This Practice Note explains how to create a risk register, a tool that allows you to collate all your risk information in one place, by categorising each risk the organisation faces, scoring each risk and then deciding on your response to each risk, eg reject or accept and, if the latter, how to control or mitigate the risk. To formulate an effective risk register, you must first identify the risks your business faces. It is also helpful to have an understanding of your organisation's appetite for risk.