Skip to main content
Rules Mate

Obligations register vs risk register: how the two connect and why you need both

Rules Mate Editorial6 min read

An obligations register records what the law requires; a risk register records what could go wrong. How the two link, who owns each, and why you need both.

The short answer

An obligations register records what is required of you; a risk register records what could go wrong and how badly. They are different artefacts with different owners, different review cycles and different audiences, and they are joined by a single field: the obligation reference carried on each compliance risk.

Organisations frequently maintain one and assume it covers the other. It does not. A complete obligations register with no risk assessment cannot tell a board where to spend money. A rich risk register with no obligations register cannot tell an auditor whether every duty has been identified in the first place.

What each register actually records

DimensionObligations registerRisk register
Core questionWhat binds us?What could go wrong?
Unit of recordA legal, licence or contractual dutyA risk event with cause and consequence
SourceLegislation, rules, codes, licence conditions, contractsBusiness analysis, incidents, near misses, external events
AssessmentApplies / does not apply, with reasonLikelihood and consequence, before and after controls
OwnerRole accountable for satisfying the dutyRole accountable for managing the exposure
Typical cadenceQuarterly review, annual refreshQuarterly review, plus event-driven update
Failure modeMissed obligationMis-prioritised spending
Primary audienceAuditors, regulatorsBoard, executive, insurers

The risk register is the artefact regulated entities are more often required to hold explicitly. APRA's CPS 220 risk management framework requires a documented framework covering material risks. Critical infrastructure responsible entities must maintain a risk management program under the Security of Critical Infrastructure Act. The internationally recognised reference is ISO 31000:2018 Risk management — Guidelines, which is paywalled and cited here by name only.

Where the two registers join

The join is a field, not a merge. Each compliance risk on the risk register carries one or more obligation IDs drawn from the obligations register. That single link produces four capabilities that neither register delivers alone:

  1. Coverage testing. Sort the obligations register by whether any risk references it. Rows with no linked risk are either genuinely low-consequence or have never been assessed. Both answers are useful; only one is acceptable undocumented.
  2. Prioritised assurance. The monitoring plan tests controls in residual-risk order, not alphabetical order.
  3. Consequence realism. Statutory maximum penalties, licence conditions and remediation costs give the consequence axis a defensible basis rather than a subjective rating. The penalty estimator draws maximum penalty ranges from the Rules Mate corpus for that purpose.
  4. Incident traceability. When an event is logged, it cites an obligation ID and a risk ID, so the register can be read for trends.

Keep the registers in separate tabs or tables with a shared key. Merging them into one giant sheet reliably produces a document nobody maintains.

A worked example: one obligation, three risks

Take a single obligation: notifying the Office of the Australian Information Commissioner of an eligible data breach under the notifiable data breach scheme. On the obligations register, that is one row with an owner, a control (the incident response plan), an evidence type (the statement lodged) and an event-driven frequency.

On the risk register, the same obligation sits behind at least three distinct risks:

RiskCauseConsequenceControlResidual rating driver
Breach occurs and is not detectedInadequate logging and monitoringExtended exposure, larger affected cohort, regulatory scrutinySecurity monitoring, access reviewDetection capability
Breach detected but not assessed in timeNo triage owner, no clock startedLate notification, enforcement exposureIncident register with clock fields, on-call escalationEscalation speed
Breach assessed but notification content is deficientUntrained preparer, no templateRework, follow-up regulator engagementPre-approved statement template, legal review stepPreparation quality

One obligation, three separate exposures, three different controls, three different owners. That is the work the risk register does and the obligations register cannot. The notifiable data breach walkthrough covers the notification mechanics; the NDB timer tracks the assessment clock.

Who owns which register

Ownership should be split, because the two registers answer to different people.

  • Obligations register — owned by the compliance function (or the CFO, company secretary or GM in a smaller business). Its audience is assurance: internal audit, external auditors, regulators.
  • Risk register — owned by the risk function where one exists, otherwise the executive team collectively, with a named risk owner on each line. Its audience is the board and, indirectly, insurers.
  • Both report into the same governance forum. In an SMB that is usually the board itself; in a larger entity it may split between an audit committee and a risk committee.

Where a single person owns both, keep the review meetings separate. A combined meeting reliably becomes a compliance meeting, and the risk conversation is the one that gets dropped.

Row-level ownership differs too, and the difference is worth stating explicitly in the policy. On the obligations register, the owner is the role that performs the control — payroll for withholding and reporting, operations for licensing and safety, technology for access management. On the risk register, the owner is the role that carries the exposure and can authorise spending to reduce it, which is usually more senior. The same obligation can therefore have a junior control owner and a senior risk owner, and that is correct rather than an inconsistency to be tidied away. Problems appear when the two are forced to match: either the control owner is given an exposure they cannot fund, or the executive is recorded as performing a control they have never touched.

One further distinction matters at review time. An obligations register row closes only when the obligation ceases to apply — the licence is surrendered, the threshold is no longer met, the contract ends. A risk line is never closed on that basis; it is re-rated as controls change, and retired only when the underlying activity stops. Registers that use the same closure logic for both end up either deleting risks that still exist or carrying obligations that lapsed years earlier.

Reporting drawn from both

A board pack should draw from both registers, and the difference between the two views is the point:

  • From the obligations register: new or amended obligations assessed this period, open gaps with owners and target dates, upcoming lodgements, attestation status.
  • From the risk register: movement in residual ratings, risks outside appetite, control failures identified by testing, and emerging risks not yet mapped to an obligation.

The second list is where new regulation shows up before it becomes law. An emerging risk with no obligation ID is often the earliest signal that a proposed regime — labelled clearly as proposed and not yet legislated — needs monitoring. Board reporting structure is covered in board and committee compliance reporting.

What breaks when you keep only one

Obligations register only. Everything looks equally important. Controls are built to the same standard for a $500 late-lodgement exposure and a licence-threatening one. Assurance testing is alphabetical. The board receives a compliance status list with no sense of exposure, and directors cannot discharge the duty to inform themselves in any meaningful way.

Risk register only. The register reflects what management already knows about. Unidentified obligations produce no risk lines, because nobody assessed them. This is the classic pattern behind threshold-triggered failures — an entity crosses a revenue, headcount or emissions threshold, a new regime switches on, and it appears in neither register because the trigger was never mapped. The obligation finder and the Compliance Fingerprint exist to surface exactly those triggers.

Both, but unlinked. The most common state. Both artefacts exist, both are reviewed, and neither can answer "which of our obligations carries the highest residual risk". Adding the obligation ID field to the risk register is a single afternoon of work and is the highest-return maintenance task in most compliance programs.

Frequently asked

Can one register do both jobs?

Not well. The unit of record differs — an obligation is a duty, a risk is an event with a cause and a consequence — and a single obligation typically maps to several distinct risks. Combining them forces one of the two structures to be distorted, and in practice the risk assessment is the part that gets flattened into a single subjective rating.

Which register should a small business build first?

The obligations register. You cannot assess the risk of an obligation you have not identified, and the obligations register is also the artefact an auditor or regulator asks for first. Once it exists, rating the top twenty rows for likelihood and consequence produces a workable first risk register in a single session.

Is a risk register mandatory in Australia?

For some entities, yes. APRA-regulated entities must maintain a risk management framework under prudential standards; responsible entities for critical infrastructure assets must have a risk management program under the Security of Critical Infrastructure Act; and various licensing regimes require documented risk management. For unregulated businesses it is not mandated as such, but directors' duties to exercise care and diligence are difficult to evidence without one.

How do statutory penalties feed the risk register?

Maximum penalties give the consequence axis an objective anchor for the regulatory component of a risk. They are not the whole consequence — remediation cost, licence impact, contract termination rights and reputational damage often exceed the fine — but starting from the statutory maximum stops consequence ratings drifting to whatever felt right at the workshop.

How often should the link between the two registers be tested?

At each quarterly review. Run two checks: obligations with no linked risk, and risks with no linked obligation. Both lists should be short and both should have a documented reason for each entry.

Related

Related reading