Lifecycle
NHS risk register software with 5x5 scoring
Good risk register software keeps identified risks, their assessed likelihood and consequence, controls, residual risk and review cadence in one working trail. Regulation 17 sits above it: the register is evidence for the “assess, monitor and improve” duty. The trap is a register that exists because the regulation expects it, not because the provider uses it.
What the regulation expects
Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires providers to have an effective system for assessing, monitoring and improving the quality and safety of the services provided, and to assess, monitor and mitigate the risks relating to the health, safety and welfare of service users. Reg 17 does not prescribe a specific risk matrix or a particular review cadence; it requires the provider to demonstrate the system is effective.
The de-facto UK healthcare standard for risk scoring is the NHS 5x5 risk matrix (likelihood from 1 to 5 against consequence from 1 to 5; product gives the score from 1 to 25; thresholds set the rating). It originates with the National Patient Safety Agency and is currently maintained by NHS England. It is not statutory but it is the framework inspectors and commissioners expect unless the provider has a defensible reason to use another. The ISO 31000:2018 risk management principles sit underneath.
For independent secondary care and NHS-contracted services, the register is also a procurement deliverable: commissioners ask to see it, and the cadence of board- level review is one of the items raised when a commissioner reviews a provider's assurance trail.
Score a risk on the NHS 5x5 matrix
Pick a likelihood and a consequence. This is the exact matrix Verivius computes on every risk, and it is what sets the review cadence so the register never goes stale. Consequence runs across; likelihood runs down.
Possible likelihood, Moderate consequence
Possible: Might happen from time to time; there is a reasonable chance it will occur. Moderate: An injury or illness needing professional treatment, with a longer recovery.
Score 9 out of 25: High
Verivius default review cadence for a high risk: reviewed every 90 days. Inside the platform the review fires automatically on that cadence and surfaces on the dashboard, so it never drifts stale.
NHS Risk Matrix (5×5 likelihood × consequence), as documented in NHS published risk management guidance (originating with the National Patient Safety Agency, currently maintained by NHS England) and aligned with ISO 31000:2018 risk management principles. Verivius uses this as the v1 default because it is the de-facto healthcare-sector standard in England. Tenant-customisable matrices are a v1.5 feature.
This calculator uses the same scoring engine that runs inside Verivius. See how the full risk lifecycle works.
What each level means
The score is likelihood multiplied by consequence, so both axes have to mean the same thing to everyone who touches the register. These are the standard NHS 5x5 descriptors. Judge likelihood against your own service, and score consequence on the most serious outcome that could credibly happen, not the outcome you think is most likely.
Likelihood, 1 to 5
How probable it is that the risk happens.
- 1Rare
- Would only happen in exceptional circumstances; you would not expect it to occur.
- 2Unlikely
- Not expected to happen, but it could occur occasionally.
- 3Possible
- Might happen from time to time; there is a reasonable chance it will occur.
- 4Likely
- Will probably happen, and may recur. Sometimes called probable.
- 5Almost certain
- Expected to happen, and to recur, in most circumstances.
Consequence, 1 to 5
How serious the harm is if the risk happens.
- 1Negligible
- No injury, or harm needing no treatment or first aid only.
- 2Minor
- A minor injury or illness needing minor treatment, with a short recovery.
- 3Moderate
- An injury or illness needing professional treatment, with a longer recovery.
- 4Major
- A major injury or illness leading to long-term incapacity or permanent disability.
- 5Catastrophic
- Death, or several people permanently or severely harmed.
Consequence is scored here on harm to people, the primary domain for a care register; the same matrix can also grade impact on service delivery, finances or reputation. Scoring the same risk the same way at every review is what lets an inspector read the trend rather than the noise.
What providers most often miss
Across the inspection portfolio Klaudiusz worked over thirteen years inside CQC, three risk-register patterns showed up most often.
One: the register is a snapshot, not a workflow. The risks were identified on a single workshop day eighteen months ago. Each row carries the initial assessment from that day and has not been touched since. The review-cadence column says quarterly but the last reviewed-on date is from the original workshop. An inspector reads the register, sees the stale dates, and concludes the system is not in use. The point of the register is the recurring conversation; the document is a side effect.
Two: the controls column is generic. Entries read “training” or “policy review” without naming the specific training module, the specific policy, or the named owner. When the inspector samples one risk and asks what the specific control looks like, the team cannot evidence it. Generic controls do not reduce risk; they describe an aspiration.
Three: the link between the register and the other lifecycles is missing. An incident logged in your incident reporting software maps to a registered risk. The incident is investigated and closed; the register entry is not updated. A complaint surfaces a theme that matches a risk; the register entry stays static. The point of the register is that the day-to-day lifecycles feed it with evidence of whether the controls are working. A register disconnected from incidents, complaints, and safeguarding is reading-room compliance, not risk management.
What an inspector looks for in the register
The standard inspector reading is at three levels: the register as a whole, two or three sampled rows in depth, and the cross-reference to the day-to-day lifecycles. At the whole-register level the test is whether the review-cadence column reflects what actually happened (last-reviewed dates within the stated cadence, not stale).
At the sampled-row level the test is whether the inspector can trace from the residual risk grade back to the specific controls, and from the controls forward to evidence of effectiveness (training completion rates, audit results, near-miss frequency). A high-rated risk with generic controls and no evidence of effectiveness is a Reg 17 well-led concern.
At the cross-reference level the test is whether the register reflects what the team is seeing on the ground. If the incident log shows three falls in the last quarter, does the falls risk on the register have a recent review date and updated control assessment? If the complaints log shows a theme on consent quality, is consent on the register with current controls? The absence of cross-reference is the signal that the register is a document rather than a workflow.
For board-level oversight (Reg 17 well-led on independent hospitals), the inspector also asks how the top-rated risks featured in the most recent board or equivalent governance meeting. The minutes should show the register-level discussion; if the minutes are silent on risks the register grades as high or extreme, either the register grading is wrong or the board is not exercising the risk-oversight function. If you want that reading before CQC gives it, a mock inspection with an ex-CQC inspector puts it in writing against the five key questions.
How the risk register software works in Verivius
Verivius gives CQC-regulated providers risk register software with NHS 5x5 scoring and a review cycle that stays visible. Each risk moves through identification, assessment, treatment, monitoring and closure. The score and rating are calculated automatically, controls have named owners and effectiveness grades, and every decision is recorded in the audit trail. Reviews surface on the dashboard when due. Links to incidents, complaints, safeguarding concerns and improvement actions show whether the controls are working in practice. For the full feature walk-through see what Verivius actually does.
See also the Day-to-day use section on the FAQ for the short answers across every lifecycle.
Common questions on the risk register
How do you assess whether a risk register is effective?
Effectiveness is not about the document. Reg 17 asks whether the system for assessing, monitoring and mitigating risk actually works. Five checks an inspector applies:
- every open risk has a named owner and a next-review date;
- the highest-rated risks are reviewed on their cadence, with nothing overdue;
- residual risk sits below inherent risk, so the controls demonstrably reduce exposure;
- the register moves when real incidents or complaints happen, rather than sitting static;
- a board or governance lead can name the top risks and explain the current mitigation without preparing.
NHS-funded services are held to the same outcome through their contract, using the NHS 5x5 grading the register already applies. A register that passes all five is effective; one that fails on overdue reviews or static grades is a document, not a system.
Does CQC require a specific risk matrix?
No. Reg 17 sets the outcome (an effective system for assessing, monitoring and mitigating risk) but does not prescribe a matrix. The NHS 5x5 matrix is the healthcare-sector default; providers who choose a different matrix should be able to explain why, particularly when commissioned by NHS-funded organisations who themselves use the NHS 5x5 internally.
How often should we review each risk?
The platform default cadence by rating is extreme risks reviewed every 30 days, high every 90 days, moderate every 180 days, and low every 365 days. These are Verivius operational defaults derived from common UK healthcare practice; they are not statutory. Each tenant can override the cadence per rating in workspace settings if a more or less frequent cadence is justifiable. The point is that the review actually happens on whatever cadence the service commits to.
What is the difference between a risk and an improvement action?
A risk is a recognised possibility of harm with an assessed likelihood and consequence; an improvement action is a specific thing to do that addresses a known issue. The lifecycle of a risk is identify- assess-treat-monitor-close; the lifecycle of an action is plan-do-review-close. The two interact: risk treatments often spawn improvement actions, and completed actions feed back into the risk monitor step. The platform links the two so the audit trail is consistent.
Should every clinical risk be on the register?
Not every clinical risk; the recognisable ones with service-level implications. Day-to-day clinical decisions sit in care plans and clinical pathways, not the risk register. The register captures the service-level risks (workforce, equipment, regulatory, environmental, financial) where the board or equivalent governance group needs to see the residual risk grade and the controls. A register cluttered with case-by-case clinical detail loses the service-level visibility it exists for.
Can we accept a high-rated risk?
Yes, with documented rationale and a defined acceptance window. Reg 17 does not require all risks to be eliminated; it requires the provider to manage them. An accepted risk needs a named decision-maker, a clear reason, an acceptance-until date, and a re-assessment trigger if circumstances change. The platform captures all four at the moment the acceptance step is taken so the audit trail is clean.
See how the risk lifecycle works inside Verivius
A 20-minute conversation walks through the NHS 5x5 matrix inside the platform, how reviews fire on cadence, and how risks link back to the incidents and complaints that evidence whether the controls are working. No demo deck.
Worth reading alongside: the clinical audit cycle and staying CQC inspection-ready, the two governance activities the register feeds; the improvement-action-plans page for how risk treatments and improvement actions interlock; and what an inspector reads in a risk register for the founder-voice essay.
Related sample policy template: Good governance (Reg 17) (Reg 17 sets the system-level risk-management duty the register operationalises).
Free to start, no card. A 14-day trial when you subscribe.
Last reviewed 18 July 2026