Project risk register
RegisterWhat might go wrong, how likely you think it is, who carries it, and what you are actually doing about it.
No score, and the absence is the feature
A five-by-five grid with a number in each cell looks like measurement and is not. The number is two guesses multiplied on a scale nobody calibrated, and its real effect is to let a register be sorted and reported without anybody reading it. What this asks for instead is a sentence: what could happen, how likely you think it is, what it would cost. Harder to write, impossible to mistake for arithmetic.
Accepted is a real answer
Deciding to live with a risk is a legitimate decision that most registers have nowhere to record, so people close risks they have not addressed instead. Accepted is its own state here, colored as still open, because the risk has not gone anywhere just because somebody made peace with it.
Where it sits
When a risk happens it becomes an entry in the issue log. What you decided and why belongs in the decision log, changes in the change request log, and the summary upward in the status report.
A register of judgments you wrote. CompliMaint produces no risk score, probability rating, severity number or ranking, and decides nothing about insurance, liability or who bears a loss. Everything runs on your device.
Questions people ask
- Why is there no risk score?
- Because a risk score is two guesses multiplied together, and once it is printed people trust it. They sort by it, report it, and justify decisions with it — and the underlying judgment, which was somebody’s honest opinion, has been laundered into a number that looks like measurement. Write what could happen and how likely you think it is, in words, and the reader knows exactly what they are looking at.
- Where do I record likelihood and impact then?
- In the description, in your own words, which is where they belong. What could happen, how likely you think it is, and what it would cost you — three sentences that a reader can weigh, argue with and act on. A dropdown pair gives you neither the nuance nor the accountability.
- What is Accepted for?
- For a risk you have decided to live with. It is a real and often correct decision, and a register with nowhere to record it pushes people to close risks they have not addressed. It is colored as waiting rather than done, because an accepted risk is still there.
- What happens when a risk occurs?
- Mark it Occurred, which is terminal here, and raise it in the issue log. It has stopped being a risk: the questions you ask about something that has happened are different from the questions you asked about something that might. Both records survive, which is exactly what you want when somebody asks whether you saw it coming.