Glossary

Risk Register

The living record of a programme's identified risks: what could go wrong, how likely, how severe, who owns the response. Also, frequently, the only place dissent about a decision is written down.

Read a programme's risk register carefully and you learn two things: what the team is worried about, and whether worrying is something this organisation does on paper or in practice.

Last reviewed 3 July 2026 · Free and ungated

Get independent perspectives

Some risks cannot appear in a register the delivery team owns; a confidential client brief to the Global Board surfaces them before you commit.

Get independent perspectives

How a client brief works · What you receive

What it means

A risk register is a structured log of the risks facing a project, programme or organisation. Each entry typically records a description, an assessment of likelihood and impact, a named owner, the mitigation planned or under way, and a review date. It is the standard instrument through which governance bodies are meant to see trouble coming.

Why it matters more than its reputation

In organisations where open disagreement is expensive, the register is where reservations go to be recorded without being voiced. That makes it an unusually honest document, if anyone reads it that way. When a major commitment is up for approval, the register shows whether the risks were engaged or ritually documented: entries with specific triggers, funded mitigations and recent review dates signal the former; a wall of amber scored 3x3 with mitigations that read "monitor closely" signals the latter. The register also creates a comfortable illusion, that a risk with an owner and a row in a spreadsheet is a risk being managed. Parking is not mitigation.

How registers decay

Risks written vaguely, "delivery timescales may be challenging", so no action could ever follow from them. Scores negotiated downward before board packs are issued, because a red risk invites questions the team would rather not take. Registers updated the day before each steering meeting and untouched between. And the structural omission: the risk that the decision itself is wrong, the strategy, the vendor, the deal, almost never appears, because the register belongs to the team executing the decision, not to anyone questioning it.

The register lists the risks to the plan. Who lists the risk in the plan?

Get independent perspectives