The risk register

The Risks Registry holds things that haven't happened yet and would hurt the work if they did. Something that has already happened belongs in a report or in Complaints & Feedback, not here.

Add a risk

  1. Open Risks Registry and add a new risk.
  2. Write a clear title and a description.
  3. Choose the type: operational, financial, security, reputational, environmental or other.
  4. Choose the likelihood and impact: low, medium or high.
  5. Write the mitigation plan: what you'll do about it. If you don't know yet, write "none yet".
  6. Link it to the project, and to the activity or indicator it threatens, if there is one.

Tip Search looks at titles only. Write a title you'd search for later, such as "Road to Northern District closed by checkpoint", rather than "Access problem".

Read likelihood and impact together

  • High impact, however likely: write a mitigation plan now.
  • High likelihood, low impact: plan around it, without escalating.
  • Low and low: record it and move on.

Statuses

Status Meaning
Identified Written down, nothing done yet
Mitigated The mitigation plan has been carried out
Escalated Passed to someone with the authority to act
Resolved No longer a live risk
Accepted You've knowingly decided to carry it

Accepted is a real decision, not neglect. Some risks can't be reduced at a reasonable cost. Write down why you accepted it.