What a usable entry contains
A scenario written as “a threat exploits a vulnerability on an asset, causing an impact” rather than a category name; the business activities affected; the likelihood and impact on the organization’s method, giving an inherent score; the controls that apply and their verified status, giving a residual score; the target score once the treatment plan lands; the owner; the treatment decision (reduce, transfer, avoid, accept); and the dated actions. Anything less is a list of worries, not a register.
Why registers die, and how they survive
Registers built in spreadsheets die of three causes: scores that are opinions with no link to controls, an annual review nobody has time for, and a group structure that produces one register per entity with incompatible scales. A living register links each risk to the controls and evidence that justify its residual score, re-evaluates when a control fails or a supplier degrades, and imposes one method across entities so that a group-level picture can be consolidated rather than reconciled.
The register the regulator reads
NIS2 requires policies on risk analysis and a management body that approves the measures they lead to; DORA requires financial entities to identify, classify and document ICT-supported functions and the risks to them, and to review the risk framework at least yearly. A register with owners, dated decisions and evidence-backed scores is the artifact both supervisors expect to see, and the one a board can defend line by line.