[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-191420-105":53,"doc-detail-191420-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","risk-register-practical-approach-white-paper","Risk Register - Practical Approach - White Paper","","Risk register framework presenting structured risk categories and corresponding adverse outcomes, likelihood, impact, priority, and control procedures. Covers People, Office, IT, Financial, Regulatory compliance, and PI-related risks, detailing primary responsibility, monitoring actions, and follow-up timescales. Includes guidance for authorisation rules referencing due diligence recruitment, business continuity testing, KYC and billing review, security controls, conflict-of-interest mitigation, and procedures to ensure legal and procedural time limits are met.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/risk-register-practical-approach-white-paper/191420/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/risk-register-practical-approach-white-paper/191420.png","ImageObject",442,249,{"name":88,"@type":89},"WPS_1786070896","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-10-05","2026-09-03",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",9,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What risk information fields are included for each risk in the register?","Question",{"text":109,"@type":110},"Each entry lists a risk description, likelihood, risk impact, priority, control procedure, primary responsibility, monitoring process/action, and follow-up required with timescale.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"How does the register address people-related recruitment risks?",{"text":114,"@type":110},"It highlights failure of due diligence with candidates and specifies mitigations such as issuing and following due diligence checklists, involving HR in every candidate recruitment, and administering appropriate tests and references.",{"name":116,"@type":107,"acceptedAnswer":117},"What controls are suggested for IT security and data protection risks?",{"text":118,"@type":110},"It recommends strong firewall and anti-virus systems, system security review for adequacy, review of internal protocols for portable equipment, and testing of existing systems plus research into improved back-up and security technology.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},191420,1788408498,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":25,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":126,"read_time":47},549768072016,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","| Outcome\u003Cbr>7.2 |\n| --- |\n|  |\n| Outcome\u003Cbr>7.3 |\n\n| Guidance note iii to Rule 8 SRA Authorisation Rules |\n| --- |\n|  |\n\n|  |  |\n| --- | --- |\n| People | Recruitment, leavers, grievances, diversity, training, work allocation. |\n| Office | Business continuity, business process outsourcing, insurance, stock supplies, relationship with suppliers, utilities, catering. |\n| IT | System failure, data loss or corruption, loss of mobile device, misuse of client data, innovation. |\n| Financial | Profitability, bad debts, audits, credit risk. |\n| Regulatory compliance | Failure to comply with provisions within the Code/Handbook, conflicts,\u003Cbr>undertakings, data protection, bribery and corruption and anti-money laundering. |\n| PI | Level of PI insurance cover, missed deadlines, mistake in application of the law, drafting error, failure to comply with a procedural time limit. |\n\n\n| No. | Description of Risk and Adverse Outcome | Likelihood | Risk Impact | Priority | Control Procedure | Primary Responsibility | Monitoring Process/Action | Follow up Required/Timescale |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 1 | People – Recruitment |  |  |  |  |  |  |  |\n| 1 | Failure to adequately follow due diligence procedures with candidates. Could lead to recruitment of people who are insufficiently qualified, under-performance, errors, wrong cultural fit, unsettled team, potential conflicts and/or PI claims. HR input might be needed to respond to these issues. Possible damage to firm’s reputation. Expensive mistake to rectify. | 1 | 4 | 2 | Mitigate | All partners with responsibility for recruitment; HR Managers | -HR to ensure that a clear list of due diligence recruitment checks is issued and followed and sent to recruiting partners.\u003Cbr>-HR to follow up regularly to check recruitment framework is being followed.\u003Cbr>-A member of HR to be involved in the recruitment of every candidate.\u003Cbr>-Appropriate tests and checks administered and references sought. | -HR Manager to completelist of recruitment requirements as part of due diligence process by X date. To be forwarded to HR Director for sign off by Managing Partner. To be distributed to all partners by X date. |\n| 2 | Office |  |  |  |  |  |  |  |\n| 1 | Failure of the business continuity system. Disruption to normal business operations. Firm/office unable to conduct business for a period of time. Could miss procedural or deal deadlines leading to a PI claim, loss of client, damage to firm’s reputation, loss of revenue. | 2 | 5 | 4 | Mitigate | Head of Facilities and Head of IT | -The firm already has resources in place to provide functional back-up support should the need arise, but ensure quarterly review of systems.\u003Cbr>-Continue to maintain offsite contingency office. Review ongoing adequacy.\u003Cbr>- Implement new IT system to ensure uninterrupted service if usual arrangements fail.\u003Cbr>- Ensure individuals involved in business interruption information cascade are still happy to act in this capacity/contact details are current. | -Regular quarterly system checks-next one to be conducted by X date.\u003Cbr>-Full trial of business continuity plan on an annual basis-next one due on X date.\u003Cbr>-Head of IT to research new IT back-up system.\u003Cbr>-Head of Facilities to check [accuracy of B.I. contact](accuracy of B.I. contact)[ ](accuracy of B.I. contact)[detail information.](detail information.) |\n| 3 | Financial |  |  |  |  |  |  |  |\n| 1 | Client may be unwilling or unable to pay bills leading to bad debt, write-off and termination of client relationship. Might result in debt proceedings leading toa counter-claim for negligence. | 3 | 2 | 3 | Mitigate/ Avoid | All partners responsible for client inception; COLP responsible for KYC policy; Head of Finance | -Strong KYC policy / rigorous approach to client inception process.\u003Cbr>-All partners to thoroughly review monthly unbilled time reports.\u003Cbr>-Provide regular updates to clients procedurally and progress against billing estimate. | -COLP to r","cbCail5S8J8QFIab","https://ap.wps.com/l/cbCail5S8J8QFIab","pdf",176552,"English","# Outcome 7.2\n# Outcome 7.3\n# Guidance note iii to Rule 8 SRA Authorisation Rules\n# People\n## Recruitment\n# Office\n## Business continuity\n# IT\n## System security and data protection\n# Financial\n## Bad debts and billing\n# Regulatory compliance\n## Conflicts and investigations\n# PI\n## Insurance cover and procedural time limits","[{\"question\":\"What risk information fields are included for each risk in the register?\",\"answer\":\"Each entry lists a risk description, likelihood, risk impact, priority, control procedure, primary responsibility, monitoring process/action, and follow-up required with timescale.\"},{\"question\":\"How does the register address people-related recruitment risks?\",\"answer\":\"It highlights failure of due diligence with candidates and specifies mitigations such as issuing and following due diligence checklists, involving HR in every candidate recruitment, and administering appropriate tests and references.\"},{\"question\":\"What controls are suggested for IT security and data protection risks?\",\"answer\":\"It recommends strong firewall and anti-virus systems, system security review for adequacy, review of internal protocols for portable equipment, and testing of existing systems plus research into improved back-up and security technology.\"}]","Risk Register - Practical Approach - White Paper | PDF"]