FS-DOC-03Operations
Process Runbook / SOP
Risk Register Management
[YourCompany.com] · Management Department · Prepared by FullSpec · [Today's Date]
This runbook is the day-to-day operating guide for the Risk Register Management automation. It tells you exactly what the system does on its own, where your team needs to act, how to handle things when something goes wrong, and who to call when you need help. FullSpec has built, tested, and launched this automation end to end. Your role is to manage the one human decision point and keep the configuration details current as your team changes.
01Process overview
Risk Register Management is the ongoing work of capturing new risks as they are identified, scoring them against your agreed risk matrix, notifying the responsible owner, chasing overdue reviews, escalating anything critical, and publishing a monthly summary to leadership. Before automation, this process consumed roughly five and a half hours of the risk manager's time every week and still left the register out of date. The automated flow replaces all ten of the original manual steps with three targeted agents, retaining one human review point for risks the scoring agent flags as critical. The register is now updated in near real time, owners are nudged automatically, and the monthly report writes and distributes itself.
Process name
Risk Register Management
Trigger
A new risk is submitted via Google Forms, or a risk item reaches its scheduled review date in the register
Final output
An up-to-date Google Sheets risk register, Slack and email notifications to owners, and a published Notion leadership report distributed monthly
Agents running
Risk Intake and Scoring Agent; Review Chase and Escalation Agent; Risk Reporting Agent
Tools involved
Google Forms, Google Sheets, Slack, Gmail, Notion
Weekly volume
Approximately 40 risk items reviewed or updated per month, with ad-hoc new submissions throughout the week
Human checkpoint
Risk manager reviews and approves any risk the scoring agent rates as critical before it is escalated or published
Process owner
[Your name] — Risk Manager
Process Runbook / SOPPage 1 of 4
FS-DOC-03Operations
02Step-by-step: what happens and who acts
What you actually need to do: There is one human step in this entire process. When the Risk Intake and Scoring Agent flags a risk as critical, you will receive an email and a Slack notification asking you to review the proposed score and either approve it or override it before the system escalates further. Everything else runs automatically. You do not need to enter risks, chase owners, update scores, or prepare the monthly report.
Step
What happens
Who acts
Type
1
A team member submits a new risk using the Google Forms intake form. The form captures the risk description, category, submitter name, and any supporting context.
Team member
Human
2
The automation receives the form submission and immediately writes a new row to the Google Sheets risk register, recording the description, category, date raised, submitter, and a timestamp. No manual data entry is needed.
Risk Intake and Scoring Agent
Automated
3
The Risk Intake and Scoring Agent reads the risk description and applies the agreed likelihood and impact matrix. It proposes an initial score for both dimensions and calculates the overall risk rating, writing all three values to the register row.
Risk Intake and Scoring Agent
Automated
4
If the proposed score does not reach the critical threshold, the automation sends the assigned risk owner a Slack message containing the risk details, the proposed score, and a direct link to the register row. The owner is asked to confirm or adjust the score within 48 hours.
Review Chase and Escalation Agent
Automated
5
If the proposed score is flagged as critical, the system pauses escalation and sends the risk manager a notification by both Slack and email. The risk manager reviews the proposed score, makes any adjustments, and approves it before the automation continues. This step takes approximately 10 minutes.
Risk Manager (you)
Human
6
If a risk owner has not responded within 48 hours of their Slack notification, the Review Chase and Escalation Agent sends a follow-up Slack message. If there is still no response after a further 24 hours, a formatted escalation email is sent to the risk manager and copied to the relevant department head.
Review Chase and Escalation Agent
Automated
7
Once the owner confirms or overrides the proposed score, the automation writes the updated likelihood, impact, and rating values back to the Google Sheets register, along with the reviewer name and a review timestamp, creating a full audit trail.
Risk Intake and Scoring Agent
Automated
8
On the last business day of each month, the Risk Reporting Agent pulls the current state of the full register, calculates the risk heat map, identifies the top risks by rating, and writes a formatted leadership summary directly into the agreed Notion page.
Risk Reporting Agent
Automated
9
The automation emails a link to the completed Notion report to everyone on the stakeholder distribution list and posts a summary excerpt in the designated Slack channel, so leadership has visibility without needing to check Notion manually.
Risk Reporting Agent
Automated
10
The automation saves a dated snapshot of the register to a designated archive tab in Google Sheets at the end of each monthly cycle, maintaining a complete audit trail without any manual file-saving.
Risk Reporting Agent
Automated
Process Runbook / SOPPage 2 of 4
FS-DOC-03Operations
03Handling exceptions
Situation
What the system does
What you do
A risk form submission is missing required fields (for example, no description or no category selected)
The automation detects the incomplete submission and sends an automated reply to the submitter via Gmail asking them to resubmit with the missing information. The incomplete row is flagged in the register as Draft and is not scored until the gap is filled.
No immediate action needed. If the submitter does not resubmit within 48 hours, the system sends you a daily digest of unresolved Draft entries. Review the list and follow up with the submitter directly if the risk appears genuinely important.
A duplicate risk is submitted that closely matches an existing open register item
The intake agent compares the new submission against open register rows. If a match above the similarity threshold is detected, the new submission is flagged as a Possible Duplicate and held without creating a new row. Both the submitter and the risk manager are notified via Slack.
Review the flagged pair in the register. If they are genuinely the same risk, dismiss the duplicate in the register so the submitter receives a confirmation. If they are distinct risks, mark the new one as Confirmed New and the intake agent will score and process it immediately.
The scoring agent cannot determine a risk category or produce a confident score from the submission text
The agent sets the risk rating to Unscored and flags the row in the register with a yellow status indicator. A Slack notification is sent to the risk manager explaining that the submission needs manual scoring.
Open the register row, review the risk description, and apply the likelihood and impact scores manually using the risk matrix. Update the status from Unscored to Scored. The automation then proceeds with owner notification as normal.
A risk owner does not respond to the initial Slack nudge or the 48-hour follow-up, and the escalation email receives no reply within a further 24 hours
The Review Chase and Escalation Agent marks the item as Escalation Unresolved in the register and adds it to the next daily digest sent to the risk manager. No further automated chasing occurs beyond this point to avoid notification fatigue.
Contact the risk owner directly by whatever means works for your team, phone, meeting, or direct message. If the owner is unavailable, reassign the risk to a covering colleague by updating the owner field in the register. The automation will send the new owner a Slack notification immediately.
A risk is updated by a team member outside the automated flow (for example, someone edits the Google Sheet directly)
The automation detects the change on the next scheduled register scan and logs a change record in the audit tab, noting the field changed, the previous value, the new value, and the edit timestamp. No score is recalculated automatically from a direct edit.
If the direct edit was intentional, no action is needed. If you want the agent to re-score the item after a description change, update the Status column in that row to Re-score Requested. The intake agent will pick this up on its next run and propose a revised score.
Google Sheets, Slack, Gmail, or Notion is unavailable due to an outage or connectivity issue
The automation platform queues all pending actions and retries them automatically at five-minute intervals for up to two hours. If the tool remains unavailable after two hours, the system sends an alert email to the risk manager and logs the failure in the error record tab of the register.
Check the status page for the affected tool (status.google.com for Sheets, Forms, and Gmail; slack.com/intl/en-gb/release-notes for Slack; notion.so/releases for Notion). If a critical risk is waiting to be escalated and the outage is prolonged, escalate it manually by emailing the risk manager and relevant department head directly. Contact FullSpec support at support@gofullspec.com if the automation does not resume within four hours of the tool recovering.
Process Runbook / SOPPage 3 of 4
FS-DOC-03Operations
04Who to contact and when
Fill in the owner team rows once your team is confirmed. Keep this table updated whenever roles or contact details change, and share the updated version with FullSpec so notification routing stays accurate.
Role
Name
How to reach them
Process owner (Risk Manager)
[Your name]
[Your email or Slack handle]
Backup risk manager (for cover periods)
[Rep name]
[Rep email]
Operations Manager
[Your name]
[Your email]
IT or system access contact (for tool credential issues)
[Your name]
[Your email]
FullSpec builder
FullSpec team
support@gofullspec.com — for automation logic changes, agent reconfiguration, or build issues
FullSpec support
FullSpec support
support@gofullspec.com — for errors, unexpected behaviour, outage recovery, or general questions about how the automation works
If a risk flagged as critical is sitting unresolved and you cannot reach anyone on this list, escalate it manually to the most senior person available in your organisation. Do not wait for the automation to retry if the risk has genuine business impact.
05Ongoing maintenance
Whenever a risk category, likelihood scale, or impact scale changes
Send the updated risk matrix definition to FullSpec at support@gofullspec.com. The scoring logic inside the Risk Intake and Scoring Agent must be updated to reflect the new thresholds before any new submissions are processed. Do not change the scoring columns in Google Sheets directly without confirming the agent has been updated first.
Risk Manager plus FullSpec team
Whenever the Notion report template changes (new sections, removed sections, or revised layout)
Agree the new format with the leadership team first, then contact FullSpec to reconfigure the Risk Reporting Agent. Give at least five business days before the next scheduled monthly report run to allow time for testing.
Risk Manager plus FullSpec team
Monthly spot-check (first week of each month)
Open the risk register in Google Sheets and review the previous month's activity log. Confirm that all new submissions were scored and progressed, that no items are stuck in Draft or Unscored status, and that the monthly Notion report was published and received by all stakeholders. Flag any anomalies to FullSpec.
Risk Manager
Weekly error-log review (every Monday morning)
Check the Error Record tab in the Google Sheets register. The automation writes a row here whenever a step fails or a retry is exhausted. Review any new entries, note the affected risk item and the tool involved, and contact FullSpec if the same error appears more than twice in a week.
Risk Manager
When a team member joins, leaves, or changes role
Update the owner routing table maintained by FullSpec by emailing support@gofullspec.com with the change. Also update the stakeholder distribution list for the monthly report. If a departing team member owns open risk items, reassign them in the register immediately so Slack nudges route to the correct person.
Risk Manager plus FullSpec team
Quarterly volume review (every three months)
Compare actual monthly risk volume against the baseline of 40 items per month used to configure the automation. If volume has grown significantly (above 70 items per month) or dropped below 10, contact FullSpec to review whether the current plan and scheduling intervals remain appropriate.
Operations Manager plus FullSpec team
The single most common maintenance issue for this process is a stale owner routing table. When a risk owner leaves the business or changes role, their Slack handle or email may no longer be valid. The automation will continue sending nudges to the old address with no error visible to you, and the risk goes unreviewed. Update the owner list with FullSpec every time a relevant team member changes, and do a full owner audit at each quarterly review.
Process Runbook / SOPPage 4 of 4