Risk Register: Essential Content and Structure from Identify Risks Process

Risk Register: Essential Content and Structure from Identify Risks Process

PMBOK v8 Definition

The risk register is the primary output of the Identify Risks process, which belongs to the Planning Process Group within the Project Risk Management Knowledge Area. According to PMBOK v8, the risk register contains a list of identified risks, each given a unique identifier, described in sufficient detail to ensure unambiguous understanding. Additional data recorded for each identified risk may include short risk title, risk category, current risk status, one or more causes, one or more effects on objectives, risk triggers, WBS reference of affected activities, and timing information.

Why It Matters for the Exam

The risk register appears in approximately 15-20% of risk management questions on the PMI exam, particularly in scenario-based questions where you must determine what information belongs in the risk register versus the risk report. Questions frequently test your ability to distinguish between the initial content recorded during Identify Risks and the content added during subsequent processes like Perform Risk Analysis and Plan Risk Responses.

Key Points to Remember (for the exam)

  • Main Input to Identify Risks: Risk management plan (specifies risk register format)
  • Main Output: Risk register (created during Identify Risks, updated throughout project)
  • Essential Initial Content: List of identified risks, potential risk owners, potential risk responses
  • Key Data Elements: Short risk title, risk category, current risk status, causes, effects on objectives, risk triggers, WBS reference, timing information
  • Common Confusion: The risk register is NOT the same as the risk report—the risk register contains detailed individual risk data; the risk report contains summary information and sources of overall project risk
  • Unique Identifier: Each individual project risk receives a unique identifier in the risk register
  • Structured Risk Statement: Used to distinguish risks from their cause(s) and their effect(s)

Typical PMI Exam Example

A project manager is facilitating the Identify Risks process. The team identifies a risk that a key supplier may go bankrupt. What information should be recorded in the risk register? Answer: Short risk title, risk category, current risk status, causes, effects on objectives, risk triggers, WBS reference of affected activities, timing information, potential risk owner, and potential risk response.

PMI Exam Traps

  • Trap: Confusing the risk register with the risk report

    • Reality: Risk register = detailed individual risk data; risk report = summary information and sources of overall project risk
  • Trap: Thinking all risk data is finalized during Identify Risks

    • Reality: Potential risk owners and potential risk responses are recorded initially but are confirmed during Perform Risk Analysis and Plan Risk Responses processes
  • Trap: Assuming the risk register content is identical for all projects

    • Reality: The risk register may contain limited or extensive risk information depending on project variables such as size and complexity
  • Trap: Confusing risk triggers with causes

    • Reality: Risk triggers are events or conditions that indicate a risk is about to occur; causes are the underlying sources of the risk

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Risk ReportComplementary outputRisk register = individual risks; risk report = overall project risk sources and summary
Risk Management PlanInput to Identify RisksSpecifies the risk register format and data requirements
Perform Risk AnalysisSubsequent processConfirms potential risk owners recorded in risk register
Plan Risk ResponsesSubsequent processConfirms potential risk responses recorded in risk register
Monitor RisksOngoing processRisk register is updated throughout this process

Quick Review Questions

  1. During which process is the risk register first created, and what is its primary content?

  2. What are the eight additional data elements that may be recorded for each identified risk depending on the risk management plan format?

  3. How does the risk register differ from the risk report in terms of content and purpose?

  4. When are potential risk owners and potential risk responses confirmed as final?

  5. What is a structured risk statement, and why is it used in the risk register?

PMBOK v8 Reference

Section 11.2 - Identify Risks (Planning Process Group, Project Risk Management Knowledge Area)