. Publish a redacted high-level risk summary in governance reports to demonstrate oversight to stakeholders and accrediting bodies.
Template download and practical notes
The downloadable template provided with this resource uses the columns above and includes an instruction sheet for owners and reviewers. Tailor categories and scoring thresholds to your institution’s size, delivery mode and regulatory environment.
Frequently asked questions
How often should the register be reviewed?
At minimum quarterly for high and medium risks; annually for low risks.
Who should own the register?
The governing body has oversight; day-to-day maintenance typically sits with the Quality or Compliance lead and senior management team.
A risk register replaces institutional policies or governance.
A risk register records and informs governance actions; it does not replace formal policies, statutory obligations, or delegated governance responsibilities.
Publishing a register exposes all details publicly.
Publish only a redacted, high-level summary. Sensitive operational or personal data must remain confidential.
ITAA’s Role
ITAA provides independent, non-governmental theological accreditation and guidance on good practice; it does not replace local legal, regulatory or licensing obligations. Institutions remain responsible for compliance with all applicable laws and for maintaining accurate public statements about their authorisations and awards. For full legal and accreditation disclaimers see the Important Accreditation Information link below.
