In today’s bulletin, Charlie shares his initial thoughts on the recently published UK National Risk Register and provides recommendations for how risk can be better prepared for.
This week, during one of my calls, it was mentioned that the new UK National Risk Register had been published on 14th July. It appears to have been released with little fanfare and has attracted surprisingly little comment from the resilience community. I therefore decided to examine the document and consider what it actually contains.
The title of this bulletin reflects my immediate reaction to discovering that the Register is 223 pages long. My first thought was whether the government was attempting to cover its own backside by including as many possible risks as it could. If one of those risks later materialised, and the country was found to be poorly prepared, the government could at least say, “The risk was included in the National Risk Register.”
I am already quite cynical about the government’s level of preparedness, and publishing such a comprehensive document allows it to claim that the risks have been identified, whether or not sufficient action has actually been taken to address them.
In this bulletin, I will examine the contents of the UK National Risk Register and consider whether my initial reaction is justified. Is it a useful reference and planning tool for resilience professionals, or is it mainly an exercise in window dressing?
The Contents
The UK National Risk Register begins by explaining its purpose as the public version of the government’s National Security Risk Assessment (NSRA). It describes how the UK’s risk landscape is changing and becoming increasingly interconnected, and what this means for national resilience.
The Register outlines 95 significant risks and explains how they are identified, assessed, and compared. This process uses reasonable worst-case scenarios, expert review, and ratings of likelihood and impact. It also recognises that national risks may affect different parts of the country in different ways.
The document emphasises that preparedness is a shared responsibility, involving: government, emergency services, businesses, voluntary organisations, communities, and individuals. It then presents the detailed risk assessments, covering threats and hazards, including: pandemics, terrorism, cyber and state threats, conflict, infrastructure and system failures, flooding, extreme weather, and disruption to essential services. Each assessment describes the relevant scenario, its possible consequences, and the preparations required to support response and recovery.
Comments on the UK National Risk Register
1. Reactive risk identification
Many of the new risks included in this year’s Register appear to relate to events that have already happened, such as the CrowdStrike IT outage in July 2024 and other data outages, or to near misses, such as attempted attacks on water infrastructure.
There seems to be little effort to anticipate emerging risks that have not yet materialised, either in the UK or elsewhere, and which have not already been highlighted by a near miss. To me, this suggests a lack of imagination.
For example, we know how dependent the UK is on technology owned and operated by American companies. If Microsoft withdrew its products and services from the UK, the effects would be enormous and would be felt across almost every part of the country and every sector of the economy.
Including such a scenario in a risk assessment might have implications for the UK’s relationship with the United States, so perhaps risks of this kind are excluded for political reasons. Whatever the explanation, the Register appears to approach the risk landscape cautiously rather than exploring more speculative, but potentially serious, threats.
2. Local risks
The document is presented as a national Risk Register, while local risk assessments are owned by Local Resilience Forums in England and Wales and Regional Resilience Partnerships in Scotland. The Register is intended to support not only individuals, but also critical national infrastructure organisations and businesses of all sizes.
However, the relevance of the risks will vary greatly depending on where an organisation is based. If I were running a business on the Isle of Coll in the Hebrides – where I am today – many of the risks in the Register might appear far more remote than they would to a business located in central London.
With the use of AI, we now have the ability to produce tailored local risk assessments. These could be far more useful to organisations than requiring them to work through 223 pages of risks, many of which may have little relevance to their location or circumstances. Perhaps this is planned for the future, but I believe it should be introduced soon.
3. Avoiding political risks
Immigration and refugees are currently controversial and polarising subjects. Any risk assessment that addressed them directly would be closely scrutinised by the press and political parties.
One risk that appears to be missing is the possibility of a very large influx of refugees caused by conflict. We have already experienced significant refugee movements as a result of the Syrian war and, more recently, the war in Ukraine.
If Ukrainian forces were to collapse and Russia took control of the country, huge numbers of people could flee to other European countries, with Britain also affected. I suspect this risk has not been included because it would be politically difficult to address.
4. Polycrisis, cascading risks, and risk interaction
The Register presents a series of individual risks. Although it acknowledges that risks may interact with one another and create unexpected consequences, the document remains largely focused on separate events.
Our lives, critical national infrastructure, and supply chains, are highly interconnected. Disruption in one area can therefore trigger cascading effects elsewhere, creating consequences that may not have been anticipated.
The Register gives limited attention to situations such as the wider consequences of a war involving Iran. Such a conflict could increase the cost of fuel and fertiliser, which could then contribute to higher food prices the following year.
A polycrisis occurs when several interconnected events happen at the same time and combine to make the overall impact worse. A risk register built mainly around individual events may therefore fail to represent the true consequences of multiple risks interacting and compounding one another.
5. A government reputational lens
The Register assesses impacts across areas including human welfare, the economy, the environment, security, and international relations. However, when the list of risks is examined more closely, it appears to be shaped largely around the types of incident for which the government might be blamed, or which could damage its reputation if they occurred.
These are risks for which the government may ultimately be considered responsible. This may help to explain the rather eclectic collection of risks in the Register, which ranges from incidents with relatively limited consequences to those with potentially major impacts.
If a risk materialises, the government can say, “We anticipated this and included it in the National Risk Register”, while pointing to a thick, glossy document as evidence. Whether the incident would then be managed effectively is a different question.
6. Planning assumptions or scenarios
Each risk includes a reasonable worst-case scenario. I believe this is useful for organisations that have responsibility for planning for the event, as it provides some indication of the scale and severity for which they should prepare.
There is little value in two organisations planning for the same incident while interpreting its likely impact in completely different ways. The Register would therefore be more useful if it went further and provided clearer planning assumptions for organisations to consider.
For example, giving an approximate number of casualties would be more useful than referring only to ‘multiple casualties’. More specific assumptions would help organisations plan consistently, and reduce the risk of different agencies preparing for the same event on the basis of incompatible expectations.
7. Are risk registers pointless?
For many years before COVID-19, a pandemic appeared in the “top-right” section of government risk registers, meaning that both its likelihood and potential impact were assessed as high. Despite this, preparedness and response were poor.
If we know that an event is very likely to occur and that its impact could be enormous, should we not prepare for it more effectively?
Ultimately, identifying a risk is not the most important part of the process. What matters is how that information is used to improve preparedness. Organisations should focus their limited time, effort, and money, on preparing for the events most likely to happen, rather than devoting excessive resources to incidents that are extremely unlikely to occur.
Conclusion
My conclusion is that the UK National Risk Register is largely an exercise in window dressing and backside covering. The reports into the Manchester bombing, COVID-19, and Grenfell, have shown that government and response agencies can be woefully unprepared to manage major incidents. They have also shown that the same ‘lessons’ are identified repeatedly.
A National Risk Register is important, and it is undoubtedly better to have one than not to have one. However, to me this document represents a cheap and relatively effortless way of appearing to demonstrate preparedness. Producing a glossy, 223-page document is far easier than investing the hard work, time, and money required to ensure that, as a country, we are genuinely better prepared to manage the risks it contains.



