Structure a risk register so risks, controls, owners and status are tracked consistently.
Security Risk Registers and Control Prioritisation for Facility Managers
Turn security findings into a live risk register that facility managers can maintain, prioritise and defend, so control spending follows actual risk rather than the loudest complaint.
Course Overview
Many facilities hold a security risk register that was populated once after an assessment and never opened again, while the controls that actually get funded are decided by whichever incident happened most recently or whoever complained loudest to the budget holder. This course treats the risk register as a working management tool that a facility manager, not only a security specialist, can maintain and use to justify spending decisions. Coverage includes structuring a register so risks, controls and owners are tracked consistently, prioritising controls using cost-benefit and as-low-as-reasonably-practicable reasoning rather than instinct, assigning clear ownership so actions do not stall, and running a review cycle that keeps the register aligned with a changing facility. Participants build a full register from a set of assessment findings, prioritise a limited control budget across competing risks, and prepare a short report that defends those choices to a facilities or finance committee that is not security-trained.
Expected Learning Outcomes
Score and prioritise risks using a method a non-specialist committee can follow and trust.
Prioritise a limited control budget across competing risks using cost-benefit reasoning.
Assign risk and action ownership so control implementation does not stall unnoticed.
Apply as-low-as-reasonably-practicable reasoning to decide when a residual risk is acceptable.
Run a review cycle that keeps a risk register current as a facility and its use change.
Defend risk register priorities to a facilities or finance committee without security expertise.
Who Should Attend
Facility and building managers responsible for maintaining a security risk register.
Multi-site facilities managers prioritising security budgets across several buildings.
Security managers who need facility teams to own and act on register entries.
Health, safety and facilities coordinators with security risk added to their remit.
Property and asset managers reporting security risk to landlords or investors.
Facilities management contractors accountable for client-side risk register reporting.
Course Modules
Select any module to see its sessions and points.
01Structuring a Working Security Risk Register
2 sessions · 8 points
Session 1What Belongs in the Register and How It Is Organised
- Define the fields a risk register needs, including risk description, cause and current controls.
- Separate the risk register from the assessment report so it can be maintained independently.
- Group related risks so the register reflects a facility's actual structure and operations.
- Avoid duplicating near-identical risks that fragment ownership and reporting.
Session 2Populating the Register from Assessment Findings
- Convert assessment findings into register entries with a consistent level of detail.
- Record existing controls accurately so residual, not just inherent, risk is visible.
- Cross-reference register entries to supporting evidence such as survey notes or incident reports.
- Retire register entries that no longer reflect current site conditions or controls.
02Scoring and Prioritising Risk for a Non-Specialist Audience
2 sessions · 8 points
Session 1Scoring Risks Consistently
- Apply a likelihood and consequence scale that a non-security committee can interpret directly.
- Score new entries against existing ones to keep the register's ranking internally consistent.
- Explain a risk score in plain terms that connects the rating to a specific scenario.
- Review scores periodically so ratings do not simply persist unchanged from year to year.
Session 2Prioritising Controls Under Budget Constraints
- Compare candidate controls by risk reduction achieved per unit of cost.
- Apply as-low-as-reasonably-practicable reasoning to decide where further spending is not justified.
- Sequence control implementation so the highest-priority risks are addressed within available budget.
- Present trade-offs transparently when budget forces a choice between competing priorities.
03Ownership, Accountability and Action Tracking
2 sessions · 8 points
Session 1Assigning and Sustaining Ownership
- Assign each register entry a named owner accountable for its status and next action.
- Set realistic target dates for actions and flag entries that repeatedly slip.
- Escalate stalled actions to a level with authority to unblock budget or resourcing.
- Reassign ownership cleanly when staff change roles without losing register continuity.
Session 2Integrating the Register into Facilities Routines
- Align risk register reviews with planned maintenance and capital budget cycles.
- Fold security risk actions into existing facilities management reporting rather than a separate process.
- Use register status to inform contractor and supplier performance conversations.
- Capture new risks arising from renovation, tenancy change or new equipment promptly.
04Reviewing, Reporting and Defending Priorities
2 sessions · 8 points
Session 1Running an Effective Review Cycle
- Set a review frequency matched to the facility's risk level and rate of change.
- Involve relevant stakeholders in reviews so the register reflects operational reality.
- Reassess residual risk after a control is implemented rather than assuming it is resolved.
- Archive superseded versions so a register's history remains available for audit.
Session 2Reporting to Facilities and Finance Committees
- Summarise register priorities in a short report suited to a non-security committee.
- Justify prioritisation decisions using the same cost-benefit reasoning used to make them.
- Respond to challenge on why a specific risk was or was not funded in a given cycle.
- Use register trends over time to support the case for sustained security budget.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
