School Governance Risk Register for Irish Schools: What Boards Should Track
Most Irish schools already maintain some form of risk log - usually a health and safety risk assessment for the building and grounds, and often a financial risk log alongside the budget. Rarer is a register focused specifically on governance risk: the risk that the Board of Management (BOM) will not meet its own obligations, will not have evidence of its oversight, or will not receive the information it needs to govern properly.
A governance risk register is not a duplicate of the health and safety log or the financial risk log. It is a distinct tool, owned by the BOM, focused on governance effectiveness itself: whether the board is meeting its obligations, whether it can evidence that it has, and whether the systems supporting governance - the Child Safeguarding Statement (CSS) cycle, policy review, finance reporting, BOM records - are actually working. This article sets out what a governance risk register for an Irish school should contain, the risks it should track across five key areas, and how to keep it current.
Section 1: What is a governance risk register for an Irish school?
A governance risk register is a living document that identifies, assesses and tracks risks specific to BOM governance, not operational risks to the school's day-to-day running. It covers risks such as:
- the risk that BOM obligations will not be met on schedule
- the risk that evidence will not be in place to demonstrate governance activity
- the risk that the BOM will not have the information it needs to exercise oversight
- the risk that child safeguarding governance will fail
- the risk that finance oversight will be inadequate
Like any risk register, each entry is assessed for likelihood (low, medium, high) and impact (low, medium, high), given a current status, assigned an owner, and reviewed on a set cycle. The key difference from an operational or financial risk log is ownership: a governance risk register belongs to the BOM itself, not the principal alone, because the risks it tracks are risks to the board's own function. It should be reviewed at least once per term, ideally as part of a wider termly governance readiness review.
The sections below set out five risk areas that cover the great majority of governance risk in a typical Irish primary or post-primary school.
Section 2: Risk area 1 - Child safeguarding governance risks
Child safeguarding sits at the top of any governance risk register, because the impact of a genuine gap is high even where the likelihood is low. The BOM's safeguarding oversight role - its duty under the Children First Act 2015 to oversee the school's safeguarding arrangements - is distinct from day-to-day safeguarding practice, and it is this oversight role, not the practice itself, that belongs on the governance risk register.
Common risks in this area:
- CSS not reviewed and BOM re-adoption not completed within the year - the annual review lapses past the school year without formal BOM sign-off.
- CPOR not completed, or not reviewed by the BOM - the Child Protection Oversight Report is missed, delayed, or completed without ever reaching the board.
- DLP/DDLP training not current - the Designated Liaison Person or Deputy DLP is operating on training that has lapsed, and no one has noticed.
- Staff not informed of the current CSS at the start of the year - a basic annual requirement that quietly slips.
- CSS not on display in the school building - a simple, visible compliance point that is often overlooked once the initial display goes up.
- BOM unable to evidence its child safeguarding oversight role under inspection - even where oversight genuinely happened, nothing was recorded to demonstrate it.
Safeguarding risks should generally be assessed as high impact regardless of likelihood, given the consequences of a genuine gap. What to track: the CSS review date, CPOR completion and BOM review date, DLP/DDLP training dates, and the date of the last CSS display check. The annual child safeguarding governance review checklist sets out the full annual review process that feeds this section of the register.
Section 3: Risk area 2 - Policy and circular compliance risks
Policy governance is one of the most common sources of governance risk, largely because a single overdue review can go unnoticed for months without anyone actively checking.
Common risks in this area:
- Policies overdue for review - not flagged until WSE pressure brings it to light.
- Policy register not maintained - the BOM has no reliable way to confirm which policies are current and which are overdue.
- Department of Education circular received but policy implications not actioned - a circular arrives, but no one assesses which policies need amending as a result.
- Published or displayed policies not the current BOM-approved version - the version on the website or noticeboard has fallen behind the version actually approved in the minutes.
- Patron or trust body template update not incorporated - a patron issues an updated policy template, but the school's own policy is never brought into line with it.
What to track: policy register review dates against a master schedule, a circular triage log recording whether each Department of Education circular has been assessed for policy impact, and the date of the last display compliance check.
Section 4: Risk area 3 - Finance oversight risks
Financial oversight is a core BOM function, and gaps here are among the most serious findings in any governance review, because they go directly to the board's duty of scrutiny over the school's finances.
Common risks in this area:
- Finance updates not presented to the BOM on schedule - the board is not kept informed of the school's financial position at the frequency it should be.
- Capitation or ancillary grant management not evidenced in BOM records - grants are received and spent, but the BOM's oversight of that spending is never recorded.
- BOM minutes do not evidence financial challenge or scrutiny - finance reports are received, but minutes show no questioning or discussion, weakening the audit trail of genuine oversight.
- Patron or trust body financial reporting obligations not met - a reporting requirement set by the patron or trust body - including, where relevant, CPSMA or the school's ETB - is missed.
What to track: adherence of the finance update schedule to what the BOM has agreed, and a periodic check of minute quality specifically for evidence of financial challenge. The finance governance best practice article sets out the wider finance oversight framework this risk area sits within.
Section 5: Risk area 4 - BOM effectiveness risks
A Board of Management can only provide effective oversight if it is properly constituted, informed and supported. Risks in this area are often slow-moving but can undermine every other area of governance if left unaddressed.
Common risks in this area:
- BOM vacancies not filled - creating a quorum risk, or a gap against the composition required by the patron.
- New BOM members not inducted - members are appointed but not equipped for the responsibilities of their role.
- Principal absence without a governance continuity plan - a sudden or extended absence leaves no clear plan for keeping BOM business running.
- BOM chairperson succession not planned - a departure leaves the board without clear leadership continuity.
- Patron or trust body reporting obligations missed - routine reporting to the patron or trust body falls behind without anyone tracking the calendar.
What to track: currency of BOM composition records against the patron's required structure, induction completion for new members, and a patron reporting calendar showing what is due and when.
Section 6: Risk area 5 - Evidence and records risks
Even where governance activity is genuinely happening, a BOM that cannot evidence it carries real risk - both at WSE and in terms of its own ability to demonstrate accountability.
Common risks in this area:
- Governance evidence store not maintained - evidence exists in principle but cannot actually be produced when a WSE asks for it.
- BOM action log not updated - the board cannot demonstrate follow-through on its own decisions.
- BOM minutes incomplete or not approved - a broken audit trail, since unapproved minutes carry less evidential weight.
- BOM composition records out of date - a basic record that inspectors frequently ask to see, and one that is often allowed to drift.
- Circular triage log not maintained - no evidence of how the school responded to Department of Education guidance as it was issued.
What to track: the review date of the evidence store, how current the action log is against the last BOM meeting, and the approval status of minutes across the year. A dedicated governance evidence log is the natural companion to this section of the risk register - while the risk register flags where evidence may be missing, the evidence log is where that evidence is actually indexed and stored.
Section 7: How to maintain the governance risk register
A governance risk register only has value if it is kept live. In practice, that means:
- Review it at least once per term - ideally as a standing item within the termly governance readiness review, rather than as a separate exercise competing for time on its own.
- Give every risk a named owner - a person, not a committee, responsible for tracking that specific risk to resolution.
- Track current status clearly - open, mitigated or closed - so the BOM can see progress at a glance.
- Set a target date for resolution - an open-ended risk with no date tends to stay open indefinitely.
- Escalate red risks - any risk assessed as high likelihood and high impact should appear as a named agenda item at the next BOM meeting, not wait for the next scheduled review.
- File the register in the evidence store - the risk register itself is part of the governance evidence base and should sit alongside minutes, policies and CSS/CPOR records, following the same evidence discipline covered in BOM actions and follow-up tracking.
Building this rhythm into the school's wider governance systems - rather than treating the risk register as a one-off document produced ahead of a WSE - is what turns it from a compliance artefact into a genuinely useful oversight tool. This is the kind of recurring discipline a proper governance operating system is designed to support.
A sample governance risk register template
The table below sets out a starting template, pre-populated with ten common governance risks drawn from the areas above. Boards of Management should adapt likelihood, impact and status to their own circumstances.
| Risk area | Specific risk | Likelihood | Impact | Current status | Owner | Target date | Notes |
|---|---|---|---|---|---|---|---|
| Child safeguarding | CSS annual review and BOM re-adoption overdue | Medium | High | Open | Chairperson / DLP | End of term | Schedule for next BOM meeting |
| Child safeguarding | DLP/DDLP training gap | Low | High | Open | Principal / Chairperson | Next BOM meeting | Confirm training booking |
| Policy | Policy register incomplete | Medium | Medium | Open | School secretary | 4 weeks | Cross-check against policy calendar |
| Policy | Department of Education circular not yet triaged | Medium | Medium | Open | Principal | Next BOM meeting | Log in circular triage log |
| Finance | Finance update missed this term | Low | High | Mitigated | Principal / Treasurer | Closed | Rescheduled and received |
| Finance | Capitation/ancillary grant use not recorded in minutes | Medium | Medium | Open | Principal | Next BOM meeting | Add finance note to minutes |
| BOM effectiveness | BOM vacancy - composition gap | High | Medium | Open | Chairperson | Next recruitment cycle | Confirm with patron |
| BOM effectiveness | New BOM member induction not completed | Medium | Medium | Open | Chairperson | Ongoing | Use standard induction pack |
| Evidence | BOM action log not updated since last meeting | Medium | Medium | Open | School secretary | Immediate | Update before next meeting |
| Evidence | Minutes from last meeting unapproved | Low | Medium | Open | Chairperson | Next BOM meeting | Approve at next meeting |
FAQ
How is a governance risk register different from the school's health and safety or financial risk log? The health and safety risk assessment covers risks to the physical school environment, and a financial risk log covers risks within the budget itself. A governance risk register is narrower and specific to the BOM: it tracks the risk that governance obligations, evidence and oversight mechanisms will fail, and it is owned by the board, not the principal alone.
How often should the governance risk register be reviewed? At least once per term. Many boards fold this into a wider termly governance readiness review rather than running it as a separate standalone exercise.
Who should own the governance risk register? The BOM as a whole, usually coordinated by the chairperson with support from the principal and school secretary. Individual risks within the register should each have a named owner responsible for tracking that item to resolution.
Does the governance risk register need to be shown at WSE? There is no requirement to produce a governance risk register for inspection, but a well-maintained one can be a useful way to demonstrate that the BOM actively manages its own governance effectiveness. Inspectors may ask how a board identifies and manages its own governance gaps, and a live risk register is direct evidence of that process.
Book a governance assurance demo
Keeping a governance risk register current means linking it to the evidence, actions and reviews that actually resolve each risk - not maintaining it as a static document that goes stale between meetings. Book a demo to see how Edvance helps Boards of Management track governance risk alongside evidence and actions in one place.
Jurisdiction note
This article is written for Irish primary and post-primary schools generally, though governance structures vary between primary, secondary, ETB, and voluntary sectors. Patron and trust bodies - including, where relevant, CPSMA or the school's ETB - may set additional risk management and reporting requirements, which BOMs should follow alongside the general framework set out here. This article provides general governance guidance and does not constitute legal advice.
Frequently Asked Questions
How is a governance risk register different from the school's health and safety or financial risk log?
The health and safety risk assessment covers risks to the physical school environment, and a financial risk log covers risks within the budget itself. A governance risk register is narrower and specific to the BOM: it tracks the risk that governance obligations, evidence and oversight mechanisms will fail, and it is owned by the board, not the principal alone.
How often should the governance risk register be reviewed?
At least once per term. Many boards fold this into a wider [termly governance readiness review](/resources/governance-readiness/termly-governance-readiness-review-irish-schools) rather than running it as a separate standalone exercise.
Who should own the governance risk register?
The BOM as a whole, usually coordinated by the chairperson with support from the principal and school secretary. Individual risks within the register should each have a named owner responsible for tracking that item to resolution.
Does the governance risk register need to be shown at WSE?
There is no requirement to produce a governance risk register for inspection, but a well-maintained one can be a useful way to demonstrate that the BOM actively manages its own governance effectiveness. Inspectors may ask how a board identifies and manages its own governance gaps, and a live risk register is direct evidence of that process.