The risk register
The Risks Registry holds things that haven't happened yet and would hurt the work if they did. Something that has already happened belongs in a report or in Complaints & Feedback, not here.
Add a risk
- Open Risks Registry and add a new risk.
- Write a clear title and a description.
- Choose the type: operational, financial, security, reputational, environmental or other.
- Choose the likelihood and impact: low, medium or high.
- Write the mitigation plan: what you'll do about it. If you don't know yet, write "none yet".
- Link it to the project, and to the activity or indicator it threatens, if there is one.
Tip Search looks at titles only. Write a title you'd search for later, such as "Road to Northern District closed by checkpoint", rather than "Access problem".
Read likelihood and impact together
- High impact, however likely: write a mitigation plan now.
- High likelihood, low impact: plan around it, without escalating.
- Low and low: record it and move on.
Statuses
| Status | Meaning |
|---|---|
| Identified | Written down, nothing done yet |
| Mitigated | The mitigation plan has been carried out |
| Escalated | Passed to someone with the authority to act |
| Resolved | No longer a live risk |
| Accepted | You've knowingly decided to carry it |
Accepted is a real decision, not neglect. Some risks can't be reduced at a reasonable cost. Write down why you accepted it.