Guide · 6 min read

Project Risk Register and Risk Management Plan

Risk management is not a list of worries. It is a process of finding risks, ranking them, deciding what to do and watching what happens. Here is how to build a register that earns marks and would actually help a project.

The risk management process

A risk is an uncertain event that, if it happens, affects a project objective such as time, cost, scope or quality. It can be a threat (negative) or an opportunity (positive). Risk management is a repeating process, not a one-off exercise.

StepWhat you doOutput
1. PlanDecide how risk will be managed, who is responsible and how risks are scoredRisk management plan
2. IdentifyFind risks using brainstorming, checklists, interviews, lessons from earlier projects, and the WBSRisk register entries
3. Analyze (qualitative)Rate probability and impact and rank risksPrioritized register
4. Analyze (quantitative)Estimate the numerical effect of the top risksExpected monetary values, contingency
5. Plan responsesDecide actions for each important riskResponse plan with owners
6. Implement and monitorCarry out responses, watch triggers, find new risks, review regularlyUpdated register and reports

Identifying risks well

Many students list generic risks such as delays and budget overruns. Better risks are specific and written as cause, event and effect: because the vendor is relying on a single supplier (cause), delivery of the servers may slip (event), which would delay testing by two weeks (effect).

To make sure you cover the ground, use a risk breakdown structure (RBS), which groups risks by source.

CategoryExample risks
TechnicalNew technology does not work as expected; integration problems
ExternalSupplier delay; regulation change; weather
OrganizationalKey staff leave; competing priorities; unclear sponsorship
Project managementPoor estimates; scope creep; weak communication
CommercialPrice rises; customer changes requirements; budget cuts

Walk through your WBS and ask what could go wrong with each work package, which finds risks that a general brainstorm misses.

Scoring probability and impact

A qualitative assessment scores each risk on probability and impact, usually from 1 (very low) to 5 (very high). Multiply the two to give a score from 1 to 25, then rank.

ScoreProbabilityImpact on schedule (example scale)Impact on cost (example scale)
1Very unlikely, below 10 percentLess than one dayLess than $2,000
2Unlikely, 10 to 30 percent1 to 3 days$2,000 to $10,000
3Possible, 30 to 50 percent3 to 7 days$10,000 to $25,000
4Likely, 50 to 70 percent1 to 2 weeks$25,000 to $50,000
5Very likely, above 70 percentMore than 2 weeksMore than $50,000
Score rangeRatingTypical action
1 to 6LowAccept and monitor
8 to 12MediumPlan a response and assign an owner
15 to 25HighImmediate action and senior attention

Agree the scale at the start and write it in the risk management plan, because without defined scales, scores are just opinions. In a project risk matrix, these scores are plotted on a grid of probability against impact, with red, amber and green zones.

A worked risk register

Here is a short register for the customer portal project from our guide on charters and work breakdown structures. The risks and figures are hypothetical.

IDRisk (cause, event, effect)PIScoreResponseOwner
R1Scope creep: stakeholders request extra features, adding work and delaying launch4416Mitigate: change control process and sponsor sign-off on any scope changeProject manager
R2Key developer leaves, so the integration stalls3412Mitigate: pair programming, documentation; identify a backupDevelopment lead
R3User adoption is low, so call volume does not fall3412Mitigate: early user testing, in-app prompts, staff scripts pointing to the portalBusiness analyst
R4Vendor delivers hosting late, delaying testing4312Transfer: penalty clause in contract; start a fallback environmentProcurement
R5Data migration errors corrupt order records2510Avoid: run migrations on a copy and verify before cutoverData lead
R6Budget overrun from underestimated integration work339Mitigate: include contingency; monthly cost reviewProject manager

Each row includes a cause, an event and an effect, a score, a response strategy and a named owner. A good register also records a trigger (the early warning sign), the status and the date of the last review.

Choosing a response

StrategyFor threatsFor opportunitiesExample
Avoid / ExploitChange the plan to remove the riskMake sure the opportunity happensDrop a risky feature; assign the best staff to a promising task
Mitigate / EnhanceReduce probability or impactIncrease probability or impactExtra testing; training that raises adoption
Transfer / ShareMove impact to a third partyShare the benefit with a partnerInsurance, fixed-price contract; joint venture
AcceptDo nothing now, with or without a contingencyTake the benefit if it occursAccept a small risk and hold a reserve

Responses should be proportionate. Spending $20,000 to reduce a risk worth $5,000 makes no sense. Also consider residual risk (what remains after the response) and secondary risk (new risk created by the response, such as a fixed-price contract that a vendor later disputes).

Working on this assignment now? Get a price for help with your paper.

Get an instant quote

Quantitative analysis: expected monetary value

For the most important risks, estimate the money at stake. Expected monetary value (EMV) is probability multiplied by impact. Summing EMVs gives a rough guide to the contingency reserve you need.

RiskProbabilityCost impactEMV
R1 Scope creep50 percent$30,000$15,000
R2 Developer leaves30 percent$40,000$12,000
R3 Low adoption30 percent$25,000$7,500
R4 Vendor delay40 percent$15,000$6,000
R5 Data migration errors20 percent$60,000$12,000
R6 Budget overrun30 percent$20,000$6,000
Total expected value of risks$58,500

The total of $58,500 is a starting point for setting the contingency reserve, which covers identified risks and is controlled by the project manager. A separate management reserve, held by the sponsor, covers unidentified risks. Remember that summing EMVs assumes risks are independent and that actual costs will be either zero or the full impact, not the average. Mention these limits, and explain that techniques such as decision trees and Monte Carlo simulation give a fuller picture.

Keeping the register alive

ActivityFrequencyOutput
Review top risks in the team meetingWeeklyStatus, new triggers, actions due
Update scores and responsesEvery two weeksRevised register
Report to the sponsorMonthlyTop five risks, trend, decisions needed
Close or retire risksAs the phase endsClosed list with lessons

Track risk burndown: the total of risk scores each month. If the sum of the top ten scores falls from 112 to 84 to 61, mitigation is working; a flat line means actions are not being done.

Risk appetite and thresholds

Organizations differ in how much risk they accept. A plan should state thresholds, such as: any risk scoring 15 or above goes to the sponsor within two days; any risk with a cost impact above $50,000 needs sponsor approval for its response. Without thresholds, escalation is a matter of mood.

Writing the risk management plan

The plan describes the approach, not the individual risks. Typical contents are listed below.

  • Methodology Process, tools and data sources.
  • Roles and responsibilities Who identifies, assesses, owns and reports risks.
  • Scoring definitions The probability and impact scales and the thresholds for low, medium and high.
  • Risk categories The RBS used to group risks.
  • Reporting and review How often risks are reviewed and who sees the reports.
  • Budget and schedule for risk work Time and reserve set aside.
  • Escalation When and how to raise a risk to the sponsor.

In agile projects, risks are reviewed at planning and retrospective meetings, and the backlog is reprioritized as risks change. Whichever approach your assignment assumes, say how the register stays alive. If you want help building a register or plan, you can order project management assignment help.

Quick answers

What is the difference between a risk and an issue?

A risk is something that might happen. An issue is a problem that has already happened and must be dealt with now. A risk that occurs becomes an issue.

How many risks should my register have?

For coursework, 8 to 15 well-described risks are usually enough. Quality, specificity and clear responses matter more than the number.

What is the difference between contingency and management reserve?

Contingency covers identified risks and is controlled by the project manager. Management reserve covers unknown risks and is controlled by the sponsor or senior management.

Can a risk be positive?

Yes. Opportunities are uncertain events that would benefit the project, and they are managed with strategies such as exploit, enhance and share.

Who should own a risk?

The person best placed to act on it, not necessarily the project manager. One named owner per risk avoids the assumption that someone else is handling it.

Need a hand with your paper?

Tell us the assignment and see your price straight away.

Get an instant quote