School Governance Risk Register: What Governors Should Track
Most schools have an operational risk register covering premises, health and safety, HR and curriculum delivery. Far fewer have a governance risk register - one that tracks risks sitting specifically within the governing board's own remit: that governance obligations won't be met, that evidence won't be in place, or that the board won't have the oversight it needs to do its job.
A governance risk register is not a duplicate of the operational register, and it isn't a subset of it either. It is a distinct tool, owned by the governing board, that focuses on governance effectiveness itself: whether the board is meeting its statutory responsibilities, whether it can evidence that it has, and whether the systems that support governance - policy review, finance reporting, safeguarding oversight, training, records - are actually working. This article sets out what a governance risk register should contain, the risks it should track across five key areas, and how to keep it current.
Section 1: What is a governance risk register?
A governance risk register is a living document that identifies, assesses and tracks risks specific to governance - not curriculum, not buildings, not HR. It covers risks such as:
- governance obligations not being met on schedule
- evidence not being in place to demonstrate governance activity
- the governing board not receiving the information it needs to exercise oversight
- accountability mechanisms - minutes, actions, approvals - failing to function as intended
Like any risk register, each entry is assessed for likelihood (low, medium, high) and impact (low, medium, high), given a current status, assigned an owner, and reviewed on a set cycle. The critical difference from an operational register is ownership: a governance risk register is owned by the governing board itself, not delegated to the headteacher or SBM, because the risks it tracks are risks to the board's own function. It should be reviewed at least once per term, ideally as part of a wider termly governance readiness review.
The sections below set out five risk areas that cover the great majority of governance risk in a typical maintained school or single-academy trust.
Section 2: Risk area 1 - Safeguarding governance risks
Safeguarding sits at the top of any governance risk register because the impact of failure is high even where likelihood is low. The board's safeguarding oversight role is distinct from the school's operational safeguarding practice - it is this oversight role, not the practice itself, that belongs on the governance risk register.
Common risks in this area:
- Safeguarding link governor visit not completed on schedule - oversight visits slip past their planned date with no reschedule.
- DSL/DDSL training not current - a gap in the single central record (SCR) that the board has not identified or actioned.
- KCSIE update not reviewed - a Keeping Children Safe in Education update is published but its policy implications are never assessed or actioned.
- Annual safeguarding review not completed or not documented - the board's yearly review of safeguarding governance either doesn't happen or happens without a written record.
- Governing board unable to evidence its safeguarding oversight role - even where oversight has genuinely taken place, nothing has been recorded to demonstrate it.
Safeguarding risks should generally be assessed as high impact regardless of likelihood, given the consequences of a genuine gap. What to track: link governor visit dates, DSL/DDSL training dates, annual review completion, and the status of the safeguarding evidence held in the school's evidence store. The annual safeguarding governance review checklist sets out the full review process that feeds this section of the register.
Section 3: Risk area 2 - Policy and compliance risks
Policy governance is one of the most common sources of governance risk, largely because a single overdue review can go unnoticed for months.
Common risks in this area:
- Policies overdue for review - not flagged until an inspection or audit brings it to light.
- Policy register not maintained - the governing board has no reliable way to confirm which policies are current and which are overdue.
- DfE guidance update received but policy implications not actioned - new statutory guidance arrives, but no one assesses which policies need amending as a result.
- School website not compliant with statutory publication requirements - required policies and information are missing or out of date on the public-facing site.
- SFVS not completed on time - applies to maintained schools only; the Schools Financial Value Standard return is a statutory annual requirement with a fixed deadline.
What to track: policy register review dates against a master schedule, a log of DfE guidance updates and whether each has been triaged for policy impact, and the date of the last website compliance review.
Section 4: Risk area 3 - Finance governance risks
Financial oversight is a core governance function, and gaps here are among the most serious findings in any governance review, because they go directly to the board's duty of scrutiny.
Common risks in this area:
- Finance committee reports not received on schedule - the governing board is not kept informed at the frequency its terms of reference require.
- Budget monitoring not presented - the board cannot evidence that it has exercised financial oversight during the term.
- SFVS not completed, or significant weaknesses identified - maintained schools only; academies use their own financial assurance framework instead.
- Governing board minutes do not evidence financial challenge or scrutiny - reports are received but minutes show no questioning, challenge or discussion, which weakens the audit trail of genuine oversight.
What to track: adherence of the finance report schedule to the terms of reference, SFVS completion status and date, and a periodic check of minute quality specifically for evidence of financial challenge. The finance governance best practice article sets out the wider finance oversight framework this risk area sits within.
Section 5: Risk area 4 - Board effectiveness risks
A governing board can only provide effective oversight if it is properly constituted, trained and supported. Risks here are often slow-moving but can undermine every other area of governance if left unaddressed.
Common risks in this area:
- Governor vacancies not filled - creating a quorum risk, or a gap in the skills mix the board needs.
- Governor training not completed - individual governors are not equipped for the responsibilities of their role.
- Clerk role vacant or unsupported - the meeting cycle, minute-taking and records are all put at risk without proper clerking capacity.
- Chair or vice-chair succession not planned - a sudden departure leaves the board without clear leadership continuity.
- Link governor roles not assigned or not active - designated oversight roles (safeguarding, SEND, finance, and others) exist on paper but aren't functioning.
What to track: currency of the governor register (terms of office, vacancies, skills audit), governor training completion against role requirements, and whether each link governor role is actively assigned and reporting.
Section 6: Risk area 5 - Evidence and records risks
Even where governance activity is genuinely happening, a board that cannot evidence it carries real risk - both at inspection and in its own ability to demonstrate accountability.
Common risks in this area:
- Governance evidence store not maintained - evidence exists in principle but cannot actually be produced when needed.
- Action log not updated - the governing board cannot demonstrate follow-through on decisions and actions.
- Meeting minutes incomplete or not approved - a broken audit trail, since unapproved minutes carry less evidential weight.
- Governor register out of date - a basic record that inspectors and auditors frequently ask to see, and one that is often allowed to drift.
What to track: the review date of the evidence store, how current the action log is against the last meeting, and the approval status of minutes across the year. A dedicated governance evidence log is the natural companion to this section of the risk register - while the risk register flags where evidence may be missing, the evidence log is where that evidence is actually indexed and stored.
Section 7: How to maintain the governance risk register
A governance risk register only has value if it is kept live. In practice, that means:
- Review it at least once per term - ideally as a standing item within the termly governance readiness review, rather than as a separate exercise that competes for time on its own.
- Give every risk a named owner - a person, not a committee, responsible for tracking that specific risk to resolution.
- Track current status clearly - open, mitigated or closed - so the board can see progress at a glance.
- Set a target date for resolution - an open-ended risk with no date tends to stay open indefinitely.
- Escalate red risks - any risk assessed as high likelihood and high impact should appear as a named agenda item at the next full governing board (FGB) meeting, not wait for the next scheduled review.
- File the register in the evidence store - the risk register itself is part of the governance evidence base and should be available alongside minutes, policies and training records, following the same evidence discipline covered in governance actions and follow-up tracking.
Building this rhythm into the school's wider governance systems - rather than treating the risk register as a one-off document - is what turns it from a compliance artefact into a genuinely useful oversight tool. This is the kind of recurring discipline a proper governance operating system is designed to support.
A sample governance risk register template
The table below sets out a starting template, pre-populated with ten of the most common governance risks drawn from the areas above. Governing boards should adapt likelihood, impact and status to their own circumstances.
| Risk area | Specific risk | Likelihood | Impact | Current status | Owner | Target date | Notes |
|---|---|---|---|---|---|---|---|
| Safeguarding | Safeguarding link governor visit overdue | Medium | High | Open | Safeguarding link governor | End of term | Reschedule via clerk |
| Safeguarding | DSL/DDSL training gap on SCR | Low | High | Open | Headteacher / Chair | Next FGB | Confirm training booking |
| Policy | Policy register incomplete | Medium | Medium | Open | Clerk to governors | 4 weeks | Cross-check against policy calendar |
| Policy | Website statutory compliance not checked this year | Medium | Medium | Open | SBM | Next FGB | Use published compliance checklist |
| Finance | Finance committee report missed this term | Low | High | Mitigated | Finance committee chair | Closed | Rescheduled and received |
| Finance | SFVS not yet completed (maintained schools) | Medium | High | Open | SBM / Chair | Statutory deadline | Maintained schools only |
| Board effectiveness | Governor vacancy - skills gap in finance | High | Medium | Open | Chair | Next recruitment cycle | Advertise via NGA/local authority |
| Board effectiveness | Clerk role unsupported (part-time capacity) | Medium | High | Open | Chair | Ongoing | Review clerking capacity |
| Evidence | Action log not updated since last FGB | Medium | Medium | Open | Clerk to governors | Immediate | Update before next meeting |
| Evidence | Minutes from last committee meeting unapproved | Low | Medium | Open | Committee chair | Next FGB | Approve at next meeting |
FAQ
How is a governance risk register different from the school's main risk register? The main operational risk register covers risks to the school's day-to-day running - premises, health and safety, HR, curriculum delivery - and is typically owned by the headteacher or SBM. A governance risk register is narrower and specific to the governing board itself: it tracks the risk that governance obligations, evidence and oversight mechanisms will fail, and it is owned by the board, not the headteacher.
How often should the governance risk register be reviewed? At least once per term. Many boards fold this into a wider termly governance readiness review rather than running it as a separate standalone exercise.
Who should own the governance risk register? The governing board as a whole, usually coordinated by the chair with support from the clerk to governors. Individual risks within the register should each have a named owner responsible for tracking that item to resolution.
Does the governance risk register need to be shown at inspection? There is no statutory requirement to produce a governance risk register for inspection, but a well-maintained one can be a useful way to demonstrate that the board actively manages its own governance effectiveness. Inspectors may ask how a governing board identifies and manages its own governance gaps, and a live risk register is direct evidence of that process.
Book a governance assurance demo
Keeping a governance risk register current means linking it to the evidence, actions and reviews that actually resolve each risk - not maintaining it as a static document that goes stale between meetings. Book a demo to see how Edvance helps governing boards track governance risk alongside evidence and actions in one place.
Jurisdiction note
This article is written for maintained schools in England and single-academy trusts following a similar governance structure. Multi-academy trusts have additional trust-level governance risks - around scheme of delegation, trust board oversight of local governing bodies, and trust-wide risk reporting - that are not covered here and should be tracked separately at trust level. The Schools Financial Value Standard (SFVS) applies to maintained schools only; academy trusts should substitute their own financial assurance framework in the finance governance risk area.
Frequently Asked Questions
How is a governance risk register different from the school's main risk register?
The main operational risk register covers risks to the school's day-to-day running - premises, health and safety, HR, curriculum delivery - and is typically owned by the headteacher or SBM. A governance risk register is narrower and specific to the governing board itself: it tracks the risk that governance obligations, evidence and oversight mechanisms will fail, and it is owned by the board, not the headteacher.
How often should the governance risk register be reviewed?
At least once per term. Many boards fold this into a wider [termly governance readiness review](/resources/governance-readiness/termly-governance-readiness-review-schools) rather than running it as a separate standalone exercise.
Who should own the governance risk register?
The governing board as a whole, usually coordinated by the chair with support from the clerk to governors. Individual risks within the register should each have a named owner responsible for tracking that item to resolution.
Does the governance risk register need to be shown at inspection?
There is no statutory requirement to produce a governance risk register for inspection, but a well-maintained one can be a useful way to demonstrate that the board actively manages its own governance effectiveness. Inspectors may ask how a governing board identifies and manages its own governance gaps, and a live risk register is direct evidence of that process.