How to Write a Risk Finding That Gets Funded

How to Write a Risk Finding That Gets Funded

Your risk register probably already lists the gap you're most worried about. It has a likelihood rating, an impact rating, and a review date. None of that has been enough to fund it. 

That's not a formatting problem. A register is built to compare gaps against each other at a glance, so it strips out exactly the detail that would make any one of them stand out: who's actually affected, what the actual mechanism is, and what somebody would have to say out loud if it went wrong. Fix that, and the same gap reads completely differently, without a single new fact. 

Here's how to rewrite one entry, and why it beats almost anything else you can do with an afternoon and no new data. 

Turn the Category Into a Sentence 

Pick one gap from your register. Not the whole list, just one, ideally the one you'd defend hardest if someone asked why it's still open. 

Answer three questions about it, in order: 

Who would actually have to explain this, and where? Not a category of person. A specific forum: the audit committee, a post-incident review, a board risk update. If you can't picture the room, you haven't found the real stakes yet. That room got a lot more concrete this year: the IIA's new Third-Party Topical Requirement gives internal audit an actual checklist to test your program against. See what the standard actually requires → 

What's the actual mechanism, not the risk category? "Exposed to fraud risk" is a category. "Nobody checks whether a bank-detail change came from the real vendor" is a mechanism. The mechanism is what you're missing on the register right now. 

What's the real reason it's still open? Usually it's a funding decision, sometimes an ownership decision. Either way, name it. This is the part almost everyone leaves out, and it's the part that does the work. 

Put the three answers together as a sentence that person would actually say, in that room, if it came to that. 

Worked example. Take a vendor-offboarding gap: access doesn't get revoked automatically when a contract ends, someone has to remember to do it. On the register, that's "Vendor offboarding, medium likelihood, reviewed quarterly." As a sentence: "We didn't revoke their system access for six weeks after the contract ended, because nobody owned offboarding once procurement closed the file." 

Same gap. Completely different reaction once it's read out loud. 

Graphic titled 'Write the Sentence in Three Questions.' Step 1, Name the Room: name where this would surface, such as an audit committee, incident review, or board update. Step 2, Name the Mechanism: name the actual mechanism, not the category, for example 'access doesn't get revoked when a contract ends' instead of 'exposed to risk.' Step 3, Name the Reason: name the real reason it's still open, usually a funding or ownership decision. Closing line: 'Three questions, one sentence: "We didn't revoke their access for six weeks after the contract ended, because nobody owned offboarding once procurement closed the file."
Click image to enlarge

Aim the Sentence at the Decision, Not the Person 

The sentence only works if it ends on a decision, not a person. "We didn't revoke access because Dana forgot" invites blame and gets forgotten along with everything else about Dana. "We didn't revoke access because nobody owned offboarding once procurement closed the file" points at the actual structural gap, which is the thing a budget conversation can actually fix. 

This matters more than it sounds. A sentence that reads as finger-pointing gets defended against instead of acted on, and you lose the exact reaction you were trying to produce.

We cover topics like this every week. Practical supplier management insights for procurement and supply chain teams. Get it in your inbox →

Where This Goes Wrong 

Three ways this exercise fails, all avoidable. 

Too vague to land. "We should have done more" describes a feeling, not a mechanism, and nobody can act on it. If your sentence could apply to any gap on the register, rewrite it. 

Missing the ending. A sentence that stops at "we didn't verify it" describes the gap but not why it's still open. The ending, the actual funding or ownership reason, is what turns a description into an argument. 

Written once and filed away. The sentence is only useful if it reaches the people who can act on it. Put it in the actual document you take into the budget or governance conversation, not in a notes file nobody opens again. 

It Costs Nothing to Produce Today 

Coverage numbers need a query against your supplier master. Intervention counts need a quarter of logging before the first number exists. This needs neither. You already know the gap and the reason it's open; writing the sentence down takes no new data, just the willingness to be specific. 

If you're building the full funding case rather than a single finding, this sentence is the fourth field in that structure, the one asking what happens if the gap stays open. See the other three fields → 

Start With What You Can Count 

If you're not sure which gap to start with, that's the more basic problem to solve first. 

Our supplier risk checklist runs nineteen questions across supplier discovery, onboarding and qualification, fraud prevention, regulatory readiness, and audit visibility. It takes about five minutes. Your answers stay in your browser, nothing is submitted, and it returns a ranked list of your gaps with the reason each one matters. 

Pick the top one and write its sentence today.

Take the Supplier Risk Checklist → 

Blog TPRM ROI
Previous reading
How to Write a Risk Finding That Gets Funded
Next reading
What the IIA’s New Third-Party Topical Requirement Actually Requires