PWPM Wiki

Risk Register

A risk register is the living log of everything that might go wrong (or right) on a project — each risk scored, owned, and paired with a response — so uncertainty is managed deliberately instead of discovered too late.

A risk register is a document (or tool) that captures identified risks along with their attributes: a description, category, probability, impact, resulting score or exposure, a named owner, a chosen response strategy, specific response actions, triggers, and current status. It typically covers both threats (negative risks) and opportunities (positive risks). The register is not a one-time deliverable — it is reviewed and updated throughout the project as risks change, close out, or emerge.

Risk Register at a glance

Category
Risk, Issues & Uncertainty · Tools & Techniques
Type
Tool / technique
Appears in
2 sections
Related
Risk Monitoring, Risk Matrix, Risk Response

Why it matters

Every project carries uncertainty; the question is whether you manage it or it manages you. A risk register makes uncertainty explicit and assignable. Scoring risks by probability and impact focuses attention on the ones that matter. Naming an owner ensures each risk is actually watched. Recording response actions means that when a risk materialises, there is already a plan — turning a crisis into a rehearsed move.

When to use it

Start the risk register during planning, as soon as enough is known to identify meaningful risks, and keep it alive through execution with regular reviews (often as a standing agenda item in status meetings). Any project with real uncertainty benefits; the higher the stakes and novelty, the more rigorous the process should be.

How to use it

  1. Identify risks through workshops, checklists, assumptions analysis and lessons from past projects.
  2. Assess each: rate probability and impact (often on a 1–5 scale) and compute a score to prioritise.
  3. Assign an owner responsible for monitoring and responding to each risk.
  4. Choose a response strategy: avoid, mitigate, transfer or accept (for threats); exploit, enhance, share or accept (for opportunities).
  5. Define concrete actions and triggers, then review and update the register regularly.

Example

Risk: "Key API vendor may miss integration deadline." Probability 3, Impact 4 → score 12 (high). Owner: Integration Lead. Strategy: mitigate — begin integration two sprints early and build a fallback adapter. Trigger: vendor misses its first milestone. Status: open, monitored weekly.

Template

A risk register template includes columns for ID, description, category, probability, impact, score, owner, response strategy, actions, trigger, residual risk and status — plus a risk matrix visual.

Browse templates →

Tools

Excel / Google SheetsJiranTaskPrimavera Risk Analysismonday.com

Formula & calculator

Risk Score = Probability × Impact · EMV = Probability × Cost Impact

Try it yourself: Risk Score Calculator computes this from your own figures.

Open the Risk Score Calculator →

FAQs

What is the difference between a risk and an issue?
A risk is a potential future event that may or may not happen; an issue is a risk that has already occurred and now needs resolving. Risks live in the risk register; issues in the issue log.
What are the four risk response strategies?
For threats: avoid, mitigate (reduce), transfer (e.g. insurance), or accept. For opportunities: exploit, enhance, share, or accept.
What is residual risk?
The risk that remains after response actions have been applied. Some exposure usually stays even after mitigation, and that remainder is tracked as residual risk.

Alternatives

  • RAID log — combines risks with assumptions, issues and dependencies
  • Risk matrix / heat map — the visual companion, not a replacement
  • Monte Carlo simulation — quantitative modelling for schedule/cost risk