Why this matters for your practice
A risk register is the document a surveyor means when they ask to see "your business risk management system". The RACGP Standards for general practices, 6th edition, published 26 August 2026, now names the register in the criterion text itself: criterion F1.G requires that the practice "uses a risk register (or equivalent) to document and prioritise identified risks". The 5th edition, which practices are still accredited against, already requires a documented risk management process under indicator C3.1C and offers the register as the evidence. If you have been told you need one, this page explains which one, what goes in it, and what an assessor will look for.
What is a risk register?
A risk register is a working document that lists each risk your practice has identified, with its rating, its controls, its owner and its review date. It is not a policy and it is not a one-off exercise. It is the record your practice updates as risks change.
Each row typically holds: an ID, the date raised, a category (strategic, operational or service-related), the risk described as event, cause and effect, existing controls, likelihood, consequence, rating, response and additional actions, an owner, a due date, a review date and a status. The event, cause and effect framing matters. "Cyber" is a topic, not a risk. "An attacker gains access to the practice's records because the only login protection is a password, resulting in a privacy breach and practice downtime" is a risk, and it can be rated and assigned.
Rating is done on a likelihood and consequence matrix. Our Practice Risk Management Policy and Risk Register template uses a five-by-five matrix. The practice sets its own review intervals; the RACGP does not fix a number. AS ISO 31000:2018 is the Australian adoption of the international risk management standard.
A general practice runs three of these documents, because three different kinds of harm attract three different duties:
| Register | Whose risk | Duty | Template |
|---|---|---|---|
| Governance risk register | Risks to the practice as a business and a service | RACGP 6th edition F1.G; 5th edition C3.1C | Practice Risk Management Policy and Risk Register template |
| Clinical risk register | Risks to patients through the care provided | RACGP 6th edition CG7 | Clinical Risk Management Policy template |
| WHS hazard and risk register | Risks to workers, contractors, visitors and patients as people on the premises | Work Health and Safety Act 2011, ss 17 to 19 | WHS Hazard and Risk Register template |
If your practice is also an NDIS provider, there is a fourth. The NDIS Practice Standards and Quality Indicators (Version 4, November 2021), Core Module, Division 2, requires that risks to participants, workers and the organisation are identified and managed, and that register is covered by our NDIS Risk Management Policy template.
What goes in a governance risk register?
The governance register captures strategic, operational and service-related risks: the things that could stop the practice functioning, as distinct from clinical risks to patients. The RACGP's own F1 guidance draws that line, noting that "strategic, operational and service-related risks are different to clinical risks which are addressed in CG7, Managing clinical risks and incidents". Criterion F1.G sits in criteria set F1, "Defining and planning for the practice", in the Foundations of general practice standard.
The F1 guidance describes four steps, with these examples:
- Implementing. Establish risk controls or mitigation actions: installing a secondary internet connection after identifying a single point of failure, or introducing multi-factor authentication after a cyber audit.
- Monitoring. Track whether the controls are working: a monthly review of appointment delays to check the results of a rostering change.
- Reviewing. Reassess the risk and the control: reviewing a data security process annually or after a near-miss, or reassessing emergency plans after a local flood event.
- Reporting. Make practice leaders aware: regularly reviewing and updating the risk register, and reporting risks to practice leaders as often as needed.
Our template ships with three worked entries so you can see the shape: a principal retiring at short notice, loss of internet on a single connection, and the after-hours deputising contract ending without renewal. Ten to twenty entries is normal for a first pass. The framework can be proportionate: the F1 guidance says the size and complexity of the practice's risk framework can scale with the practice, and its Table 1 actions are "suggestions only". A realised operational risk is what a business continuity plan responds to, and the register is where you identify those risks before they land.
What the regulator or assessor expects
Under the 5th edition, which accreditation currently uses, indicator C3.1C states: "Our practice has a business risk management system that identifies, monitors, and mitigates risks in the practice." You must maintain a documented risk management process and develop procedures to mitigate risks. You could maintain a risk register, maintain a log of risks if you are a small practice, or keep a record of meetings where risks have been identified and actions agreed on to manage those risks. Indicator C3.2D requires at least one team member with primary responsibility for leading risk management systems and processes, and you must educate that person so they understand their role.
Under the 6th edition, criterion F1.G requires that the practice "maintains documented processes for identifying, assessing, and responding to strategic, operational, and service-related risks", "implements, monitors and reports risk management and mitigation actions", "uses a risk register (or equivalent) to document and prioritise identified risks", and "regularly reviews and reports risks, including their management and mitigation, to practice leadership". The four guidance steps, implementing, monitoring, reviewing and reporting, are how a surveyor will test whether that is happening.
Evidence of reporting matters as much as the register. Meeting minutes recording risks discussed and actions agreed are the proof that the register is read.
Practices are still accredited against the 5th edition. Transition arrangements under the National General Practice Accreditation Scheme are a matter for the Australian Commission on Safety and Quality in Health Care and have not been published; the Commission's own page says accreditation "currently uses the 5th edition" and that arrangements will come "in due course". Nobody can give you a date. The official RACGP mapping document classifies F1.G, "Governance risk management", as "Expanded" from 5th edition indicators C3.1C and C3.2D, so the underlying obligation is not new. See our 6th edition standards guide for how the new criteria are structured and our 6th edition migration guide for what is known about the move.
Common mistakes
One register for everything. Practices sometimes merge clinical risks and WHS hazards into the governance register. The clinical entries drown the governance ones, or the reverse, and the surveyor cannot see that each duty is met by its own document. Keep the three separate: F1.G for governance, CG7 for clinical, the WHS Act for hazards.
A register with two entries. Two rows signals a document written for an accreditation visit rather than a working tool. Ten to twenty entries is normal for a first pass, and the register should reflect the practice's actual size and complexity.
No owner or review date. A risk without a named owner is a risk nobody is managing. A risk without a review date will be rediscovered at the next survey, unchanged.
No reporting to leadership. Both editions require risks to be reported to practice leadership. A register nobody reads fails F1.G's reporting requirement even if the document itself is immaculate. Minutes are the evidence.
Writing the risk as a topic. "Cyber" is not a risk. Describe the event, the cause and the effect, so the risk can be rated on likelihood and consequence and given a control.
Assuming the 6th edition wording is not yet assessable. Transition arrangements are unpublished, but 5th edition C3.1C already requires the documented process today, with the register as the suggested evidence for it.
Frequently asked questions
Is a risk register mandatory for RACGP accreditation?
Yes, in substance. The 6th edition criterion F1.G requires the practice to use "a risk register (or equivalent)", and 5th edition C3.1C requires a documented risk management process with a risk register listed as the suggested evidence. Practices are still accredited against the 5th edition, but a surveyor asking for your business risk management system is asking for this document either way.
What is the difference between a risk register and a clinical risk register?
The governance register covers strategic, operational and service-related risks to the practice as a business. The clinical risk register covers risks to patients through the care provided, and sits under criterion CG7, alongside the clinical incident and event register under CG7.B. The RACGP's F1 guidance draws this line explicitly, so clinical risks belong in the clinical register.
Who should own the practice risk register?
The 5th edition C3.2D requires at least one team member with primary responsibility for leading risk management systems and processes, and requires that the practice educate that person so they understand the role. Individual risks should still have named owners in the register, since the person leading the system is not always the person best placed to act on each entry.
How many risks should a practice risk register have?
Ten to twenty entries is normal for a first pass. The RACGP's guidance is that the risk framework can be proportionate to the practice, so a small practice's register will look different to a large one's. What matters is that each entry is described as event, cause and effect, with controls, an owner and a review date.
Does an NDIS provider need a risk register?
Yes. The NDIS Practice Standards and Quality Indicators (Version 4, November 2021), Core Module, Division 2, requires that risks to participants, workers and the organisation are identified and managed. A practice that is both a general practice and an NDIS provider holds this register alongside the governance, clinical and WHS registers, since each covers a different kind of harm.
How often should a risk register be reviewed?
The practice sets its own intervals; the RACGP does not fix a number. Criterion F1.G requires that risks are regularly reviewed and reported to practice leadership, and the guidance examples include reviewing a data security process annually or after a near-miss, and reassessing emergency plans after a local flood event. The pattern is periodic review plus review after events that change the risk.
Related terms
Go deeper
Last reviewed