| name | risk-register |
| description | Maintain a project risk register that makes uncertain events, probability, impact, triggers, mitigation, contingency, ownership, and residual exposure visible throughout delivery. |
Risk Register
Use when project delivery has material uncertainty that should be managed before it becomes an issue.
Procedure
- Capture risks as specific uncertain events or conditions and the outcome they could affect.
- Record likelihood or uncertainty, impact, time horizon, trigger indicators, and evidence at a level of precision the project can support.
- Assign one accountable owner for monitoring and response.
- Define mitigation that reduces likelihood or impact and contingency that applies if the risk occurs.
- Distinguish risks from active issues, assumptions, dependencies, and decisions so each gets the right treatment.
- Prioritize attention on exposure and decision value rather than maintaining a decorative list of every imaginable problem.
- Review risks at meaningful milestones and when scope, architecture, vendor, staffing, or external conditions change.
- Close, accept, transfer, or escalate risks explicitly and preserve rationale for accepted residual exposure.
Decision rules
- A long risk list is not evidence of good risk management.
- Do not assign every risk to the project manager by default.
- Risks without triggers or owners are easy to ignore.
- Escalate when mitigation requires authority outside the project team.
Quality gate
The register is useful when material risks are specific and owned, mitigation and contingency are actionable, triggers are observable, active issues are separated, and accepted residual exposure is visible to the people accountable for the outcome.