Risk
Risk Register
A single register linking risks to controls, audits and findings. Ratings move only when a human approves the change.
Registered risks
25
12 shown
Rating changes (90d)
8
6 up, 2 down
Risks without tested controls
3
R-05, R-10, R-03
Owners engaged
11
All attested Q3
Enterprise risks
| Risk | Category | Owner | I × L | Velocity | Controls | Inherent | Residual | Trend | Approval |
|---|---|---|---|---|---|---|---|---|---|
Revenue recognition on multi-element arrangements R-01 | Financial reporting | Corporate Controller | 5 × 4 | 3 | Partially effective | Critical | High | ↑ | Approved |
Cybersecurity breach affecting manufacturing systems R-02 | Technology | CISO | 5 × 4 | 5 | Partially effective | Critical | High | ↑ | Approved |
Acquisition integration control gaps (Halcyon) R-03 | Strategic | Integration PMO | 4 × 5 | 4 | Ineffective | Critical | Critical | ↑ | Pending |
Third-party logistics service disruption R-04 | Operational | VP Supply Chain | 4 × 4 | 5 | Partially effective | High | High | ↑ | Pending |
Export control and sanctions non-compliance R-05 | Regulatory | Chief Compliance Officer | 5 × 3 | 4 | Not assessed | High | High | ↑ | Approved |
Inventory valuation and excess/obsolete reserves R-06 | Financial reporting | VP Manufacturing Finance | 4 × 3 | 2 | Effective | High | Moderate | → | Approved |
Segregation of duties conflicts in ERP R-07 | Technology | CIO | 4 × 4 | 3 | Partially effective | High | High | ↑ | Approved |
Fraudulent journal entries at period end R-08 | Fraud | Corporate Controller | 5 × 2 | 3 | Effective | High | Moderate | → | Approved |
Channel partner rebate misstatement R-09 | Financial reporting | GM Asia Pacific | 3 × 4 | 3 | Partially effective | High | Moderate | ↑ | Approved |
ERP modernization program failure R-10 | Strategic | Program Director | 5 × 3 | 3 | Not assessed | High | High | ↑ | Pending |
Key person dependency in financial close R-11 | Operational | Corporate Controller | 3 × 3 | 2 | Partially effective | Moderate | Moderate | → | Approved |
Data privacy non-compliance (EU / GDPR) R-12 | Regulatory | Chief Compliance Officer | 4 × 2 | 3 | Effective | Moderate | Low | ↓ | Approved |