Appendix Y · Digital companion · all tools
The Public Accounting Risk Register
Appendix Y: The Public Accounting Risk Register
Every serious reform method creates risk. Public accounting exposes records, follows money, tracks land, documents wages, asks police to issue acknowledgments, asks hospitals to show stock, asks courts to measure delay, asks families to record women as heirs, and asks public bodies to explain what they prefer to leave vague. Public accounting is therefore not a harmless administrative exercise; it changes the cost of secrecy. That means it will produce resistance, mistakes, retaliation, manipulation, and fatigue unless risks are identified early.
A risk register is not a reason to stop but a way to continue intelligently. Reformers who ignore risk often harm the people they are trying to protect. Reformers who fear every risk never begin. The disciplined path is to name the risk, estimate its likelihood, estimate its impact, assign responsibility, create mitigation steps, and review the risk regularly.
The central standard: every public accounting project should know what can go wrong before it asks vulnerable people to step forward.
Find your country’s law
Your country’s page in the Atlas shows which law applies, the office to approach, and the deadline, fee, and appeal route to confirm at the counter.
Why a Risk Register Is Necessary
Public accounting work often begins with moral certainty. A worker has not been paid. A woman has been pressured out of inheritance. A patient has been told to buy medicine outside. A police station has refused acknowledgment. A ward project has no board. A public land record is missing. A tax concession is hidden. The injustice appears obvious, and the instinct is to expose it quickly.
But exposure without risk discipline can create new harm. A worker may be fired. A woman may face family retaliation. A patient may lose privacy. A complainant may be threatened. A volunteer may be sued. A report may contain an error. A public official may be falsely accused. A donor may try to shape findings. A political faction may hijack the campaign. A digital system may leak personal documents. A pilot may collapse because no one assigned follow-up.
A risk register makes these dangers visible. It does not remove them completely. It reduces surprise and creates planned responses.
Core Risk Categories
- Every public accounting project should review at least ten categories of risk.
- Claimant safety risk.
- Privacy and data protection risk.
- Legal and defamation risk.
- Evidence quality risk.
- Political capture risk.
- Official retaliation risk.
- Volunteer conduct risk.
- Digital security risk.
- Operational capacity risk.
- Public credibility risk.
Each category should be assessed before a pilot, report, campaign, ledger, audit, or public release begins. The review does not need to be bureaucratic. But it must be real.
Claimant Safety Risk
Claimant safety is the first risk category because public accounting often depends on people who are weaker than the institutions or individuals they challenge.
- High-risk claimants may include:
- Workers claiming unpaid wages.
- Women claiming inheritance.
- Domestic violence complainants.
- Police complainants.
- Patients alleging serious hospital failure.
- Students challenging institutions.
- Tenants facing eviction.
- Whistleblowers.
- Small vendors or residents challenging local power.
- Overseas heirs relying on local relatives.
- Citizens challenging land actors.
- The risk questions are:
- Can the claimant be identified?
- Can the opposing party retaliate?
- Could the claimant lose job, housing, documents, grades, medical access, family support, or physical safety?
- Does the claimant understand the risks of publication?
- Is legal aid available?
- Can the case be anonymized?
- Should action begin privately rather than publicly?
Mitigation may include anonymization, legal aid referral, delayed publication, aggregate reporting, emergency contact planning, private official notice, safe storage of documents, and consent review.
Privacy and Data Protection Risk
Public accounting collects sensitive information. A single careless upload can expose identity documents, addresses, medical records, family disputes, bank details, phone numbers, signatures, children's information, or worker messages.
- The risk questions are:
- What personal data is being collected?
- Is it necessary?
- Who can access it?
- Where is it stored?
- Can it be redacted?
- Can aggregate reporting replace individual disclosure?
- What happens if the file leaks?
- Has the claimant consented?
- Is the data being shared through secure channels?
Mitigation may include collecting less data, assigning privacy levels, restricting access, redacting documents, encrypting storage, removing metadata where necessary, using protected case identifiers, training volunteers, and deleting unnecessary copies.
Legal and Defamation Risk
A public accounting project can be sued, threatened, or discredited if it makes unsupported allegations. Even where the claim is true, poor wording can create avoidable legal risk.
- The risk questions are:
- Is the statement allegation, evidence, or finding?
- Has the opposing party been contacted where safe?
- Are documents available?
- Is criminal language being used without legal basis?
- Are names necessary?
- Can the issue be framed around missing records rather than accusing individuals?
- Has a lawyer reviewed high-risk material?
- Are corrections possible after publication?
Mitigation may include legal review, careful wording, right of reply, distinction between allegation and finding, correction process, evidence logs, and avoiding unnecessary personal accusations.
Evidence Quality Risk
Weak evidence can destroy a strong cause. Public accounting depends on credibility. If a project publishes false, exaggerated, outdated, manipulated, or poorly verified claims, power will use that failure to discredit the entire method.
- The risk questions are:
- What evidence supports the claim?
- Is the evidence original or copied?
- Is the date clear?
- Is the location clear?
- Has the document been altered?
- Is the photograph current?
- Is the witness reliable?
- Does an official record confirm or contradict the claim?
- Is there missing context?
- What is still unverified?
Mitigation may include evidence classification, verification workflow, source logging, field confirmation, official record requests, cross-checking, expert review, and labeling uncertain claims clearly.
Political Capture Risk
Public accounting can be hijacked by political factions. A party may support transparency when it targets opponents but resist it when it reaches allies. A local group may use the ledger to settle rivalries. A donor may fund selective exposure. A media platform may frame findings for factional benefit.
- The risk questions are:
- Who benefits politically from this project?
- Is the standard being applied across sides?
- Are certain cases being ignored because they involve allies?
- Are funders influencing targets?
- Are volunteers linked to local factions?
- Can the methodology be published?
- Is the project focused on records rather than personalities?
- Mitigation may include universal criteria, conflict-of-interest disclosure, independent review, multi-stakeholder governance, transparent methodology, and refusal to target only enemies.
Official Retaliation Risk
Public bodies and officials may respond defensively. They may refuse records, threaten legal action, intimidate claimants, transfer honest insiders, accuse the project of political motives, or block access.
- The risk questions are:
- Which authority may feel threatened?
- Does the project have legal basis for requests?
- Are communications respectful and documented?
- Are honest officials protected?
- Is there a senior escalation route?
- Is media escalation appropriate or premature?
- Could retaliation harm claimants?
Mitigation may include formal notices, lawful information requests, right-of-reply letters, legal support, quiet engagement first where appropriate, public escalation only after evidence review, and documentation of threats.
Volunteer Conduct Risk
Volunteers can become a risk if they are untrained, careless, ambitious, factional, or hungry for attention. They may expose claimants, make false promises, confront dangerous actors, take money, post unverified claims, or mishandle documents.
- The risk questions are:
- Have volunteers been trained?
- Do they understand privacy rules?
- Do they know what they are not allowed to promise?
- Do they know when to refer to lawyers?
- Can they access sensitive data?
- Are they posting independently?
- Is there a code of conduct?
- What happens if a volunteer violates rules?
- Mitigation may include training, signed code of conduct, limited access, supervision, publication approval rules, disciplinary process, and role separation.
Digital Security Risk
Digital systems can leak, be hacked, be misconfigured, or be misused internally. Public accounting often creates a valuable archive of sensitive disputes.
- The risk questions are:
- Where is the data stored?
- Who has access?
- Are passwords strong?
- Is two-factor authentication enabled?
- Are files backed up?
- Are sensitive files encrypted?
- Can former volunteers still access records?
- Are documents being shared through personal accounts?
- Is artificial intelligence being used with sensitive data?
Mitigation may include role-based access, two-factor authentication, password managers, encrypted storage, secure backups, access review, audit logs, and rules against uploading sensitive data into unsafe tools.
Operational Capacity Risk
A public accounting project can fail because it collects more claims than it can process. Citizens may be encouraged to come forward, but the team may lack lawyers, reviewers, data capacity, field verification, or follow-up discipline.
- The risk questions are:
- How many cases can the team handle?
- Who reviews evidence?
- Who communicates with claimants?
- Who follows deadlines?
- Who handles urgent cases?
- Who writes reports?
- Who corrects errors?
- What happens if volume doubles?
- What services will the project explicitly not provide?
- Mitigation may include narrow scope, intake limits, referral networks, staged pilots, triage categories, clear disclaimers, and realistic timelines.
Public Credibility Risk
A project can lose credibility through errors, exaggeration, selective targeting, poor communication, privacy breaches, no follow-up, or failure to correct mistakes.
- The risk questions are:
- Are findings written carefully?
- Are limitations stated?
- Are corrections visible?
- Are official responses included?
- Are follow-ups scheduled?
- Are claimants protected?
- Are numbers accurate?
- Is language too theatrical?
- Does the public understand the purpose?
- Mitigation may include editorial review, correction policy, publication standards, evidence notes, follow-up ledger, and consistent communication discipline.
Risk Rating
- Each risk should be rated by likelihood and impact.
- Likelihood:
- Low: unlikely but possible.
- Medium: reasonably possible.
- High: likely without mitigation.
- Impact:
- Low: limited harm, easy to correct.
- Medium: meaningful harm, reputational or operational damage.
- High: serious harm to claimant, legal exposure, safety threat, major credibility damage, or project failure.
A risk that is low likelihood but high impact still deserves planning. A domestic violence complainant exposed accidentally may be a rare event, but the harm can be severe. A data leak may be unlikely if systems are strong, but the impact could be large. High-impact risks require mitigation even when likelihood appears low.
Risk Owner
Every risk should have an owner. A risk without an owner is only a note. The owner is not necessarily responsible for causing the risk, only for watching it and ensuring mitigation happens.
- Possible risk owners:
- Project coordinator.
- Privacy reviewer.
- Legal advisor.
- Data manager.
- Volunteer coordinator.
- Official liaison.
- Communications lead.
- Claimant support lead.
- Fieldwork lead.
- Audit lead.
- Each risk entry should name a person or role responsible for review.
Mitigation Plan
- Mitigation should be specific. "Be careful" is not a mitigation plan.
- Weak mitigation:
- Protect privacy.
- Strong mitigation:
Assign privacy level at intake, remove names from public reports, store identity documents in restricted folder, redact phone numbers before publication, and obtain written consent before using case details.
- Weak mitigation:
- Avoid defamation.
- Strong mitigation:
Classify every statement as allegation, record, finding, or opinion; seek legal review for named accusations; request official response before publication where safe; and maintain correction log.
Mitigation should be written as actions, not intentions.
Residual Risk
Even after mitigation, some risk remains. This is residual risk. A project should decide whether residual risk is acceptable.
Example:
A woman claiming inheritance faces high family retaliation risk. Mitigation includes anonymization, legal aid referral, no public naming, and private notice through counsel. Residual risk remains medium because family may still discover the claim. The team must decide whether to proceed and under what safeguards.
Residual risk should be accepted consciously, not by accident.
Escalation Triggers
- The risk register should identify triggers that require escalation.
- Examples:
- Claimant reports threat.
- Legal notice received.
- Sensitive data leaked.
- Volunteer publishes unapproved material.
- Official threatens staff or claimant.
- Evidence appears fabricated.
- Media requests claimant identity.
- Donor requests suppression of finding.
- Opposing party contacts claimant directly.
- Case involves child, sexual violence, or domestic violence.
- A high-risk trigger should pause publication until review occurs.
Stop Rules
- Some situations require stopping or delaying action.
- Stop rules may include:
- Claimant withdraws consent.
- Claimant safety risk becomes high.
- Evidence is suspected to be false.
- Legal review identifies serious risk.
- Publication would expose a child.
- Medical privacy cannot be protected.
- Volunteer misconduct affects data integrity.
- Official response reveals major factual error.
- Data storage is compromised.
- Opposing party retaliation begins.
- Stopping is not failure. Sometimes stopping protects the claimant and the credibility of the work.
Risk Register Fields
- A basic risk register should include:
- Risk identifier.
- Risk category.
- Risk description.
- Likelihood.
- Impact.
- Risk rating.
- Risk owner.
- Mitigation steps.
- Residual risk.
- Escalation trigger.
- Review date.
- Status.
- Notes.
- The register should be reviewed at fixed intervals and before major publication.
Model Risk Register Entry
A translated version of any form or letter is a draft for your understanding. Submit in the office’s official language, and have the final text checked by someone you trust.
Risk identifier: R-001 Category: Claimant safety Description: Worker may be fired or threatened after wage claim becomes known. Likelihood: Medium Impact: High Risk rating: High Risk owner: Claimant support lead
Mitigation: Use protected reference, do not publish employer name until evidence review and worker consent, refer to labor lawyer, record retaliation risk, contact employer through formal notice only after worker approves, prepare emergency support contact.
Residual risk: Medium Escalation trigger: Any threat, dismissal, or pressure on worker. Review date: [Insert] Status: Active
Risk Register for Wage Recovery Pilot
- Common risks:
- Workers fired after complaint.
- Employer denies employment relationship.
- Workers sign false settlement under pressure.
- Volunteer reveals worker identity.
- Employer threatens defamation action.
- Evidence incomplete.
- Public contractor shifts blame to subcontractor.
- Political actor tries to use wage claims against rival contractor.
- Mitigation:
Private intake, evidence preservation, legal referral, written settlement proof, public reporting in aggregate, contractor right of reply, worker consent before publication, and wage compliance request to public authority.
Risk Register for Female-Heir Inheritance Pilot
- Common risks:
- Family retaliation.
- Woman pressured to withdraw.
- Documents withheld.
- Relinquishment signed before advice.
- Personal details exposed.
- Male relatives accuse project of breaking family.
- Land office refuses records.
- Case becomes public without consent.
- Mitigation:
Confidential intake, legal aid referral, no public naming, separate consent review, document copy assistance, aggregate reporting, religious-language framing around haqq, and safety assessment before any notice.
Risk Register for Hospital Medicine Pilot
- Common risks:
- Patient privacy breach.
- Frontline staff blamed for procurement failure.
- Hospital denies stockout.
- Patients fear future neglect.
- Outside purchase evidence incomplete.
- Pharmacy records inaccurate.
- Media sensationalizes patient suffering.
- Mitigation:
Protected patient references, stock-chain analysis, official response request, aggregate reporting, patient consent, no public photographs of patients without consent, distinguish procurement failure from clinical conduct.
Risk Register for Police Complaint Access Pilot
- Common risks:
- Complainant intimidation.
- Police hostility to monitors.
- False complaint concern.
- Misunderstanding acknowledgment as proof of guilt.
- Sensitive domestic violence details exposed.
- Volunteer confrontation at station.
- Legal risk in test cases.
- Mitigation:
Legal supervision, real complaints only, no false test complaints, written protocols, privacy safeguards, senior liaison where possible, complainant safety assessment, clear language that acknowledgment does not prove allegation.
Risk Register for Ward Ledger Pilot
- Common risks:
- Local political capture.
- Encroachers confront volunteers.
- Photographs expose private residents.
- Officials accuse team of opposition politics.
- Complaints overwhelm capacity.
- False reports submitted.
- Contractor intimidation.
- Mitigation:
Public methodology, no party branding, fieldwork safety rules, photograph public assets not private homes, verification before publication, complaint triage, official right of reply, volunteer training.
Risk Register for Public Land Inventory Work
- Common risks:
- Powerful land actors retaliate.
- Ownership disputes misreported.
- Maps inaccurate.
- Poor settlements targeted while elite encroachments hidden.
- Legal notices from beneficiaries.
- Public disclosure affects vulnerable residents.
- Mitigation:
Use official records, classify uncertainty, avoid declaring title without legal basis, distinguish survival from privilege, protect vulnerable locations where necessary, legal review, public-purpose framing.
Risk Register for Tax Expenditure Disclosure
- Common risks:
- Technical misinterpretation.
- Business groups accuse project of anti-growth agenda.
- Small actors fear taxation.
- Government refuses cost estimates.
- Data incomplete.
- Political faction uses findings selectively.
- Mitigation:
Use finance experts, define tax expenditure clearly, distinguish small actors from high-capacity groups, publish limitations, seek official response, focus on disclosure and review rather than blanket condemnation.
Risk Register for Media Follow-Up Ledger
- Common risks:
- Defamation claim.
- Incorrect story status.
- Failure to update correction.
- Authority response omitted.
- Claimant identity exposed.
- Political selectivity.
- Mitigation:
- Source each entry, classify status, include authority responses, maintain correction log, anonymize claimants, use universal criteria for story selection.
Crisis Response Plan
- Every project should have a crisis response plan.
- Possible crises:
- Claimant threatened.
- Data leaked.
- Legal notice received.
- False evidence discovered.
- Volunteer misconduct exposed.
- Official publicly attacks project.
- Media misreports findings.
- Publication causes unintended harm.
- The crisis plan should state:
- Who is notified first.
- Who speaks publicly.
- Who contacts claimant.
- Who secures data.
- Who contacts legal advisor.
- Who investigates internally.
- Who issues correction.
- Who decides pause or continuation.
- In a crisis, confusion causes more damage. Assign roles before crisis occurs.
Insurance Against Overreach
Public accounting projects should build internal friction against reckless action. The goal is not bureaucracy. The goal is to prevent one angry person from publishing a dangerous accusation.
- Internal controls may include:
- Two-person review before publication.
- Privacy review for every case.
- Legal review for named allegations.
- Evidence checklist before findings.
- Official response request where safe.
- Correction mechanism.
- Volunteer posting rules.
- Conflict disclosure.
- These controls protect the movement from itself.
Risk Communication
When speaking publicly, be transparent about risk and limits.
Example:
We reviewed 26 anonymized wage claims. We are not publishing worker names because retaliation risk is high. The employer categories and total unpaid amounts are reported in aggregate. Notices have been sent to the relevant employers and public authority where applicable.
This tells the public that privacy is a deliberate safeguard, not a gap.
Review Cycle
- Risk registers should be reviewed regularly.
- For high-risk pilots: weekly.
- For active campaigns: every two weeks.
- Before publication: mandatory review.
- After any incident: immediate review.
- After project completion: lessons learned review.
Risk changes over time. A quiet wage claim can become high-risk after employer notice. A private inheritance matter can become dangerous after relatives learn of legal aid. A harmless ward audit can become risky if a contractor is politically connected.
Lessons Learned
- Every project should record lessons learned.
- Questions:
- Which risks actually occurred?
- Which risks were missed?
- Which mitigations worked?
- Which mitigations failed?
- Did any claimant suffer harm?
- Were any errors published?
- Was data secure?
- Did volunteers follow rules?
- Did official engagement reduce or increase risk?
- What should change next time?
- A movement improves by studying its own mistakes.
The Standard
One standard governs the work: courage with discipline.
A public accounting movement should not be reckless, but it should not be paralyzed. Risk is real because the work is real. The answer is to identify danger, protect claimants, verify evidence, secure records, control publication, correct errors, and keep going.
A captured order benefits when citizens are either careless enough to discredit themselves or afraid enough to remain silent.
A republic builds the discipline to speak, record, protect, and persist.
Improve this tool
If you used this template and something confused you, failed, or worked well, send what happened, the office involved, and the date. Every submission is reviewed before anything changes on this site. Route: the contact on the About page.