Project Risk Management Basics
A simple framework for identifying, assessing, and controlling project risks
Purpose. This original quick-reference guide is intended for general educational use. It
summarises practical concepts and provides a compact checklist for everyday reference.
1. What Is a Project Risk?
A project risk is an uncertain event or condition that may affect objectives such as scope,
cost, schedule, quality, security, or stakeholder confidence. Risks are different from issues: a
risk may happen, while an issue has already happened and requires action.
Good project teams do not try to eliminate every risk. They identify the most important
uncertainties, assign ownership, and make conscious decisions about how to respond.
2. Build a Useful Risk Register
A practical risk register should contain a short risk statement, cause, potential impact,
probability, impact rating, overall score, owner, response, target date, and current status.
Avoid vague entries such as “project may be delayed.” A better statement explains why the
delay could occur and what consequence it would have.
The owner should be the person accountable for managing the risk, not simply the person
who wrote it down. Each major risk should have a specific next action.
3. Assess Probability and Impact
A simple three- or five-level scale is usually sufficient. Probability describes how likely the
event is, while impact describes the consequence if it occurs. Teams may calculate a score
by multiplying the two ratings, but the score is only a decision aid.
Some risks deserve escalation even when their mathematical score is moderate. Examples
include regulatory non-compliance, safety concerns, irreversible data loss, or events that
could stop the project entirely.
4. Choose a Response
Common responses are avoid, reduce, transfer, and accept. Avoidance changes the plan so
that the risk no longer exists. Reduction lowers probability or impact. Transfer moves part of
the exposure to another party, often through contracts or insurance. Acceptance means
consciously taking the risk while watching for triggers.
Where possible, define both preventive actions and contingency actions. Preventive actions
are taken now; contingency actions are used if the risk actually occurs.
5. Review Risks Regularly
Risk management works best as a recurring project activity. Review major risks during status
meetings, remove closed risks, add new ones, and update ratings when circumstances
change. A risk that has not been reviewed for months is unlikely to be useful.
The objective is not a large register. The objective is better decisions, fewer surprises, and
clear ownership of uncertainty.
Original quick-reference document • 2026
Quick Checklist
Don Check
e
☐ Write risks as cause-event-impact statements
☐ Assign one accountable owner
☐ Rate probability and impact
☐ Define a response and next action
☐ Record contingency triggers
☐ Review high risks at every status cycle
Note: This guide is general information and should be adapted to your environment, policies, and
professional requirements.
Original quick-reference document • 2026