A risk is something that has not happened and might, and would affect the project if it did. The register captures each one with enough structure to act on: what it is, what would trigger it, how likely it seems and how much it would hurt, what the project will do about it, who is responsible for doing that, and when the entry will next be looked at. The estimates are rough and the ranking they produce is still the most useful thing in the document, because attention is finite and the register says where to spend it.
| Response | What it means on a project | Example |
|---|---|---|
| Avoid | Change the plan so the risk cannot occur | Drop the untested technology from the design |
| Mitigate | Act now to lower likelihood or impact | Run a pilot before the full rollout |
| Transfer | Move the consequence to someone else | Fixed-price contract, insurance, a penalty clause |
| Accept | Decide to live with it, and say so | Record the owner and the trigger that would change the decision |
| Escalate | It belongs above the project | Take it to the sponsor or the programme, and record that you did |
- One owner per line, and the owner is a person who can act, not a team or a role.
- A trigger, so the owner knows what to watch for and when the risk has become an issue.
- A funded response, because a mitigation without budget or time is a wish.
- A review date, because likelihood changes as the project moves and a register reviewed only at the start describes a project that no longer exists.
- A separate issue log, for things that have already happened; a register that mixes risks and issues is managing neither.
The entry-level certificates ask for the vocabulary and the response types; the professional ones test what a manager does when a risk on the register materialises, which is to move it to the issue log, execute the planned response, and tell the people the register said to tell. PRINCE2 makes the register a mandated product and the review a fixed step in each stage; PMI's body of knowledge treats risk as a performance domain running through the whole project. Both agree that the document is worthless unless it changes what somebody does.
