AccreditAZ

← All articles

Risk Management · 6 min read · Published 6 April 2026 · Reviewed 17 August 2026

How to Build a Risk Register That Actually Satisfies NZISM

A risk register is mandatory under NZISM — but most agencies treat it as a compliance tick-box rather than a useful tool. Here's how to build one that satisfies the auditors and actually helps you manage risk.

NZISM requires agencies to maintain a risk register as part of their security risk management programme. The Government Communications Security Bureau expects this register to be current, actively maintained, and used to inform security decisions — not just produced for assessment purposes.

In practice, many agencies have a risk register that exists primarily as a document. It was created when the system was first certified, reviewed briefly before the last assessment, and otherwise not touched. This is both a compliance risk and a genuine security risk — because the threats and vulnerabilities facing your systems change continuously.

Here's how to build a risk register that satisfies NZISM requirements and is genuinely useful.

What NZISM Requires

NZISM's risk management chapter requires agencies to:

The PSR self-assessment guidance reinforces these requirements from a governance perspective. The risk register is the primary artefact demonstrating that the agency takes a risk-based approach to security.

The Structure of a Good Risk Register Entry

Each risk in the register should include:

Risk description — what is the risk? Describe it in terms of a threat acting on a vulnerability to produce a consequence. "A malicious insider exploiting excessive access privileges to exfiltrate classified information" is a risk description. "Access control" is not.

Likelihood — how probable is this risk materialising? Use a consistent scale (1–5 or similar) with documented definitions for each level. Reference threat intelligence from the NCSC's Cyber Threat Report where relevant.

Consequence — if the risk materialises, what is the impact? Consider: harm to individuals, operational disruption, reputational damage, legal and regulatory exposure, financial cost. Again, use a consistent scale with documented definitions.

Inherent risk rating — likelihood × consequence, before controls.

Current controls — what controls are currently in place to reduce this risk? Link to the relevant NZISM controls and evidence.

Residual risk rating — likelihood × consequence, after current controls.

Treatment decision — accept, mitigate, transfer, or avoid? For accepted risks, document the rationale and who accepted it. For risks being mitigated, link to the treatment plan.

Owner — who is accountable for this risk? Not a team — a named individual.

Review date — when was this risk last reviewed? When is the next review due?

Keeping the Register Current

The most common failure: the register is accurate at certification time and deteriorates thereafter.

Build a maintenance rhythm:

The NZISM guidance on security risk management specifies that the risk register must be reviewed as part of any significant change assessment. If you're making major changes to your system, the risk register review is not optional.

Connecting the Risk Register to Accreditation

The risk register is the primary input to the Accreditation Authority's decision. When the AA reviews the accreditation package, they are looking at the residual risk the agency is accepting when it authorises the system to operate.

Residual risks that are rated HIGH or CRITICAL should be explicitly presented to the AA with a recommendation — accept with conditions, or require further mitigation before accreditation. The AA's decision on each significant risk should be documented in the Accreditation Letter.

An assessor reviewing a risk register wants to see: that every significant risk has been identified, that treatment decisions are documented and current, that ownership is clear, and that the register is actually being used to manage the programme. A register with every risk rated LOW and every treatment decision marked "Accept" with no justification will attract questions.

AccreditAZ provides a structured risk register linked directly to your NZISM controls and accreditation documentation — so changes in control status automatically surface as risk register review prompts. Try it free.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →