How to Build a Risk Register for a Multi-Site FM Operation

 

FM Director conducting a quarterly risk register review at a corporate facilities office desk

The Incident That Asks the Question You Cannot Answer

A contractor working on a rooftop HVAC unit loses his footing on a wet surface. He is not seriously injured, but the near-miss triggers an insurer notification and a formal site review. Within 48 hours, three questions arrive from the insurer’s risk assessor: What risk controls were in place for rooftop access? Was this risk identified in the FM risk register? When was the register last reviewed?

If the answer to the second question is no — or more precisely, if there is no register to check — the conversation shifts immediately from a near-miss investigation into a liability exposure assessment. The insurer’s position changes. The FM team’s position changes. The absence of a risk register does not mean the operation was unsafe. It means there is no evidence that it was safe.

This is the central problem with FM risk management on most sites. The risks are known. Experienced FM professionals carry a mental map of every hazard, every ageing asset, every contractor dependency, every compliance gap on their site. What is missing is the structured document that converts that mental map into an auditable record — one that protects the FM team, satisfies insurers, and gives leadership the evidence they need to make informed decisions.

Why Most FM Operations Do Not Have a Register

The most common reason is not ignorance — it is inertia. Building a risk register from scratch feels like a significant project. You have to identify every risk, rate each one, assign ownership, document controls, and set review dates. For a single site, that might be a full day’s work. For a portfolio of ten buildings, it feels insurmountable.

The second reason is that risk registers created under pressure — typically the week before an audit or insurer review — tend to be superficial. They are populated quickly with generic risks and generic controls, they do not reflect the actual conditions on site, and they are filed and never reviewed again. An insurer or auditor who has seen thousands of these can identify a form-filling exercise within minutes. It provides the appearance of risk management without the substance.

The third reason applies specifically to multi-site operations: there is no standard. Each building manager maintains whatever they maintain, in whatever format they inherited. One site has a spreadsheet. One has nothing. One has a Word document last updated three years ago. When a liability event occurs, pulling together a coherent risk picture across the portfolio is an immediate problem.

None of these problems require expensive software to solve. They require a standard template, applied consistently across all sites, reviewed on a defined schedule.

What a Well-Structured FM Risk Register Contains

A risk register built for FM operational use — as opposed to a generic corporate risk template — has six components that work together.

A 5×5 likelihood × impact scoring matrix. Every risk is rated on two axes: how likely is it to occur (1 = Rare, 5 = Almost Certain) and what is the impact if it does (1 = Negligible, 5 = Catastrophic). The product of the two scores gives a risk score from 1 to 25. This number drives everything else — review frequency, escalation requirement, and management response. A score of 15–25 is CRITICAL and requires immediate escalation. A score of 1–3 is LOW and needs only annual review.

Pre-populated FM risk categories. A blank register is hard to use. A good FM risk register comes pre-populated with the standard operational risk categories that apply to most commercial facilities: fire and life safety, HVAC and mechanical, electrical systems, water and legionella, structural and building envelope, contractor and vendor management, compliance and regulatory, asset end-of-life, business continuity, and environmental. These give the FM manager a starting point and a quality check — ensuring no obvious category is left unaddressed.

Current controls and mitigation actions — kept separate. The most common failure in FM risk registers is conflating what is already in place with what still needs to be done. A well-structured register has two distinct columns: Current Controls (what exists now) and Mitigation Action (what will be done to reduce the risk further). Auditors and insurers read these two columns first. Vague controls — “we have a contractor” or “staff are trained” — do not pass scrutiny. Specific controls do: “Quarterly PTW review completed; all rooftop access contractors induction-verified against approved vendor list.”

Named risk owners with review dates. Every open risk must have a named individual accountable for ensuring controls are maintained and mitigation actions are executed. Not a role title — a name. And every risk must have both a target date (when the mitigation action will be complete) and a review date (when the risk rating will be reassessed). Without these two dates, a risk register is a list. With them, it is a management plan.

A residual risk rating. Once a mitigation action is complete, the risk does not disappear — it reduces. The residual rating captures the expected risk score after planned controls are fully in place. This is the target state. Comparing the current rating to the residual rating shows the risk reduction journey and gives leadership a clear view of where the operation is headed.

A quarterly review log and sign-off record. A risk register that is never reviewed is worse than no register at all — it creates a false impression of control. CRITICAL and HIGH risks must be reviewed at minimum quarterly. The review log documents when each review occurred, what changed, and who approved the current state. The sign-off record — FM Manager, FM Director, and Risk/Compliance Committee — is the governance evidence that the register is actively managed, not filed and forgotten.

FM Operational Risk Register showing Risk ID, Category, Likelihood, Impact, Risk Score, Rating bands (CRITICAL/HIGH/MEDIUM/LOW), and Status columns

What Standardising Across a Portfolio Looks Like

When I took over a manufacturing campus portfolio in India — eight sites across three states, each with a local FM team and a different approach to documentation — risk management was entirely site-dependent. Two sites had a form of risk register. Three had HSE documents that contained some risk information but were not maintained as operational registers. Three had nothing.

The first thing we did was introduce a single risk register template across all eight sites. Same format, same scoring matrix, same review schedule. Each site FM manager completed their register within a six-week window. We ran a cross-site calibration session to ensure risk ratings were being applied consistently — a Likelihood 4 at one site should mean the same thing as a Likelihood 4 at another.

Within one quarter, two things emerged that would not have been visible any other way. First, a water and legionella risk had been rated LOW at one site because the local team was unaware of a recent regulatory change that elevated the required monitoring frequency for their water system type. The cross-portfolio review caught it before any regulatory authority did. Second, three sites had identified an identical single-vendor dependency for their critical cooling systems — one supplier, no qualified backup. Consolidated across the portfolio, that was a HIGH-rated risk. Site by site, each team had treated it as a known condition rather than a documented risk requiring mitigation.

The portfolio-level risk view was only possible because every site was using the same register structure. Without that, you cannot aggregate. You cannot compare. You cannot identify systemic risks that are invisible when each site operates in isolation.

“In 20+ years of FM operations across Asia-Pacific and Europe, I have seen risk registers treated as an audit obligation rather than an operational tool at every level of building complexity. The distinction matters: an audit obligation gets filed. An operational tool gets used. The difference between the two is whether the register has named owners, specific controls, and a review date that someone actually keeps.”

Building the Register: Where to Start

The practical starting point for any FM risk register is not a blank page — it is a structured template pre-populated with the standard FM risk categories. From there, the process is four steps.

  • Step 1: Identify your risks. Work through each pre-populated category and confirm which risks are applicable to your site. Add any site-specific risks in the blank rows. Do not aim for comprehensiveness in the first pass — aim for honesty. A register with 20 accurately-rated risks is more valuable than one with 50 risks rated to look acceptable.
  • Step 2: Rate each risk using the 5×5 matrix. Be specific about what you are rating. A fire and life safety risk is not the same across a data centre and a commercial office. Calibrate your Likelihood and Impact scores to your actual site conditions, not to a generic template expectation.
  • Step 3: Assign owners and actions. Every CRITICAL and HIGH risk needs a named owner and a specific mitigation action before the register leaves your desk for the first time. Medium and Low risks need owners and review dates at minimum. Generic actions — “review process” or “consider training” — are not actions. An action has a verb, a deliverable, and a date.
  • Step 4: Set the review schedule and keep it. CRITICAL risks require immediate attention and monthly review until closed. HIGH risks require quarterly review. Medium and Low risks can be reviewed annually. Log every review. The review log is your evidence that the register is a living document, not a compliance artefact.

For a multi-site operation, add a fifth step: cross-site calibration. Bring building managers together — even for a single session — to review how each site has rated comparable risks. Inconsistencies in rating signal either different site conditions (legitimate) or inconsistent understanding of the scoring criteria (a training gap). Either way, catching it at calibration is better than discovering it when an insurer asks why the same risk is rated 3 at one site and 12 at another.

The Register, Ready to Complete

I have packaged a complete FM Risk Register Template — with 27 pre-populated FM operational risks across all standard categories, a 5×5 scoring matrix, named owner and review date fields, current controls and mitigation action columns, a residual risk rating column, a quarterly review log, and a Summary Dashboard for leadership reporting — into the BizzXpert FM Operations Playbook Pack Starter tier. The template also includes an AI Prompt Toolkit with risk identification, rating validation, and escalation report prompts. Fully editable Word format, ready to use from Day 1.

Get the FM Operations Playbook Pack — Starter Tier on Etsy

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top