Risk Register and Risk Log: Documenting Threats, Responses, and Ownership

Risk Register and Risk Log: Documenting Threats, Responses, and Ownership

PMBOK v8 Definition

The Risk Register (also called Risk Log) is a document where identified risks, their analysis, planned responses, and current status are recorded and tracked throughout the project lifecycle. It is an output of the Identify Risks process and is continuously updated during Perform Qualitative Risk Analysis, Perform Quantitative Risk Analysis, and Plan Risk Responses processes (Project Risk Management Knowledge Area). The Risk Register typically includes risk description, date identified, likelihood, impact, risk rating, response strategy, and assigned owner.

Why It Matters for the Exam

The Risk Register appears in approximately 10-15% of PMI exam questions, often testing your ability to interpret risk documentation and distinguish between risk attributes (likelihood vs. impact vs. rating). Questions frequently present a partial Risk Register entry and ask you to identify the missing element, the appropriate response, or the correct next process step based on the documented information.

Key Points to Remember (for the exam)

  • Core Components: Every Risk Register entry must include: Risk Description, Date, Likelihood, Impact, Risk Rating, Response, and Owner
  • Risk Rating Calculation: Risk Rating = Likelihood × Impact (e.g., "High" likelihood + "High" impact = "High" risk rating)
  • Response Documentation: The Risk Register captures planned responses (not actual results) — e.g., "Include financial penalties in contract; build contingency into the schedule"
  • Owner Assignment: Each risk must have a single named owner responsible for monitoring and implementing the response (e.g., "Annie" or "Jim" or "Mark")
  • Update Frequency: The Risk Register is a living document updated during every risk-related process meeting
  • Common Confusion: The Risk Register is not the same as the Issue Log — risks are potential future events; issues are current problems already occurring
  • Information Radiator Use: The Risk Register can be displayed as an information radiator (Figure 5-9) for team visibility

Typical PMI Exam Example

Situation: Your project Risk Register shows: "The lead time for the leased line exceeds 90 days" — Likelihood: Unlikely, Impact: Medium, Risk Rating: Medium, Response: "Order leased line earlier than necessary; incur additional rental fees", Owner: Jim. During a status review, the leased line vendor confirms the lead time will be 95 days. What should you do first?

Correct approach: Review the Risk Register to confirm the planned response is being executed, then verify with Jim that the order was placed early as documented.

PMI Exam Traps

  • Trap: Confusing "Risk Rating" with "Impact"

    • Reality: Risk Rating is the product of Likelihood × Impact (e.g., "High" impact + "Likely" = "High" rating)
  • Trap: Assuming the Risk Register only contains threats

    • Reality: The Risk Register documents both threats and opportunities, though PMBOK v8 examples typically show threats
  • Trap: Thinking the Risk Register is created once and finalized

    • Reality: The Risk Register is updated continuously — new risks are added, existing risks are reassessed, and responses are adjusted
  • Trap: Confusing Risk Register with Risk Report

    • Reality: The Risk Register is the detailed log; the Risk Report is a summary for stakeholders (different artifacts)

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Issue LogComplementary artifactIssues are realized risks; when a risk occurs, it moves from Risk Register to Issue Log
Lessons Learned RegisterInput to / Output fromRisk Register entries inform lessons learned; lessons learned help identify new risks
Information RadiatorDisplay methodRisk Register can be displayed as an information radiator (Figure 5-9) for transparency
Project DashboardSummary viewDashboard shows risk status at a glance; Risk Register provides the detail behind dashboard metrics

Quick Review Questions

  1. A Risk Register entry shows: Likelihood = "Very likely", Impact = "High". What is the Risk Rating?
  2. In the Risk Register example provided, who is the owner of the risk about insufficient capacity for database instances?
  3. What is the difference between a Risk Register entry and an Issue Log entry?
  4. If a risk's planned response is "Employ temporary staff to free up resources for testing; revise project schedule", what process produced this response?
  5. Which Risk Register field would change if a risk that was "Unlikely" becomes "Very likely" after reassessment?

PMBOK v8 Reference

Section 11.2 - Identify Risks (Risk Register as output) Section 11.3 - Perform Qualitative Risk Assessment (Risk Register updates) Section 11.5 - Plan Risk Responses (Risk Register updates with response plans) Figure 5-9 - Information Radiator (Risk Register display example) Figure 5-16 - Project Dashboard Example (Risk Register integration)