The SMB risk library

62 risks I keep seeing at small organizations, written the way a register entry should be written: event, caused by cause, resulting in impact. Each comes with a suggested starting score, the first controls worth deploying, and the evidence that proves them.

A risk you can't write as event–cause–impact is a worry, not a risk. The suggested scores are starting points from my own anchors — re-score against yours (the register's Scoring Guide shows how).

Filter by situation, sort any column, and click a risk to see its full statement, first controls, and evidence. Sorting by score puts the library's 80/20 on top — the rows most registers should start from. Copy what fits into your risk register, or download the whole library as a workbook below. Don't import all 62 — a register with everything on it manages nothing. And notice the Response column: not everything here says Mitigate. Some risks are best accepted (with an owner and a review date), transferred, or avoided outright — a register that only ever says Mitigate isn't making decisions.

Fits
RL-01 Cyber Universal 6 Mitigate
RL-02 Process Universal 6 Mitigate
RL-03 Operational Universal 6 Mitigate
RL-04 Financial Universal 6 Mitigate
RL-05 People Universal 6 Mitigate
RL-06 Cyber Universal 4 Mitigate
RL-07 Vendor Universal 3 Transfer
RL-08 Cyber Universal 4 Mitigate
RL-09 Process Universal 6 Mitigate
RL-10 Financial Universal 6 Mitigate
RL-11 Cyber Universal 6 Mitigate
RL-12 Process Universal 6 Mitigate
RL-13 Operational Universal 4 Mitigate
RL-14 Operational Universal 4 Mitigate
RL-15 People Universal 4 Mitigate
RL-16 Financial Startups 6 Mitigate
RL-17 Cyber Startups 6 Mitigate
RL-18 Process Startups 6 Mitigate
RL-19 Process Startups 6 Mitigate
RL-20 People Startups 6 Mitigate
RL-21 Compliance Startups 4 Mitigate
RL-22 Operational Startups 3 Mitigate
RL-23 Compliance US Gov 6 Mitigate
RL-24 Compliance US Gov 6 Mitigate
RL-25 Operational US Gov 6 Mitigate
RL-26 Vendor US Gov 6 Mitigate
RL-27 Compliance US Gov 4 Mitigate
RL-28 Operational US Gov 4 Mitigate
RL-29 Compliance India 4 Mitigate
RL-30 Compliance India 4 Mitigate
RL-31 Compliance India 6 Mitigate
RL-32 Compliance India 6 Mitigate
RL-33 Financial India · ISO/MS 4 Mitigate
RL-34 Compliance ISO/MS 4 Mitigate
RL-35 Process ISO/MS 6 Mitigate
RL-36 Operational ISO/MS 4 Mitigate
RL-37 Process ISO/MS 4 Mitigate
RL-38 Cyber Universal 6 Mitigate
RL-39 Financial Universal 6 Mitigate
RL-40 Vendor Universal 3 Mitigate
RL-41 Operational Universal 3 Mitigate
RL-42 Cyber Universal 4 Mitigate
RL-43 Process Universal 6 Mitigate
RL-44 Operational Universal 2 Accept
RL-45 Operational Universal 4 Accept
RL-46 Financial Universal 3 Transfer
RL-47 Financial Universal 3 Avoid
RL-48 Cyber Universal 9 Mitigate
RL-49 Cyber Universal 2 Mitigate
RL-50 Operational Universal 4 Mitigate
RL-51 Process Universal 3 Mitigate
RL-52 Process Startups 4 Mitigate
RL-53 Compliance Startups 4 Avoid
RL-54 Compliance Startups 4 Mitigate
RL-55 Compliance US Gov 4 Mitigate
RL-56 Compliance US Gov 3 Mitigate
RL-57 Vendor US Gov 4 Mitigate
RL-58 Compliance India 3 Avoid
RL-59 Compliance India 2 Mitigate
RL-60 Compliance India 2 Accept
RL-61 Process ISO/MS 4 Mitigate
RL-62 Compliance ISO/MS 4 Mitigate

The whole library, as a workbook

Same 62 risks in register-compatible columns — copy rows straight into your risk register. No macros, ever.

Download the workbook

How this connects: pick 8–15 risks that match your situation, paste them into the register, re-score with your own anchors, and take the top rows to leadership with the briefing template. The library is a menu, not a meal — and the 90-day plan shows where seeding the register fits in your first quarter.