rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/obligations-register-vs-risk-register
Printed 28 August 2026
Obligations register vs risk register: how the two connect and why you need both
An obligations register records what the law requires; a risk register records what could go wrong. How the two link, who owns each, and why you need both.
The short answer
An obligations register records what is required of you; a risk register records what could go wrong and how badly. They are different artefacts with different owners, different review cycles and different audiences, and they are joined by a single field: the obligation reference carried on each compliance risk.
Organisations frequently maintain one and assume it covers the other. It does not. A complete obligations register with no risk assessment cannot tell a board where to spend money. A rich risk register with no obligations register cannot tell an auditor whether every duty has been identified in the first place.
What each register actually records
| Dimension | Obligations register | Risk register |
|---|---|---|
| Core question | What binds us? | What could go wrong? |
| Unit of record | A legal, licence or contractual duty | A risk event with cause and consequence |
| Source | Legislation, rules, codes, licence conditions, contracts | Business analysis, incidents, near misses, external events |
| Assessment | Applies / does not apply, with reason | Likelihood and consequence, before and after controls |
| Owner | Role accountable for satisfying the duty | Role accountable for managing the exposure |
| Typical cadence | Quarterly review, annual refresh | Quarterly review, plus event-driven update |
| Failure mode | Missed obligation | Mis-prioritised spending |
| Primary audience | Auditors, regulators | Board, executive, insurers |
The risk register is the artefact regulated entities are more often required to hold explicitly. APRA's CPS 220 risk management framework requires a documented framework covering material risks. Critical infrastructure responsible entities must maintain a risk management program under the Security of Critical Infrastructure Act. The internationally recognised reference is ISO 31000:2018 Risk management — Guidelines, which is paywalled and cited here by name only.
Where the two registers join
The join is a field, not a merge. Each compliance risk on the risk register carries one or more obligation IDs drawn from the obligations register. That single link produces four capabilities that neither register delivers alone:
- Coverage testing. Sort the obligations register by whether any risk references it. Rows with no linked risk are either genuinely low-consequence or have never been assessed. Both answers are useful; only one is acceptable undocumented.
- Prioritised assurance. The monitoring plan tests controls in residual-risk order, not alphabetical order.
- Consequence realism. Statutory maximum penalties, licence conditions and remediation costs give the consequence axis a defensible basis rather than a subjective rating. The penalty estimator draws maximum penalty ranges from the Rules Mate corpus for that purpose.
- Incident traceability. When an event is logged, it cites an obligation ID and a risk ID, so the register can be read for trends.
Keep the registers in separate tabs or tables with a shared key. Merging them into one giant sheet reliably produces a document nobody maintains.
A worked example: one obligation, three risks
Take a single obligation: notifying the Office of the Australian Information Commissioner of an eligible data breach under the notifiable data breach scheme. On the obligations register, that is one row with an owner, a control (the incident response plan), an evidence type (the statement lodged) and an event-driven frequency.
On the risk register, the same obligation sits behind at least three distinct risks:
| Risk | Cause | Consequence | Control | Residual rating driver |
|---|---|---|---|---|
| Breach occurs and is not detected | Inadequate logging and monitoring | Extended exposure, larger affected cohort, regulatory scrutiny | Security monitoring, access review | Detection capability |
| Breach detected but not assessed in time | No triage owner, no clock started | Late notification, enforcement exposure | Incident register with clock fields, on-call escalation | Escalation speed |
| Breach assessed but notification content is deficient | Untrained preparer, no template | Rework, follow-up regulator engagement | Pre-approved statement template, legal review step | Preparation quality |
One obligation, three separate exposures, three different controls, three different owners. That is the work the risk register does and the obligations register cannot. The notifiable data breach walkthrough covers the notification mechanics; the NDB timer tracks the assessment clock.
Who owns which register
Ownership should be split, because the two registers answer to different people.
- Obligations register — owned by the compliance function (or the CFO, company secretary or GM in a smaller business). Its audience is assurance: internal audit, external auditors, regulators.
- Risk register — owned by the risk function where one exists, otherwise the executive team collectively, with a named risk owner on each line. Its audience is the board and, indirectly, insurers.
- Both report into the same governance forum. In an SMB that is usually the board itself; in a larger entity it may split between an audit committee and a risk committee.
Where a single person owns both, keep the review meetings separate. A combined meeting reliably becomes a compliance meeting, and the risk conversation is the one that gets dropped.
Row-level ownership differs too, and the difference is worth stating explicitly in the policy. On the obligations register, the owner is the role that performs the control — payroll for withholding and reporting, operations for licensing and safety, technology for access management. On the risk register, the owner is the role that carries the exposure and can authorise spending to reduce it, which is usually more senior. The same obligation can therefore have a junior control owner and a senior risk owner, and that is correct rather than an inconsistency to be tidied away. Problems appear when the two are forced to match: either the control owner is given an exposure they cannot fund, or the executive is recorded as performing a control they have never touched.
One further distinction matters at review time. An obligations register row closes only when the obligation ceases to apply — the licence is surrendered, the threshold is no longer met, the contract ends. A risk line is never closed on that basis; it is re-rated as controls change, and retired only when the underlying activity stops. Registers that use the same closure logic for both end up either deleting risks that still exist or carrying obligations that lapsed years earlier.
Reporting drawn from both
A board pack should draw from both registers, and the difference between the two views is the point:
- From the obligations register: new or amended obligations assessed this period, open gaps with owners and target dates, upcoming lodgements, attestation status.
- From the risk register: movement in residual ratings, risks outside appetite, control failures identified by testing, and emerging risks not yet mapped to an obligation.
The second list is where new regulation shows up before it becomes law. An emerging risk with no obligation ID is often the earliest signal that a proposed regime — labelled clearly as proposed and not yet legislated — needs monitoring. Board reporting structure is covered in board and committee compliance reporting.
What breaks when you keep only one
Obligations register only. Everything looks equally important. Controls are built to the same standard for a $500 late-lodgement exposure and a licence-threatening one. Assurance testing is alphabetical. The board receives a compliance status list with no sense of exposure, and directors cannot discharge the duty to inform themselves in any meaningful way.
Risk register only. The register reflects what management already knows about. Unidentified obligations produce no risk lines, because nobody assessed them. This is the classic pattern behind threshold-triggered failures — an entity crosses a revenue, headcount or emissions threshold, a new regime switches on, and it appears in neither register because the trigger was never mapped. The obligation finder and the Compliance Fingerprint exist to surface exactly those triggers.
Both, but unlinked. The most common state. Both artefacts exist, both are reviewed, and neither can answer "which of our obligations carries the highest residual risk". Adding the obligation ID field to the risk register is a single afternoon of work and is the highest-return maintenance task in most compliance programs.
Frequently asked
Can one register do both jobs?
Not well. The unit of record differs — an obligation is a duty, a risk is an event with a cause and a consequence — and a single obligation typically maps to several distinct risks. Combining them forces one of the two structures to be distorted, and in practice the risk assessment is the part that gets flattened into a single subjective rating.
Which register should a small business build first?
The obligations register. You cannot assess the risk of an obligation you have not identified, and the obligations register is also the artefact an auditor or regulator asks for first. Once it exists, rating the top twenty rows for likelihood and consequence produces a workable first risk register in a single session.
Is a risk register mandatory in Australia?
For some entities, yes. APRA-regulated entities must maintain a risk management framework under prudential standards; responsible entities for critical infrastructure assets must have a risk management program under the Security of Critical Infrastructure Act; and various licensing regimes require documented risk management. For unregulated businesses it is not mandated as such, but directors' duties to exercise care and diligence are difficult to evidence without one.
How do statutory penalties feed the risk register?
Maximum penalties give the consequence axis an objective anchor for the regulatory component of a risk. They are not the whole consequence — remediation cost, licence impact, contract termination rights and reputational damage often exceed the fine — but starting from the statutory maximum stops consequence ratings drifting to whatever felt right at the workshop.
How often should the link between the two registers be tested?
At each quarterly review. Run two checks: obligations with no linked risk, and risks with no linked obligation. Both lists should be short and both should have a documented reason for each entry.
Related
Related reading
APRA CPS 220 Risk Management: the framework explained
APRA's Prudential Standard CPS 220 sets risk management governance and framework requirements for ADIs and insurers. Here's how it fits with CPS 510 (governance) and CPS 230 (operational risk).
SOCI Critical Infrastructure Risk Management Program (CIRMP) requirements
Responsible entities for certain critical infrastructure assets must have a Critical Infrastructure Risk Management Program under the SOCI Act. Here are the four hazard domains and the annual attestation.
Building a compliance obligations register: artefacts, owners and review cadence
What belongs in an Australian compliance obligations register: minimum fields, a named owner per row, review cadence, and the evidence auditors ask to see.
The three lines model applied to an Australian SMB
How the three lines model works without a compliance department: mapping the roles, keeping second line independent, and third-line options for an SMB.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/obligations-register-vs-risk-register