Record what could go wrong
Not everything can be read from a cloud environment. This is the part you record yourself, in a form that survives an audit.
Risk register
From a list of risks to a file that holds up.
Every risk gets its own reference, a likelihood and an impact scored separately, and a treatment: mitigate, accept, transfer or avoid. Accept a risk and the register records who did so on behalf of the organization. That is the question an audit presses on, because an accepted risk with no name under it was not accepted, it was forgotten.
A risk register in a spreadsheet usually does not survive the first audit, not because the content is wrong but because nobody can show when a line changed and who changed it. Here the register also connects to the rest: a requirement you exclude in your Statement of Applicability is linked to the risk that carries the exclusion.
Incident register
The reporting chain keeps running, weekends included.
A reportable incident has three moments: an early warning within 24 hours, a full notification within 72 hours and a final report no later than one month after that first notification. The register tracks all three clocks from the moment you record the incident, and warns you before one of them runs out.
It also records severity, status and how the incident developed, so afterwards you can show what you knew when and when you acted. Reconstructing that story from a mailbox rarely works, and it is exactly what a regulator asks for.
Vendor register
Know who touches your data, and on what terms.
Per vendor you record what data they process, whether personal data is involved, how critical the service is to you, where the processing happens and whether a data processing agreement is in place. Vendor certifications go in with their expiry date, so a lapsed certificate stands out before a customer asks about it.
This register is also where several standards land at once. Your supply chain risk under NIS2, your outsourced services under DORA and your subprocessors under GDPR all come out of the same list, and that list can be published on your trust page with one choice.
