By Vaibhav Rane, Founder, Cresolv One
Between technology and business risk consulting at Protiviti and running internal audit as Group Director at Etisalat, I sat in more annual risk review meetings than I can count — the kind where a risk register gets dusted off, presented to the board once a year, and then quietly shelved until the next cycle. Everyone in the room knew, without saying it out loud, that half the risks on the register had already changed by the time the meeting happened.
That's not a governance failure of the people in the room. It's a structural problem with treating risk as an annual event instead of a live condition.
Risk doesn't wait for the calendar. A key vendor's financial health can deteriorate in a quarter. A regulatory change can shift a compliance risk from low to critical overnight. A control that was adequate last year can become inadequate the moment a process changes. An annual review captures a single frame of a moving picture and then treats that frame as current for the next twelve months — which is exactly backwards from how risk actually behaves.
Done well, a risk heat map isn't a compliance artifact, it's a communication tool. Plotting likelihood against impact lets a board or leadership team see, in seconds, where attention needs to go, without reading forty pages of narrative. Done badly, it's a static slide built once a year from stale inputs, which gives the appearance of oversight without the substance of it. The difference isn't the heat map itself. It's whether the data underneath it is current.
Identifying a risk is the easy part — most organizations are reasonably good at naming what could go wrong. The harder part, and the part that actually protects the business, is what happens next: is there a named owner, a deadline, a defined mitigation action, and does anyone know if it slipped? In my experience, this is where most risk registers fall apart. Risks get identified, assigned in principle, and then nobody's tracking whether the mitigation is actually happening — until the risk materializes and everyone rediscovers it was flagged eighteen months earlier with no action taken.
A live risk register doesn't wait for a scheduled review to update. A control failure, a new regulatory requirement, a vendor red flag — each updates the register when it happens, not months later when someone remembers to revisit the spreadsheet. That single change, from periodic to continuous, is what actually closes the gap between "we identified this risk" and "we did something about it in time."
Most governance leaders already suspect the honest answer, and most know that fixing it isn't about working harder at the annual review — it's about not needing an annual event to know where the business stands.
If your board saw your risk heat map today, how much of the underlying data is from this quarter, versus carried forward from the last annual cycle because nobody's updated it? See our Risk Management platform.