Template · Risk Register

Risk Register Template

A register that changes decisions — cause-event-effect risks, scales you define yourself, a named owner per risk, responses with dates, and the five-question review.

Markdown. No sign-up, no email.

Ten risks that are genuinely managed beat sixty that are catalogued. If a row cannot be acted on, it is a condition, not a project risk.

Issues go in a different list. A risk might happen; an issue has happened. Mixing them lets today's problems crowd out tomorrow's, which is the failure this register exists to prevent.

Project: _______________ Owner: _______________ Last reviewed: _______ Next review: _______

Define the scales first#

Undefined scales produce scores that vary by author and cannot be compared. Fill these in for this project before scoring anything.

ScoreLikelihoodImpact — costImpact — scheduleImpact — other
5almost certainover ___over ___regulatory breach / customer-visible outage
4likely
3possible
2unlikely
1rare

The register#

Write each risk as cause → event → effect. It forces you to name the cause, which is usually the only part you can act on.

IDRisk (because… there is a risk that… resulting in…)LIScoreOwner (person)ResponseActionDueStatus
R1avoid / reduce / transfer / acceptopen
R2

Response definitions:

ResponseMeansNote
AvoidChange the plan so it cannot occurUsually cheapest, least considered
ReduceLower likelihood or impactNeeds a specific action, owner and date
TransferContract, insurance, supplier obligationTransfers cost, not operational consequence
AcceptLive with it, deliberately, on the recordNeeds a trigger for reconsidering

🔴 A risk owned by "the project" or by the project manager for all thirty rows gets reported on rather than acted on. The owner must be someone who can actually influence it.

Accepted risks#

IDRiskAccepted byDateTrigger to reconsider

Accepting a risk explicitly is a legitimate and underused decision. Accepting it silently is not.

Closed risks#

IDRiskWhy closedDate
passed / mitigated / became issue ___

A register that only grows stops being read. Close things.

The review — five questions, fifteen minutes#

Not a read-through of the same twenty rows.

  1. Movement — which scores changed since last time, and what caused the change.
  2. Additions — anything arising from new dependencies, commitments or information.
  3. Retirements — risks that can no longer occur. Close them here, not "later".
  4. Overdue mitigations — actions past their date. Work this list first; it is the one that most often goes unread.
  5. Realised risks — anything that became an issue, plus a note on what this register said about it in advance. Comparing the two is how the team's scoring gets better.

Health check#

Risks scored medium___ of ___
Risks owned by the project manager___ of ___
Mitigations with no date___
Mitigations overdue___
Risks closed since last review___

If the first two are most of the register, it is being maintained rather than used.

Sign-off#

NameDate
Project manager
Sponsor reviewed

Back to Risk Register