Free during our launch: every feature, every plan, until 31 March 2027.

See the offer

Risk

Project risk management, step by step

A risk is something that may happen and would change your cost, date or scope. This guide covers the five steps that keep risks from becoming surprises: identify, assess, respond, review and close.

Updated · 3 min read

1. Identify: build the risk register

The risk register is the list of everything that might go wrong, or better than planned. Fill it with the people doing the work: walk the schedule phase by phase and ask what could delay it, what depends on someone outside the team, and what went wrong last time. Write each risk as cause, event and effect so it is clear what would have to be true for it to happen.

A register needs these columns, and not many more:

ID and titleA short name anyone on the project understands.
Cause, event, effect"Because of X, Y may happen, which would lead to Z." One sentence.
Probability and impactEach rated 1 to 5. The score is one times the other.
Cost and schedule exposureWhat it would cost and how many days it would add if it happens.
OwnerOne named person, not a department.
Response and due dateWhat will be done, by whom and by when.
StatusOpen, being treated, occurred or closed.

2. Assess: score each risk

Rate probability and impact from 1 to 5 and multiply them. On a five by five matrix that gives a score from 1 to 25. A common banding is 1 to 5 low, 6 to 14 medium and 15 to 25 high. Agree what each rating means before you start: "impact 4" should mean the same delay or cost to everyone in the room.

For the risks that matter, put numbers on them. The expected monetary value is the probability times the cost if it happens: a 30% chance of a 200,000 cost is an EMV of 60,000. The sum of EMVs across the register is a first estimate of the contingency the project needs. You can try both with the risk score and EMV calculator.

3. Respond: choose what to do

Every high risk needs one of four responses, an owner and a date:

  • Avoid. Change the plan so the risk cannot happen, for example by choosing a proven supplier.
  • Transfer. Move the consequence to someone better placed to carry it, through insurance or contract terms.
  • Mitigate. Reduce the probability or the impact, for example by ordering long-lead items early.
  • Accept. Do nothing now, and hold a contingency in case it happens.

Opportunities mirror these: exploit, share, enhance or accept. A response is worth doing when it removes more expected cost than it costs.

4. Connect risks to the schedule

A matrix ranks risks; it does not tell you what they do to the finish date. For that, link each risk to the activities it would delay and run a Monte Carlo schedule risk analysis. The result is a range of finish dates, such as a P50 and a P80, and a list of the risks and activities that drive it. Remove one risk and run it again, and the change in P80 is what that risk costs you in days.

5. Review and close

A register that is filled in once and never opened again is the usual failure. Review it at every reporting period:

  • Re-score the open risks. Has anything changed?
  • Check each response against its due date.
  • Close risks whose window has passed, so the list stays short.
  • Move risks that happened to the issue log, with an owner and an action.
  • Add the new risks the last month revealed.
  • Report the top five and the total exposure to the sponsor.

In Critova the register is a list, a board by status and a clickable five by five matrix. Each risk has an owner, a response and a due date, the EMV is calculated for you, and risks can be linked to activities for the Monte Carlo run. See risk and Monte Carlo.

Common questions

What is the difference between a risk and an issue?

A risk may happen; an issue has happened. Risks get responses that reduce their chance or impact. Issues get actions that fix them.

How many risks should a register have?

As many as the team will actually review. Twenty well-described risks with owners are worth more than two hundred nobody reads.

Who should own a risk?

The person best placed to act on it, by name. The project manager owns the register, not every risk in it.

Bring one schedule. See your critical path in an hour.

Free during our launch until 31 March 2027.