An auditor questioning your risk register is not looking for a longer document -- they are looking for traceability. A defensible entry answers five questions clearly enough that someone outside your team could verify the reasoning.

1. What asset or system is exposed?

Name the specific asset, not a category. 'RTU-14 at Substation North' is verifiable; 'the network' is not.

2. What is the specific threat scenario?

Describe the credible path an adversary would take, not a generic label. 'Compromised vendor VPN account used to issue unauthorized breaker commands' is a scenario. 'Cyber attack' is not.

3. What controls currently exist, and are they evidenced?

List existing controls and, critically, the evidence that they work -- a test result, a monitoring log, a configuration review -- not just their presence in an architecture diagram.

4. Who owns this risk, by name?

A department is not an owner. A named person with the authority to approve treatment decisions is.

5. What is the treatment decision and review date?

Mitigate, transfer, accept, or avoid -- explicitly, with a documented rationale and a date by which the decision will be revisited. Entries with no review date tend to become permanently stale.