Most mature risk programs don’t think in terms of “one big list.” They think in terms of regions, product lines, and business units—APAC versus global, Product A versus Product B, enterprise-wide strategic risks versus more localized issues.
When everything is forced into a single register:
Ownership gets blurry as different teams crowd into the same view.
It’s hard to separate what’s happening in one region or product from the rest of the business.
Reporting turns into manual filtering, exporting, and reconciling just to answer basic questions.
At the same time, risks rarely line up cleanly with a single system or workspace. A single risk—like an outage scenario in APAC—can span multiple products, services, and teams. If your tools only see part of that picture, it’s harder to understand where controls are mapped, who owns what, and what your actual exposure looks like.
Risk leaders need two things at once:
Structure that reflects how they actually manage risk (by region, product, or business unit).
A unified view that still shows the full risk picture across all of those slices—without duplicating effort or losing control of configuration.
Shape Your Risk Registers Around How You Actually Operate
As part of Drata’s Integrated Risk Management capability on the Agentic Trust Management Platform, Multiple Risk Registers in Risk Management Pro gives teams a way to mirror how they run their programs—while keeping a unified, continuously visible view of overall exposure across registers and workspaces.
This capability is available to customers with Risk Management Pro enabled and includes updates across roles, navigation, register setup, and analytics.
Give Every Register a Clear, Accountable Owner
In role administration, a new Risk Register Owner role lets you assign day-to-day ownership at the register level:
Risk Register Owners can manage all risks within the registers they own.
They cannot change global risk settings, which stay with existing Risk Manager–type roles.
This is designed to sit alongside your current model:
Existing roles like risk owner and restricted risk manager continue to control which individual risks a user can see or act on.
Combined, this gives you clear boundaries: global configuration in one place, register-level ownership in another, and risk-level permissions on top—so only the right people have access to each register and its risks.
See Every Risk—No Matter Which Register It Lives In
The Risk area now makes it easy to move between a unified view and register-level detail:
All Risks gives each user a consolidated list of all risks across all registers they have permission to see, using the same access model and filters they’re used to.
Registers shows a list of the registers they can access, with the ability to drill into a specific register or create a new one.
If no registers have been created yet, the Registers view will simply appear empty until you stand up your first one.
In Risk Insights, register becomes a first-class filter:
Filter by one register to see that slice of your program on its own.
Combine multiple registers to see a rollup across, for example, APAC and Enterprise.
Clear filters to see an aggregate view across all registers.
You use the same familiar filters (status, severity, and more), with register acting as another dimension for analysis.
Create Registers for Regions, Products, or Business Units
From the Registers view, you can stand up new registers that reflect how your team actually works:
Give each register a clear title (for example, “APAC Risks” or “Enterprise Risks”).
Add an optional description for additional context.
Choose whether to associate controls to risks in that register (this is selected by default and is generally recommended).
If Workspaces are enabled, optionally associate one or many related workspaces with the register.
Optionally assign one or more register owners.
The design is intentionally flexible:
You’re not limited to a one-register-per-workspace model.
A single register can span multiple workspaces—such as an APAC register that applies to several product workspaces.
Only workspaces a user already has access to will appear in the related Workspaces selection. If your tenant doesn’t use Workspaces, that field simply doesn’t appear.
Every register starts with the standard template library of risk scenarios, and that library is the same across registers, so you can keep scenario definitions consistent while you add more structure.
Reorganize Existing Risks Without Starting Over
If you already have a single, established register, you don’t have to start from scratch.
With Multiple Risk Registers, you can:
Select risks in an existing register (for example, Enterprise Risks) and move them into a new register (such as APAC Risks).
Move multiple risks at once—those risks are removed from the original register and now live in the new one, maintaining a single source of truth.
Today, risks cannot be copied so that they exist in multiple registers simultaneously. If you need to represent a similar scenario in more than one register, you can create a new risk in the destination register, or import risks into another register via CSV.
Within any register, you can add new risks in two ways. Either one by one through the standard create-risk flow (choosing the risk source—internal or vendor—setting status, title, and other required details), or in bulk via CSV upload.
The core create-risk experience remains the same, Multiple Risk Registers just adds structure on top of what you already know.
Connect Each Risk to the Right Controls Across Workspaces
Multiple Risk Registers also extends how risks connect to controls and Workspaces.
When you create or edit a risk, you can:
Map the risk to controls by framework (for example, all controls associated with SOC 2 requirements).
Filter the available controls by one or more of the workspaces related to that register.
Leave the workspace filter blank to see controls across all related workspaces.
This makes it possible for a single risk to be mapped to controls across multiple workspaces. In the APAC example, one APAC risk can be associated with controls from several product workspaces if that’s how the organization truly mitigates that risk.
Workspace behavior for risk is handled inside the feature itself:
The workspace picker at the top of the app does not control what appears in Risks and Registers.
Changing the global workspace selector will take you back to the dashboard, but it won’t change which registers or risks you see.
Instead, workspace scoping for risk is driven by each register’s related Workspaces and the controls those workspaces contain.
Keep Scoring and Categories Consistent as You Scale
To keep assessments comparable across the program, core configuration stays global:
Custom scoring models, categories, and thresholds defined in risk settings apply to all registers; there is no per-register scoring or categorization in this release.
Custom fields created for risks also apply across every register.
That means you can introduce new registers, move risks between them, and scale your structure without fragmenting how risks are scored or categorized. Governance stays centralized, while execution becomes more segmented and manageable.
How Multiple Risk Registers Changes Your Day-to-Day
Enterprise GRC Director
Problem: Needs to see risk across regions and product lines, but a single register makes it hard to distinguish what’s happening in APAC versus globally.
Solution: Create separate registers (for example, APAC and Enterprise), associate them with the right workspaces, and use All Risks and register filters in Insights to move between segmented and rollup views.
Outcome: A clearer picture of regional versus enterprise risk without maintaining separate tools or manual rollups.
Risk Director or Risk Manager
Problem: Wants to segment risks into meaningful domains (APAC, Enterprise, specific products) and assign accountable owners—without handing out broad configuration access.
Solution: Use the Risk Register Owner role to give specific teams ownership over their registers, while keeping global scoring, categories, and thresholds in central Risk Management roles.
Outcome: Local teams manage their own registers day-to-day, while overall governance remains consistent and centrally controlled.
GRC or Security Program Owner / Admin
Problem: Already has a populated single register but needs more structure without re-implementing everything.
Solution: Stand up new registers, move existing risks into them, or import via CSV, all while reusing the same templates, risk settings, and custom fields.
Outcome: A more organized, multi-register risk program with minimal rework and no loss of historical data or configuration consistency.
The Business Impact: Structure, Visibility, and Control
Multiple Risk Registers is designed to improve both how risk teams work and how leaders see their posture with:
Programs structured the way you actually operate. Registers can mirror regions, products, or business units instead of forcing everything into one list, and ownership and workflows become clearer at the register level.
Unified, continuous visibility across the program with All Risks and register-aware Insights that let you see aggregate and per-register views in one place, and risk posture stays continuously visible across regions, products, and workspaces instead of being fragmented across tools or spreadsheets.
Less manual reconciliation and fewer fire drills thanks to flexible mapping between risks, controls, and Workspaces means you don’t have to maintain duplicate lists or workarounds when risks span multiple areas. Global settings keep scoring and categories aligned, reducing configuration drift over time.
Tighter access and accountability via the combination of Risk Register Owner, risk owner, and restricted risk manager roles ensures the right people have access to the right registers and risks. No more all-or-nothing access.
Why Drata Stands Out
Multiple Risk Registers is part of Drata’s broader approach to Integrated Risk Management on the Agentic Trust Management Platform:
Enterprise-grade flexibility: Many-to-many relationships between registers and Workspaces (one register to many workspaces, and one risk to controls across multiple workspaces) match the complexity of modern organizations instead of forcing a one-register-per-workspace compromise.
Centralized governance, decentralized execution: Global scoring models, categories, thresholds, and custom fields apply across all registers, while register-level ownership and structure stay close to the teams that manage the work.
One platform for a complete view of risk: All Risks and register-aware Insights give leaders a clear, consistent lens on risk across regions, products, and business units—without stitching together exports or external spreadsheets.
It’s a focused release that deepens Drata’s role as the place where risk is not only documented, but structured, owned, and continuously visible across the business.
Bringing It All Together
Risk programs don’t stand still. As you add regions, products, and teams, the way you organize risk has to evolve too.
Multiple Risk Registers in Risk Management Pro lets you:
Reflect your organizational reality with registers that match how you operate.
Keep a single, unified picture of risk across all those registers and workspaces.
Maintain consistent scoring and configuration as your program grows.
If you’re ready to start structuring your risks with Multiple Risk Registers, connect with your Drata account team or admin to plan your first set of registers and how to roll them out across your environment. Not a Drata customer yet? Schedule a demo to learn more.