Guidelines for Creating the Risk Register
1) Work with your entire project team to identify possible risk events for your
project. Leave no stone unturned, you should be able to identify at least 8.
2) Collaborate with your team to assign probabilities and impacts to each event.
3) Multiply the probability percentage (1 to 10 using whole numbers instead of a
percentage) by the impact level (1 to 10 whole numbers) to arrive at a product
that represents a level of risk for that event. The impact level represents the
effect that the risk event has upon the completion of your project. A 10 m eans a
catastrophic effect on your project, usually resulting in failure or cancellation.
An impact level less than 10 means that the risk event has an effect that will
delay the due date of your project depending upo n where it is on the scale of 1 to
9. The next step is to create thresholds that represent low, medium and high
risks so that you can prioritize risk events in order to assign possible responses.
4) Create thresholds fo r low, medium and high risk classifications. Be sure to add
these thresholds as part of a legend for your risk register just as you saw in the
Great Escape and Hurricane Katrina Risk Register. These are thresholds
assigned specifically for each project , but you will set thresholds based on the
risk parameters of your team’s unique project. Organizations usually create
thresholds for their projects based on experience with the specific risk events
common to that industry.
5) Once you have assigned thresholds, address the possible risk responses for the
“high risk ” events first. Do this collectively as a team, since this takes some
discussion and choices need to be made . Your choices are avoid, transfer,
mitigate, contingent response, and accept. Make sure that you select only ONE
of the above as a risk response for your Risk Register, even though more than
one is listed in some of the entries on the Great Escape Risk Register. This has
been done to show choices available at the time of the creation of the risk
register for that event. In the case of the Great Escape, they started with a
mitigation strategy using three tunnels, but later updated their Risk Register
and changed to a contingent response strategy because they found that they did
not have enough wood to shore up all three tunnels. Instead the risk response
became a contingency; open up one of the other tunnels if the main tunnel
“Tom” is discovered by the German guards. When this risk event does occur,
they are ready to open up tunnel “Harry”, which has already been partially
completed. Mitigation is not the same as contingency, so make sure that you
understand the difference before assigning risk responses. Mitigation usually
involves some pre-paid actions that will reduce either the probability of
occurrence or the impact or in some cases, can affect both. Contingent Response
involves creating alternative plans to reduce the impact of a ris k event should it
occur, but has no effect on the probability of occurrence.
6) If you decide to mitigate the risk event, then you want to make an educated guess
as to what it would cost to reduce the impact and/or probability of the event
happening. Put in a pre -paid cost for the mitigation or if you decide to transfer
the risk to third party, this then becomes the insurance premium that you will
pay over the course of project in case that specific risk event occurs.
7) Also calculate a cost per occurrence for each event that qualifies as high risk.
8) Contingent Response is an “if/then” strategy. That means if a specific risk event
happens, then an alternative plan to reduce the impact of the risk event is
activated. Planning is not without cost. Estimate how much time it would take
times the number of people at your hourly assigned pay rates for the team
members who will create the plan(s). Put that number in your “pre -paid cos t”
column on the Risk Register along with any additional costs to creating a specific
contingent response.
9) Take a look at your medium risk events, and do the same process for these as
well if your project team sees these as impo rtant enough to mitigate or have a
contingency plan.
10) Low risk events in general will have “accept” as a risk response, but discuss
these as well with your team.
11) Be sure to populate at least half of your risk events with pre-paid costs and cost
per occurrence, this should be the high and medium risks based on the threshold
levels that you have assigned.
12) Sponsors typically are not averse to providing resources associated with the risk
register. However, these are specifically related to the cost of contingencies and
mitigation, as delineated by the project team. Any such costs are then added to
your project budget.
However, sponsors are typically not comfortable with a catch -all margin (like
10%) tacked on to the project to cover those costs that are listed in the risk
register. This margin is then used in due course as if it were part of the original
budget, thus increasing the cost of the project by that percentage and giving the
project team license to perform inaccurate cost estimating.