Every framework you answer to assumes you keep a risk register, even when it never uses the words. The obligation is not to own a tool; it is to show a maintained, scored, owned record of your risks over time. That second word, maintained, is where the spreadsheet quietly fails.
What a risk register must show
NIS2, DORA and ISO 27001 never mandate a tool, yet none of their obligations can be met without one maintained record of your risks. Put the texts side by side and they specify what that record must be able to show.
- One record of risks from every source: projects, audits, supplier assessments (NIS2 Art. 21(2)(a); DORA Art. 6).
- A named owner and current status for every risk, because oversight requires accountability (NIS2 Art. 20).
- Treatment decisions and residual levels, including formal acceptance of what you chose not to fix (ISO 27001 cl. 8.3).
- Review dates, history and evidence producible for a supervisor or auditor (NIS2 Art. 32 to 33; ISO 27001 cl. 8.2).
Scored assessment, not a list
A register is only useful if the numbers are honest. A defensible assessment scores each risk on a matrix, separates inherent from residual, and ties risks to the criticality of the assets they threaten, so a high score means high exposure, not a guess. Asset criticality on C-I-A-T (confidentiality, integrity, availability, traceability) is what makes the score reflect what is actually at stake.
The lifecycle, recorded
The value is not the snapshot; it is the trail. A risk moves through identified, treated, mitigated, accepted or closed, with inherent and residual levels and the path between them. Formal acceptance lives in an exception registry with a justification and an expiry date, so an accepted risk cannot quietly become a forgotten one.
From obligation to evidence
The same record answers three frameworks at once. Here is the mapping we use on engagements.
| OBLIGATION | WHAT YOU MUST PRODUCE | IN SYNAPSERM |
|---|---|---|
| NIS2 Art. 21(2)(a) | Risks identified, scored, owned and treated | Scored risk register, configurable scales |
| DORA Art. 6 | A documented framework, reviewed at least yearly | Register with review dates and history |
| ISO 27001 cl. 8.3 | Risk treatment decisions and formal acceptance | Lifecycle and exception registry |
| NIS2 Art. 32 to 33 | Everything above, on demand, an auditor can read | Immutable history, read-only auditor role, export |
Questions we get asked
Is a spreadsheet enough for the risk register?
For a first assessment, often yes. It fails on two obligations that only appear over time: effectiveness assessment (NIS2 Art. 21(2)(f)) and evidence on demand (Art. 32 to 33). A spreadsheet has no history, no owner accountability and no read-only auditor view, so what a supervisor receives is a snapshot you assembled last week, not a record you maintained.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before your controls; residual risk is what remains after them. Recording both, and the path between them, is what shows a control actually reduced something. A register with only one number cannot demonstrate that your treatment worked, which is exactly what an auditor checks.
What is C-I-A-T criticality?
It scores an asset on four dimensions, confidentiality, integrity, availability and traceability, in business language rather than technical jargon. Feeding that criticality into the risk assessment is what makes a high score mean high business exposure, so the register reflects what is genuinely at stake rather than a gut feel.
How do we score risk defensibly?
On a consistent, documented scale, applied the same way to every risk, with the assessment recorded rather than argued. Defensibility comes less from the exact numbers than from the fact that the method is written down and applied uniformly, which is what a supervisor or a certification auditor probes.
Is a risk register the same as a risk assessment?
No. The assessment is the act of scoring; the register is the maintained record of every assessment, its owner, its treatment and its history. You run assessments; you keep a register. The obligations are met by the second.
Go deeper
The obligations, article by article.
Why the register outgrows the file.
How criticality feeds the risk score.
Bring one real supplier or one real system. In 45 minutes we run it through the mapping and you keep the output.
Book a demoThis page summarises NIS2 (Directive (EU) 2022/2555), DORA (Regulation (EU) 2022/2554) and ISO/IEC 27001 for general information. It is not legal advice.