
Risk Register: The Central Repository for Project Risk Management
PMBOK v8 Definition
The risk register is a repository in which outputs of risk management processes are recorded. It captures details of identified individual project risks. The results of the following processes are recorded in the risk register as these processes are conducted throughout the project: Identify Risks, Perform Risk Analysis, Plan Risk Responses, Implement Risk Responses, and Monitor Risks. The risk register may contain limited or extensive risk information depending on project variables such as size and complexity.
This concept belongs to the Project Risk Management knowledge area and is a key output of the Identify Risks process (Planning Process Group), which is updated continuously throughout all subsequent risk processes.
Why It Matters for the Exam
The risk register appears in multiple process questions on the PMI exam, particularly those testing the sequence of risk management activities and the inputs/outputs of each process. Expect scenario-based questions where you must determine which document is being updated, and process flow questions where you need to identify which risk processes feed into or update the risk register.
Key Points to Remember (for the exam)
- Five Processes That Update the Risk Register: Identify Risks → Perform Risk Analysis → Plan Risk Responses → Implement Risk Responses → Monitor Risks
- Primary Content from Identify Risks: List of identified risks (each with a unique identifier) and potential risk owners
- Risk Statement Structure: Distinguishes between cause, risk, and effect (structured risk statement format)
- Iterative Nature: Risk register updates are performed regularly throughout the project life cycle; initial identification is always incomplete
- Variable Detail Level: Content depends on project size and complexity (limited vs. extensive information)
- Key Distinction: The risk register tracks individual project risks, not overall project risk (which is in the risk report)
- Timing Information: Records when a risk was identified, when it might occur, when it may no longer be relevant, and the deadline for taking action
Typical PMI Exam Example
A project manager is facilitating a risk identification workshop. The team identifies a potential delay due to supplier delivery issues. The project manager assigns a unique identifier and records the risk along with its cause (supplier capacity constraints) and effect (schedule delay of 2 weeks). The potential risk owner is documented as the procurement lead. Which process is being performed, and what is being updated?
Answer: The Identify Risks process is being performed, and the risk register is being updated with the list of identified risks and potential risk owners.
PMI Exam Traps
-
Trap: Confusing the risk register with the risk report
- Reality: The risk register captures individual project risks; the risk report presents information on overall project risk exposure
-
Trap: Thinking the risk register is created only once during planning
- Reality: The risk register is iteratively updated throughout all five risk processes and the entire project life cycle
-
Trap: Assuming the risk register only contains identified risks
- Reality: It also contains risk analysis results, response plans, implementation status, and monitoring updates from all subsequent processes
-
Trap: Believing the risk register is created during Plan Risk Management
- Reality: Plan Risk Management produces the risk management plan; the risk register is first created during Identify Risks
Important PMI Connections
| Related Concept | Relationship Type | Exam Attention Point |
|---|---|---|
| Risk Report | Complementary output | Risk register = individual risks; Risk report = overall project risk exposure |
| Assumption Log | Input to Identify Risks | Assumptions and constraints help identify potential risks; both documents are updated iteratively |
| Issue Log | Related document | Issues are realized risks; the issue log tracks problems that have occurred, while the risk register tracks potential future events |
| Lessons Learned Register | Updated during risk processes | Lessons from risk management activities are recorded and inform future risk identification |
Quick Review Questions
-
Which five processes record their outputs in the risk register as they are conducted throughout the project?
-
When the Identify Risks process is performed, what two main elements are included in the risk register content?
-
Why must the risk register be updated regularly throughout the project life cycle, rather than only during planning?
-
What is the difference between information captured in the risk register versus information captured in the risk report?
-
During which process is the risk register first created as an output?
PMBOK v8 Reference
Section 4 – Inputs and Outputs (Risk Register definition and updates) Figure 2-47 – Risk Performance Domain Processes Overview Figure 2-52 – Implement Risk Responses Inputs, Tools and Techniques, and Outputs Figure 2-53 – Monitor Risks Inputs, Tools and Techniques, and Outputs