Risk linkage

Linking risks to procedures without orphan lists

Cloud Datastorage journal · 9 min read

Documents being reviewed for risk assessment

Orphan risk lists are polite fiction. They sit in a shared drive, updated once during planning, then ignored while procedures evolve in the audit planning workflow app. Reviewers ask about risks; the answer lives somewhere else.

Make the link the unit of work

A risk entry is incomplete until it points to at least one procedure module a reviewer can open. If your app cannot create that link, invent a temporary field—and treat that invention as a configuration debt, not a permanent habit.

Write risks as decisions, not adjectives

“Revenue is elevated” tells a junior nothing. “Cut-off risk is elevated because despatch notes post overnight; procedures 4.2 and 4.3 must include the final five shipping days” tells them where to look.

Review from the procedure outward

Managers often start in the risk register. Try the reverse once: open each elevated procedure and ask which risk justifies the extra work. Missing answers reveal padding. Duplicate answers reveal thin risk writing.

Retire the parallel sheet on purpose

If you must keep a spreadsheet during migration, date its retirement. Teams that never set a retirement date still have the spreadsheet three seasons later. Our Fundamentals course treats that as a planning limitation worth naming aloud.

← All articles