Project Risk Register Guide
A practical guide to identifying, rating, assigning, and monitoring project risks.
What a risk register does
A risk register gives the project team one place to record uncertainties that could affect cost, schedule,
quality, safety, compliance, or delivery. It supports decisions by making ownership and mitigation
visible.
Describe risks clearly
Write risks as cause-event-impact statements where possible. For example: 'Because a key approval
may be delayed, procurement could start late, causing schedule slippage.' This is clearer than simply
writing 'approval risk.'
Rate consistently
Many teams use likelihood and impact scales such as 1 to 5. The score is not the goal by itself;
consistency and management attention are more important. Define each rating so different users
interpret the scale similarly.
• Likelihood: how probable the event is.
• Impact: severity if the event occurs.
• Inherent risk: before additional mitigation.
• Residual risk: after current controls and mitigation.
Assign and review
Every significant risk should have an owner with authority to act. Review risks at a frequency
appropriate to the project and update status when circumstances change.
Register field What to record
Risk ID Unique reference number.
Risk statement Cause, uncertain event, and impact.
Owner Person accountable for managing the risk.
Likelihood / impact Defined rating using the project scale.
Mitigation Actions that reduce likelihood or impact.
Target date Expected completion date for mitigation.
Status Open, monitoring, mitigated, closed, or escalated.
Original reference document Page 1