Skip to main content

MightyGroupUK update

Put shared risks in one register across your business portfolio

A risk can look small inside one venture and much bigger when the same supplier, account or public fact is used elsewhere. One missed renewal might affect a website and its email. One outdated parent-page summary might send enquiries to the wrong place. Nobody needs a complicated risk system to notice those connections, but they do need somewhere to record them.

A business portfolio risk register gives shared risks one home. It should show what could happen, which ventures would feel the effect, what is already being done and who owns the next sensible action. The register is a working management record, not a prediction and not a substitute for specialist advice.

MightyGroupUK currently presents four live ventures on its Our Brands page, with the parent brand providing the shared home, standards and longer-term direction. That makes the parent level the right place to see connections between ventures while each specialist brand keeps responsibility for its own detailed work.

Start with the shared consequence

Keep a risk at venture level when it affects only that venture and can be managed there. Bring it into the portfolio register when it crosses a boundary. That may happen because several ventures rely on the same service, because the response needs a parent-level decision or because a change could make shared public information inaccurate.

Write the risk as a short chain of cause and effect. For example: “If the renewal notice for a shared domain is missed, the website and email using that domain may be interrupted, which could affect enquiries.” That is more useful than writing “domain risk” because it explains the event and the business consequence.

GOV.UK guidance on emergency risk assessment says business and organisational planning should be built on identifying and assessing risks that could obstruct performance. The National Cyber Security Centre also advises small organisations to identify critical systems and assets, understand why they matter and put risk discussions on the normal management agenda. Those principles work beyond cyber security.

Record enough to support a decision

A useful register does not need a long description for every concern. Give each entry the same basic information:

  • A clear risk statement covering the cause, event and likely consequence.
  • The ventures, shared services or public pages that could be affected.
  • The evidence behind the concern, such as a contract date, account record, incident note or authoritative web page.
  • The controls already in place and where the supporting record is kept.
  • A simple assessment of likelihood and impact, each with a short reason.
  • One next action, one owner and a realistic date for checking it.
  • A review trigger, such as a supplier change, renewal, new venture, incident or material website update.

Keep likelihood and impact separate. A low-likelihood event may still deserve attention if the impact would reach several ventures. Avoid a precise-looking score unless the business has agreed what the numbers mean. Plain ratings such as low, medium and high are easier to challenge in a small team when each rating has a written reason.

Keep evidence close without putting secrets in the register

The register should point to evidence, not become a store for passwords, recovery codes, personal data or confidential contract details. Record the approved location of the supporting information and who may access it. The NCSC’s guidance on preparing for incidents recommends keeping important information in a safe place, assigning responsibilities and documenting the point at which an issue needs wider management attention.

Evidence also keeps the discussion honest. “We probably have a backup” is not a control. A dated record showing who checked the backup and where the result was recorded is evidence. The same standard applies to supplier contacts, renewal ownership and public information.

Use examples as prompts, not claims about your business

The examples below are illustrative. They show how an entry can move from a vague concern to a checkable action.

Possible shared risk Evidence to check Useful next action
Two ventures rely on the same online supplier and the service becomes unavailable. Current contract, support route, affected systems and any recovery record. Confirm who contacts the supplier and how each venture would communicate during an interruption.
A renewal notice reaches an inbox that only one person checks. Registrar record, renewal date, account owner and backup contact. Update the domain renewal register and confirm that the next reminder reaches the right people.
A specialist source page changes while a parent-brand summary still carries the old wording. The authoritative page, the repeated summary and the named content owner. Use a website content ownership record to trace and check every affected page.

Do not copy a specialist risk into the parent register simply to make the list look complete. Health and safety, safeguarding, data protection, financial, legal and technical risks may need qualified advice or a dedicated assessment. The portfolio entry can record the shared consequence, owner and link to the specialist record without pretending to replace it.

Review actions, not just ratings

A risk register goes stale when the meeting spends all its time debating whether an item is amber or red. Check the evidence first. Then ask whether the current control still exists, whether the next action happened and whether the affected ventures have changed.

The existing MightyGroupUK guide to a monthly portfolio review gives shared decisions a regular place to land. The risk register can sit beside that agenda. New high-impact concerns may need attention sooner, while stable entries can wait for their stated review trigger.

Close an entry only when the reason is recorded. The risk may have been removed, reduced to a level the business has consciously accepted or moved into a specialist plan with a named owner. Deleting the row loses that decision and makes the same discussion more likely to return later.

Turn the highest priorities into workable plans

The register shows where attention is needed. It does not tell people exactly how to respond when an interruption happens. For the risks that matter most, create or update the relevant continuity or incident plan. Name the first actions, decision points, contacts, alternative ways of working and the evidence needed before normal service resumes.

Start with the shared dependencies already known across the portfolio. Write each consequence plainly, link it to evidence and give the next action to somebody who can complete it. If the register is too long to check during the monthly review, it will soon be ignored. Keep enough detail to support the next decision and put the supporting documents in their proper place.