Risk Register in Project Management - Project Management Academy Resources (2024)

Posted on December 29, 2021 December 1, 2022

Risk is such a given in any project that, as we like to say, the biggest risk is ignoring project risk management. One strategy to help you anticipate and plan for potential project risks is creating a risk register and risk report. Project Management Professionals (PMP) use a risk register and risk report on risk-driven projects or risk-aware projects.

This risk register overview by your experts at Project Management Academy is your complete resource on the “who, what, when, where, and why” of risk registers in project management.

On this page:

  • When is a Risk Register Created?
  • Who Creates a Project Risk Register?
  • What is Included in a Risk Register?
  • Risk register PMP how-to guide
  • Conclusion
Risk Register in Project Management - Project Management Academy Resources (1)

Get Your Comprehensive Guide to Risk Management

Learn how to manage risk in every project.

Risk Register PMP definition & purpose

A risk register is a document used to track and report on project risks and opportunities throughout the project’s life cycle. The contents of this tool can help you identify and organize information about potential issues that can impact project elements and outcomes. Here are some other uses of a risk register:

  • Identifying potential risks
  • Predicting the probability of a risk event occurring
  • Putting controls in place to mitigate risks
  • Establishing a response plan in the event a risk occurs
  • Creating a risk report to summarize overall project risk, communicate to project stakeholders, and support overall risk management
  • And much more!

For some projects, risk registers are required to meet compliance regulations. However, a risk register is an essential PMP exam tool for any project, no matter the size, complexity, or industry. Although it is impossible to anticipate every possible risk that could affect your project, a risk register will help you establish an effective risk management plan to prevent risks from derailing your project.

What is the difference between an issue vs. a risk?

While risk is an event that has not happened yet, an issue is an event that has already happened. Both issues and risks describe problematic events or conditions that can impact your project elements or outcomes.

As a project manager, you should know how to store, track, and organize information about both risks and issues. The document you use to store content about risks is called a risk register, while the document you use to store content about issues is called an issue log.

When is a Risk Register Created?

A risk register is created when a project carries many moving parts or much risk. The more complex a project is, the more critical it is to create a risk register. However, having a risk register is helpful for any project. Even including a simple spreadsheet in your project plan can help you track and mitigate risks.

Similarly, while a risk register is typically created during the project’s execution phase, it is never too early to begin thinking about risk management. Risk management should start as soon as project planning does. The sooner you create your project risk register, the sooner you will have a thorough document on hand to help you manage and report on risk.

Who Creates a Project Risk Register?

Project managers are typically responsible for creating a project risk register. However, if your project team includes a dedicated risk management professional, such as a PMI Risk Management Professional (PMI-RMP)® credential holder, creating and maintaining the content in the risk register would be their job.

Despite this, every project team member should contribute content to the risk register if possible. One person might be aware of a risk that no one else knows about, and in addition, anyone could potentially be impacted by any risks to the project. As a result, it can help to collaborate in identifying risks and appropriate risk response plans.

What is Included in a Risk Register?

There are many ways to go about creating a risk register, and there is no single correct method. You might need to include much detail in your risk register, or you might need a simple tool to help you stay organized. The contents of your risk register should at least capture the following:

  • Qualitative and quantitative data about potential risks
  • Estimates regarding the potential impact of the risk
  • An outline of your established response plan
  • Who on the project team will take ownership of the risk

This list is also a helpful general guide to the order in which you should acquire risk information. If you want to get more detailed, the following components can help you break down and organize project risk content on a more granular level:

  • Risk Identification: a name or ID number to identify the risk. This element can be as simple as a reference number or letter.
  • Risk Description: a brief explanation of the risk event or conditions that may trigger the risk event.
  • Risk Analysis: a qualitative or quantitative estimate of the probability and impact of the risk event.
    • Risk Probability: the likelihood of a risk event occurring
    • Risk Impact/Categories: a description of which categories can impact or be impacted by the risk event, such as schedule, budget, scope, quality, or more.
    • Risk Priority: the risk score, which can be determined quantitatively (by multiplying the risk impact and probability) or qualitatively (by putting risks in the order of the highest impact and highest probability)
  • Risk Response Plan: a description of the actions you will take to mitigate the effects of a risk event if it occurs
  • Risk Ownership: a description of who will become the risk owner and take on the responsibility for deploying and supervising the risk response plan

Now you know what goes into a risk register, let’s go over some recommendations for creating your PMP risk register.

Studying for the PMP Exam?

Risk register PMP how-to guide

Over time, you will be able to determine what content you need in your risk register to meet the needs of your specific industry and project types. When you first begin, try using a sample PMP exam risk register such as the Project Management Academy template.

Using a risk register template as a reference will help you familiarize yourself with the process of gathering, calculating, and documenting all the necessary information. As you become more familiar with risk registers, you can adapt these practices to your needs.

Follow these steps to add content to your risk register using the Project Management Academy PMP risk register template as your guide.

1. Identify all potential risks

Your first step in creating a risk register is identifying risks. This step is essential in effective risk management. It can be challenging to identify every single possible risk, but here are some tips to help you add content to your risk register:

  • Review historical data. If your organization has run a similar project in the past, there may be common risks to add to your register.
  • Check-in with stakeholders. Your project team members, clients, and other stakeholders may be aware of potential risks that you don’t know about, so ensure you ask for their input.
  • Do some market research. Market research will help you discover potential external risks, such as supply and demand, common project management issues, or past project information shared by other organizations and project managers.

Once you have identified all potential risks, you can organize your content in a risk breakdown structure.

2. Layout your risk breakdown structure

A risk breakdown structure is a tool to help you organize your risk register. You can use your risk breakdown structure to categorize risks, track data, and compare information about various risks. Examples of risk breakdown structures include charts or spreadsheets structured to classify and compartmentalize project risk content logically.

Keeping an organized risk breakdown structure is critical to risk reporting. Your risk register is the primary tool you will use to track and report project risks to stakeholders.

3. Gather qualitative data about each risk in your risk register

Qualitative project risk data can include your risk identification, risk description, and some or all elements of your risk analysis. For example, a risk description or risk statement can be phrased in the following ways:

  • EVENT may occur, causing IMPACT
  • If CONDITION exists, EVENT may occur, leading to EFFECT

In this sample content, the capitalized words represent variables on the specific risk you describe.

Risk analysis can be done either qualitatively or quantitatively. Here are some examples of qualitative risk analysis:

  • Risk probability: is the chance of a risk event happening low, medium, or high?
  • Risk impact/categories: will a category impact or be impacted by a risk event, and is the impact likely to be low, medium, or high?
  • Risk priority: how would you describe each risk’s combined probability and impact score? For example, if a risk’s probability is low and its potential impact is medium, its priority is medium-low.

There may be other qualitative components to each risk, but these content elements provide a great starting point to help you break each risk down in more detail.

4. Calculate quantitative data about each risk in your risk register

If you are performing quantitative risk analysis, here are some examples of how you would adjust your approach:

  • Risk probability: calculate the likelihood of the risk event or condition occurring and express it as a ratio or percentage.
  • Risk impact/categories: score the potential impact of the risk on each of your project’s objectives or categories using a standardized number system.
  • Risk priority: multiply the probability by the impact score to calculate a risk priority level.

Risk quantification can help you evaluate your identified risks and develop data to support your decision-making processes.

5. Determine the order of priority for your risk register

Once you have established the risk priority level for each risk event or condition in your risk register, you should order them within your risk breakdown structure by priority level. Arranging your risk register content by order of priority will give you a better picture of your highest-priority risk, any related risk events, and more.

6. Outline your risk response plan

Understanding each risk event’s priority level will also help you determine the urgency for your relevant risk response plans. You should come to a consensus with your project stakeholders about a favorable risk response for each item in your risk register, including identifying the risk owner who will oversee the execution of the risk response plan if the risk becomes an issue.

Ideally, your risk response plan will lower the likelihood of the risk occurring, reduce the impact of each risk on your project categories, or eliminate the risk. Ensure you think about how your risk response plan may impact your project’s budget, timeline, and other categories as well.

Risk Register in Project Management - Project Management Academy Resources (2)

Conclusion

Having a risk register to record and track all identified project risks is essential to the success of your project. This crucial tool in the risk management process can help you avoid problems or mitigate their effects on your project outcomes.

Do you want to learn more about risk management for the PMP exam and project management? Read our resources on risk audits in project management or how to apply risk management in your projects.

Risk management is critical in project management. That’s why the Project Management Professional certification and the PMI Risk Management Professional (PMI-RMP)® certification both emphasize practical risk management skills. Get in touch with your Project Management Academy experts to learn how to hone your risk management skills.

Upcoming PMP Certification Training – Live & Online Classes

NameDatePlace
PMP Certification TrainingMar 30,31 & Apr 6,7
8:30am-6:00pm
Boston, MAView Details
PMP Certification TrainingApr 22,23,24,25
8:30am-6:00pm
Boston, MAView Details
PMP Certification TrainingMar 4-7 & 11-14
5:00pm-9:30pm
Online - Green Mean Time (GMT)View Details

PMP Certification Training

Mar 30,31 & Apr 6,7 8:30am-6:00pm

Boston, MA

View Details

PMP Certification Training

Apr 22,23,24,25 8:30am-6:00pm

Boston, MA

View Details

PMP Certification Training

Mar 4-7 & 11-14 5:00pm-9:30pm

Online - Green Mean Time (GMT)

View Details

Author profile

Risk Register in Project Management - Project Management Academy Resources (3)

Erin Aldridge, PMP, PMI-ACP, & CSPO

Director of Product Development at Project Management Academy

Related entries

  • Erin Aldridge, PMP, PMI-ACP, & CSPO

    #molongui-disabled-link

  • Erin Aldridge, PMP, PMI-ACP, & CSPO

    #molongui-disabled-link

    Choosing Your Path: In-Depth Comparison of PRINCE2 Agile and PMI-ACP Certifications

  • Erin Aldridge, PMP, PMI-ACP, & CSPO

    #molongui-disabled-link

    Passing the PMI-ACP Audit: A Complete Guide to Success

  • Erin Aldridge, PMP, PMI-ACP, & CSPO

    #molongui-disabled-link

    Choosing Your Agile Path: A Comparative Guide to PMI-ACP and Disciplined Agile Certifications

Risk Register in Project Management - Project Management Academy Resources (2024)

FAQs

What should be included in a project risk register? ›

What's included in a risk register?
  1. Risk identification. One of the first entries included in a risk register is the identification of the risk. ...
  2. Risk description. ...
  3. Risk category. ...
  4. Risk likelihood. ...
  5. Risk analysis. ...
  6. Risk mitigation. ...
  7. Risk priority. ...
  8. Risk ownership.

What are the risk documents for PMP? ›

The Risk Register documents each risk and any related activities, including descriptions, probability of occurrence ratings, impact rankings, mitigation activities, and status.

What is the risk register in PMI? ›

The purpose of a risk register in project management is to record the details of all risks that have been identified along with their analysis and plans for how those risks will be treated. Basically, it's a log that identifies risks along with their severity and the actions and steps to be taken to mitigate the risk.

What is the difference between a risk report and a risk register? ›

The risk register is where you document specific risks and how to handle them. The risk report summarizes what risks you have identified, which have occurred, what responses you have implemented, and the overall risk exposure to the project.

How do I fill out a risk register? ›

Here are the basic steps to create a risk register:
  1. Identify risks to the organization. ...
  2. Define the risks the enterprise faces. ...
  3. Estimate the probability and impact of organizational risks. ...
  4. Create a risk response plan. ...
  5. Prioritize risks based on impact to the organization. ...
  6. Assign risk owners for each project.
Aug 18, 2023

What is a risk register in project management with examples? ›

A project risk register is usually a spreadsheet that documents a project's potential risks. The register includes a possible mitigation plan and a response owner. A risk listing has a risk name, ID number, description, and priority or risk score.

What are the 4 types of risk in project management? ›

A risk breakdown structure outlines the various potential risks within a project. There are four main types of project risks: technical, external, organizational, and project management. Within those four types are several more specific examples of risk.

When can you first start filling out the risk register? ›

Even including a simple spreadsheet in your project plan can help you track and mitigate risks. Similarly, while a risk register is typically created during the project's execution phase, it is never too early to begin thinking about risk management. Risk management should start as soon as project planning does.

What is a project risk checklist? ›

The use of a risk checklist is the final step of risk identification to ensure that common project risks are not overlooked. What is it? Risk checklists are a historic list of risks identified or realized on past projects. Risk checklists are meant to be shared between Estimators and discipline groups on all projects.

What is a typical risk register? ›

There is no one way to create and use a risk register. Different businesses would have different needs and risks, so each risk register can be created differently. However, the typical risk register has the following elements: Risk identification and description: what is the risk and a brief description of it.

How many risks should be on a risk register? ›

As a general rule of thumb, boards should only consider a organisations top 10-15 risks articulated at a “macro” level.

What is the difference between risk register and risk management plan PMP? ›

While the risk management plan outlines your team's risk management process and approach to handling risk work, Emerson says that “the risk register is your list of risks, your analysis of those risks, and what you are planning to do about them.”

Who is responsible for risk register? ›

If you're working on a very large, complex, or critical project, you may have a risk coordinator or risk manager on your team. In this scenario, it would be their job to create and maintain the risk register. However, for most projects, responsibility for creating the risk register falls on the project manager.

How do you identify a risk register? ›

Risk registers may include the following information in a table:
  1. Risk identification number. ...
  2. Date of entry. ...
  3. Risk description. ...
  4. Likelihood that risk may occur. ...
  5. Potential impact of risk. ...
  6. Intensity of risk. ...
  7. Owner of risk response. ...
  8. Preventative actions.
Feb 3, 2023

Do you need a risk register? ›

The benefits of having a risk register

First and foremost, your risk register will aid you in identifying hazards before they become an issue or cause an injury. This allows you to plan and implement preventative measures that will ultimately reduce the likelihood of any workplace incidents or injuries occurring.

What does a project risk register look like? ›

A risk register is essentially a table of project risks that allows you to track each identified risk and any vital information about it. Standard columns included in a project risk register are: Identification number (to quickly refer to or identify each risk) Name or brief description of the risk.

What five items should be included in a risk assessment? ›

2. Steps needed to manage risk
  • Identify hazards.
  • Assess the risks.
  • Control the risks.
  • Record your findings.
  • Review the controls.

What are the three categories of risk in the project risk register? ›

To relate the risk categories to the levels of project objectives, the three categories are defined as follows:
  • Operational risks. This term refers to risks related to operational objectives of the project. ...
  • Short-term strategic risks. ...
  • Long-term strategic risks.

Top Articles
Latest Posts
Article information

Author: Corie Satterfield

Last Updated:

Views: 6364

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Corie Satterfield

Birthday: 1992-08-19

Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

Phone: +26813599986666

Job: Sales Manager

Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.