The UK Government’s National Risk Register (NRR) highlights risks to ‘lives, health, society, critical infrastructure, economy and sovereignty’ ranked by impact and likelihood – but how can businesses make use of this information? Gary Lynam looks at how to use the NRR to inform operational risk, business continuity, and resilience strategies.
If the pandemic taught us anything, it’s that some risks can sometimes never be fully predicted. With that kind of uncertainty in mind, the latest update of the UK Government’s National Risk Register (NRR) was released in August 2023 to help businesses fully account for every possibility when measuring risk. For the first time, it is based directly on the government’s internal, classified National Security Risk Assessment and runs to 192 pages.
Unsurprisingly, risk scenarios can take many forms – from terrorism and cyber threats to those relating to health, societal issues, and natural disasters – and there are 89 in total. What they have in common is the risk posed to ‘lives, health, society, critical infrastructure, economy and sovereignty’.
Dig deeper, and what also becomes clear is the distinction that exists between acute and chronic risks, with the NRR focusing on acute risks that require a rapid response as opposed to long-term, chronic risks that are addressed with more strategic decision-making.
These are organized as a matrix where the Impact of each risk scenario is plotted alongside its Likelihood to give readers a point of comparison. While the impact and likelihood of some risks, such as earthquakes, are considered to be minor in the UK, a civil nuclear accident is right at the other end of the impact scale despite being considered unlikely. Collectively, it paints a complex and interconnected picture of where each type of risk fits in 2023, giving stakeholders a reference point for developing contingency plans.
One key question to ask is how relevant is the NRR to everyone outside of government? While the NRR isn’t targeted at the general public, its intended audiences do include businesses (including SMEs) who need to understand how risks could ‘impact their business continuity’. The hope is, of course, that the country rarely has to deal with the risks included within the NRR, but for many organizations, even low-impact, low-likelihood risks have the potential to cause disruption.
Making use of the National Risk Register
From a business perspective, a good place to start is to review the risks and the impact/likelihood matrix to see what might be relevant from a management perspective. In doing so, it’s important to link risks to organizational objectives, leaving out all those that aren’t going to impact decision-making policies or processes.
This insight can provide a useful foundation for creating scenarios to inform operational risk, business continuity, and resilience strategies. For some organizations, this might be as simple as borrowing content straight from the report or, at the very least, using it as the basis for creating something more tailored and specific that more closely aligns with the organization in question. These risk scenarios can then be used to test continuity, incident management and crisis response plans to ensure that a) a full list of relevant risks has been considered and b) that existing processes are fit for purpose.
Taking this a step further, it’s also good practice to factor in how each organization’s own risk matrix could be impacted by strategic partners. Ideally, they should also be focused on effective risk planning and incident response themselves but given the increasing complexity and interdependence of modern supply chains, this kind of extended planning can be essential. How much information, for example, can key suppliers share about their risk planning and resilience?
For international businesses, the task takes on extra levels of complexity, given differing national risk priorities and the extent to which they overlap. Scenarios that might be considered to be high risk in one locality, for example, could be almost irrelevant elsewhere. Effective planning takes these nuances into account to ensure an incident response strategy is properly tailored.
Given the unpredictable nature of the kind of risks described in the NRR, it goes without saying that the more each organization can identify and plan for its risk scenarios, the better the outcomes will be. While the NRR provides a helpful starting point, effective risk management requires going beyond a generic view to analyse an organization’s unique risk profile carefully. With proper planning and testing of response strategies, even unlikely events can be managed while regular reviews of the risk register, continuity plans and crisis simulations help ensure readiness in an ever-evolving risk landscape. Though risks can never be fully eliminated, resilience can almost always be strengthened, benefiting all involved.
The author
Gary Lynam, Managing Director for EMEA, Protecht.






