Risk Information in the Risk Report and Risk Register

Risk Information in the Risk Report and Risk Register

PMBOK v8 Definition

Risk information is documented throughout the Risk performance domain processes: Perform Risk Analysis, Plan Risk Responses, Implement Risk Responses, and Monitor Risks. When the Identify Risks process is completed, the risk report may include sources of overall project risk (indicating the most important drivers of overall project risk exposure) and summary information on identified individual project risks (number of identified threats and opportunities, distribution across risk categories, metrics and trends). The risk register contains a list of identified risks (each with a unique identifier), described in sufficient detail to ensure unambiguous understanding, and may include potential risk owners identified during the process.

Why It Matters for the Exam

The distinction between the risk report and the risk register is frequently tested on the PMI exam, particularly in questions about which document contains what type of information. Exam questions often present a scenario where you must determine whether a specific piece of risk data belongs in the risk report (overall project risk) or the risk register (individual project risks). This concept appears in situational and definition-type questions across the Planning and Monitoring & Controlling process groups.

Key Points to Remember (for the exam)

  • Risk Report Content (after Identify Risks): Sources of overall project risk, summary of identified individual risks (threats/opportunities count, risk category distribution, metrics and trends). Additional information depends on the risk management plan reporting requirements.
  • Risk Register Content (after Identify Risks): List of identified risks (each with unique identifier), detailed risk descriptions using structured risk statements to distinguish cause(s) from effect(s), and potential risk owners.
  • Key Distinction: The risk report focuses on overall project risk exposure and aggregate information; the risk register focuses on individual project risks with detailed descriptions.
  • Schedule Baseline: The schedule baseline is included as risk report information (per PMBOK v8 context).
  • Nonrisks: The Identify Risks process focuses on distinguishing genuine risks from nonrisks such as concerns and issues. Not all risks can be identified at the outset due to inherent uncertainties.
  • Risk Statement Structure: A structured risk statement distinguishes risks from their cause(s) and their effect(s) to ensure unambiguous understanding.

Typical PMI Exam Example

You are the project manager for a software development project. During the Identify Risks process, your team identifies 15 individual risks and determines that the main source of overall project risk is the dependency on a third-party API. Where should you record the dependency on the third-party API as a source of overall project risk?

Answer: The risk report, as it includes sources of overall project risk indicating the most important drivers of overall project risk exposure.

PMI Exam Traps

  • Trap: Confusing the risk report with the risk register when both contain "risks." Reality: The risk report contains overall project risk sources and summary information; the risk register contains individual project risks with detailed descriptions.
  • Trap: Thinking all risks must be identified at the beginning of the project. Reality: Not all risks can be identified at the outset due to inherent uncertainties and unknowns present at the beginning of a project.
  • Trap: Recording concerns or issues as risks in the risk register. Reality: The Identify Risks process distinguishes genuine risks from nonrisks such as concerns and issues.
  • Trap: Assuming the risk register contains only negative risks (threats). Reality: The risk register includes both threats and opportunities, as risk identification recognizes both negative and positive risks.

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Plan Risk ManagementPredecessor processDefines reporting requirements that determine additional risk report content
Perform Risk AnalysisSubsequent processUses risk information from Identify Risks to perform qualitative/quantitative analysis
Monitor RisksOngoing processTracks identified risks, identifies new risks, and updates both risk register and risk report
Risk Management PlanInput to Identify RisksSpecifies how risk information is documented and what reporting requirements exist

Quick Review Questions

  1. After the Identify Risks process is completed, which document contains the list of identified individual project risks with unique identifiers?
  2. What information about overall project risk is included in the risk report after Identify Risks?
  3. What is the purpose of using a structured risk statement in the risk register?
  4. Why might not all risks be identified at the beginning of a project?
  5. How does the risk report differ from the risk register in terms of the type of risk information each contains?

PMBOK v8 Reference

Section 2.7.2.2 - Identify Risks Section 2.7 - Risk Performance Domain