A risk register cannot be both a truthful account of exposure and an input to individual appraisal, and almost no enterprise has decided which one it is — so the appraisal system, not the appetite statement, writes the organisation's real risk position.
Two instructions sit inside most enterprise risk frameworks. The first is that identifying a risk must never be used to evaluate the person who identified it; the register exists to surface exposure, not to apportion blame. The second is that managers who surface risk early and handle it well should be recognised for it — in performance reviews, in competency frameworks, in promotion criteria. Both are usually written down. Both are usually endorsed by the same executive committee, sometimes in the same governance paper. They cannot both be operating.
This is a genuine tension rather than a drafting error: a board wants both things and both are defensible. It wants an unflinching account of what could go wrong, and it wants risk discipline to matter enough that careers respond to it, since an obligation carrying no consequence is an obligation nobody meets. But the second want destroys the evidentiary value of the first: once register content can move a person's standing, every entry becomes a statement about its author as well as about the enterprise, and it is drafted accordingly.
The contradiction is not a local failure of one policy team. It is embedded in the material the discipline uses to train its practitioners, where the prohibition on using risk identification to evaluate individuals and the prescription to fold risk maturity into competency frameworks and promotion criteria sit as adjacent items of good practice, neither acknowledging the other. A contradiction surviving inside a field's own teaching indicates the field has never had the argument.
Most enterprises have not had it either. They hold an appetite statement, a register, a review cadence and an appraisal cycle, and no document states which purpose the register serves when the two collide. In the absence of that decision, the appraisal cycle decides, because it is the instrument with teeth. Whatever the appetite statement says the enterprise will carry, the real position is set by what a mid-level manager judges it is safe to write down about work they own.
The Strategic Context
The register has quietly become the load-bearing document of enterprise governance. Capital committees read it before releasing funds; insurers and lenders ask for it; boards use it to discharge oversight duties they cannot discharge by observation.
That is a great deal of weight for a document whose accuracy nobody has structurally protected. Financial statements are protected by separation of preparation from audit, by defined recognition rules, and by personal liability for misstatement. The register has none of that. It is prepared by the people whose performance it describes, reviewed by their line managers, and aggregated by a function reporting to the executive whose portfolio it summarises.
Consider a veterinary hospital group running general clinics alongside a few referral and emergency centres — hypothetical, but structurally ordinary for a multi-site professional service business. Its register carries entries on after-hours cover, controlled drug handling, imaging equipment obsolescence, clinical incident escalation and the retention of specialist surgeons. Each entry is drafted by the site principal it concerns, and each of those principals is also assessed on clinical governance quality and on whether their site is running well. The board reads the aggregated register as a portrait of the group. It is reading the aggregate of several dozen individual judgements about self-presentation.
What Leaders Commonly Misread
The first misreading is that the problem is cultural and can be fixed with reassurance. Executives who see the dynamic usually respond by stating that nobody will be penalised for raising a risk. The statement is sincere and almost always insufficient, because it addresses the wrong system: assurance about intent does not neutralise a structural incentive. Managers do not read the intent. They read the promotion decisions of the previous two years and infer the rule.
The second misreading is that the effect shows up as suppression — risks omitted entirely. Outright omission is conspicuous and rare. What happens instead is subtler and much harder to detect: the risk appears, stripped of the attributes that would make it consequential. Cause is recorded as external rather than internal, impact as a delay rather than a failure, ownership at a level senior enough to be diffuse. The entry is present, defensible and useless. A register full of such entries passes every completeness check an assurance function can apply while carrying almost no information about actual exposure.
The third misreading is that the dual use is a price worth paying, since risk work with no career consequence produces indifference. The trade is real — but it is made by default, and at the level of the individual entry, where the damage to honesty is greatest and where the same motivational effect is available from behaviours that do not distort the record.
Reframing the Issue
The productive reframing is to stop treating the register as one document with a culture problem and treat it as two instruments sharing a filename.
One instrument is evidentiary. Its function is to state, as accurately as the enterprise can manage, what threatens the achievement of objectives; its quality criterion is correspondence with reality, and it is valuable in proportion to how uncomfortable it is.
The other is evaluative. Its function is to support judgements about how well individuals exercise a professional discipline; its quality criterion is fairness and comparability, and it is valuable in proportion to how consistently it is applied.
These are not variations on a theme. Their failure modes are opposed: the evidentiary instrument fails when it is too flattering, the evaluative one when it is inconsistent. They require different governance, access rules and retention. An enterprise running both through one artefact has not integrated them; it has allowed the instrument with consequences attached to overwrite the one without.
How the Divided Register Rewrites the Enterprise Risk Position
The document the board believes it is reading
Boards read the register as a survey — an attempt at a complete account of material exposure, with judgement applied to severity. On that reading, an entry's absence means the threat was considered and dismissed; a mild rating means the enterprise assessed it as mild. Both inferences are unsafe in a register that feeds appraisal.
The document the author knows they are writing
The author is answering a different question. Not "what threatens the objective?" but "what can I say about my own area that is true, defensible, and will not be quoted back to me in a review?" That question has good answers. Risks originating outside the author's control are safe; so are risks already known to the executive, and risks whose materialisation would visibly be nobody's fault. Risks arising from a decision the author made, a capability their team lacks, or a supplier they selected are not. The filter is not dishonesty; it is rational conduct under an incentive the enterprise created and never examined.
Take a national museum and collections body, again hypothetical. Its most consequential exposures are slow: environmental control drift in offsite storage, undocumented provenance in older accessions, conservation backlogs, a digitisation programme scoped before the condition survey. Each implicates a curatorial or facilities leader who has held the portfolio for years. The register will readily carry funding uncertainty and loan-agreement risk; it will carry the storage and provenance entries in language no reviewer could act on.
Why the contradiction is never adjudicated
Nobody owns the question. The risk function owns the process, not the appraisal system. The people function owns the appraisal system and holds no view on register integrity. The audit committee reviews register content and never reviews what it is used for. Each party discharges its remit; the question falls between all of them. Nor will external assurance reliably catch it where a whole sector has adopted the same framework and trains its auditors on the same templates — that correlation belongs to [Related article: When an Industry Agrees on One Framework, It Goes Blind Together], and this article stops at the incompatibility inside a single enterprise's own document. Risk maturity assessment compounds the problem: a rating applied to a named manager converts a diagnostic of organisational capability into a personal grade — a conversion belonging to Article 26, which owns the question of who a maturity rating is for.
Two adjacent effects belong elsewhere. Where a risk leaves the register, its disappearance may reflect treatment or a moved threshold, and the record cannot distinguish them; this article does not trace those exits because [Related article: Treated, or Tolerated?] does. And once a risk is admitted, the decision to buy a control is made with no field for what the control costs — this article addresses only whether the exposure is stated truthfully, because the economics of treatment belong to [Related article: The Only Spend With No Business Case].
Decision Framework
The instrument is the register purpose declaration: a governing statement, adopted by the board or its audit committee, fixing what the register is for and what may be done with it. It is complete when it answers five questions in writing.
One: which instrument is this? The register is designated evidentiary or evaluative. There is no third option and no "both, with care". If evidentiary, the remaining four answers follow.
Two: what is the admissibility rule? State whether register content — entries, ratings, ownership, timing — may be cited in any performance review, promotion paper, remuneration decision or disciplinary process. An evidentiary register requires an unqualified no, extending to indirect use through derived summaries and dashboards.
Three: what does the enterprise reward instead? Removing register content from appraisal does not mean removing risk from appraisal. Assess process behaviours observable without reading the entries: whether reviews happened on cadence, treatment actions were completed, escalations were made within the required window, a post-event review was convened. These are verifiable, carry no incentive to understate exposure, and preserve the consequence the board wanted.
Four: who may see what? An evidentiary register needs an access rule keeping authorship out of the appraisal chain: aggregated for governance reading without attributing entries to named managers, with attribution retained inside the risk function for follow-up.
Five: what happens when the rule is breached? Name the consequence for citing register content in an appraisal, and name who adjudicates. A declaration with no enforcement is an appetite statement by another name.
Test it against evidence before adopting it: take the promotion and remuneration decisions of the past two cycles and ask whether any referenced register content, directly or through a derived report. If they did, the enterprise has been running an evaluative register while believing it held an evidentiary one, and the register's history should be read again on that basis.
From Strategy to Execution
Immediate. Determine which instrument you hold empirically rather than by policy. Ask the people function whether register content has entered any appraisal, calibration or promotion discussion in the past two cycles, and ask three or four managers separately, off the record, what they would not write in the register. The gap between those answers and the register is the size of the distortion.
Medium-term. Adopt the declaration and rebuild the appraisal linkage around observable process behaviours. Separate maturity assessment from individual assessment. Reissue the register template with authorship held by the risk function rather than shown in governance packs. Expect the register to worsen for two or three cycles as previously unsayable exposure surfaces; deterioration after the declaration is the sign it is working.
Long-term. Treat the declaration as a standing constraint on every adjacent system — the assurance plan, the incentive scheme, the delegation framework, the reporting stack. Each will, left alone, reattach consequence to register content, because attaching consequence is what management systems do. This is not a document adopted once but a boundary defended annually.
Signals to Monitor
Watch the distribution of causes. A register in which most entries attribute cause to something outside the enterprise is describing its authors' incentives, not its environment. Watch the ownership level: entries clustering at executive level while operational entries thin out suggests attribution is being pushed where it is diffuse.
Watch what follows a materialised risk. If the post-event review names an individual, the register became evaluative that day, whatever the policy says. Watch entries around a promotion round: a quiet register before calibration and a fuller one after is difficult to explain otherwise. And watch for entries never downgraded and never escalated: a risk held at amber for eleven consecutive reviews is usually one whose author has found a rating that is safe to hold.
Questions for the Leadership Team
- In the last two appraisal cycles, was risk register content — entries, ratings, timing or ownership — referenced in any promotion, remuneration or performance discussion, including through derived reporting?
- If we asked four operational managers privately what they have chosen not to record, what would they say, and how much aggregate exposure does that represent?
- Which named individual or committee currently owns the question of whether our register is evidentiary or evaluative, and when did they last consider it?
- How many entries on our current register attribute their primary cause to a decision, capability gap or supplier selection inside the enterprise, and how does that proportion compare with our incident history?
- What would our insurance, capital and covenant positions look like if the register we rely upon were shown to have been systematically moderated by its authors?
- Which of our reward mechanisms for risk behaviour can be verified without reading a single register entry?
Closing Perspective
The choice is not between a strict register and a lenient one. It is between knowing what your register is and not knowing. An enterprise that never made the declaration has not avoided the decision; it has delegated it to several hundred private calculations about career safety, never reconciled, aggregated into the document its board treats as the definitive account of what could go wrong.
The appetite statement is a claim about what the enterprise is willing to bear. The appraisal system determines what it is willing to hear. Where the two disagree the second wins, and it wins silently. Deciding which instrument the register is takes one board resolution. Discovering that you never decided usually takes an event.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
