Documents
How to write a risk register
A risk register lists each risk with its cause, a likelihood and consequence score on defined scales, the resulting rating, an owner, a response and a status, and it is reviewed on a fixed cycle. The scales matter most: without written thresholds, two people rate the same risk differently and the matrix means nothing.
Indunil Asanka · Co-founder
6 min read · Published
To write a risk register, first write a likelihood scale and a consequence scale with plain definitions and dollar or time thresholds, then list each risk with an ID, a short description, its cause, likelihood and consequence scores, the rating they produce on a matrix, one owner, a response and a status. Review it on a fixed cycle, and at each review record which ratings moved and why. The scales are the part most registers skip, and the part that makes the numbers mean anything.
Write the scales first
Every argument about a rating traces back to an undefined scale. If “major” means $50,000 to one manager and $500,000 to another, the same risk lands in different squares and the matrix is theatre.
The risk register example, for a fictional airport terminal refurbishment, puts its scales on page one. The likelihood scale gives each score a sentence: 1, rare, might happen once in the life of the project; 3, possible, could happen in any given month of the works; 5, almost certain, expected to happen this month without action. The consequence scale gives each score a cost and a time threshold: 1, negligible, under $10,000 or under a week; 4, major, $150,000 to $500,000 or one to two months; 5, severe, over $500,000 or more than two months.
With thresholds, two people rating the same risk land on the same square.
The Commonwealth Risk Management Policy, which non-corporate Commonwealth entities must comply with, expects an entity’s framework to include a risk appetite statement supported by risk tolerance statements that set acceptable levels of risk. A small organisation does not need that vocabulary, but the scales and bands do the same job: they write down, in advance, how much is too much.
The columns
A register needs enough columns to act on a risk and no more. The example uses nine: ID, risk, cause, likelihood, consequence, rating, owner, response and status. Twelve open risks fill one table.
ID. A permanent reference such as R-02, never reused. The example’s IDs skip R-06 and R-13 because those risks closed; renumbering would break every earlier report.
Risk and cause. Short and specific. “Glazing delivery slips” caused by “single supplier” is actionable; “supply chain issues” is not.
Owner. One role. The Commonwealth policy’s guidance on responsibilities expects risk owners to be accountable for managing, monitoring, reporting and escalating risks.
Response and status. What is being done, and where the risk stands: open, treated, monitor or closed.
Add a movement section at the review rather than extra columns, as the example does.
Scoring on a matrix
A rating is likelihood multiplied by consequence. Lay the matrix out with likelihood down the side and consequence across the top, so each cell holds the product, and colour it by band. The example’s bands are low 1 to 4, medium 5 to 9, high 10 to 15 and extreme 16 to 25.
Write what each band requires next to the matrix, because the bands are policy, not decoration. The example says a risk that is likely and major, 4 by 4, scores 16, sits in the extreme band, and nothing rated extreme stays untreated past one review.
Scored examples from the register:
- R-02, glazing delivery slips. Likelihood 3, consequence 4, rating 12, high.
- R-04, airside access breach. Likelihood 2, consequence 5, rating 10, high, because the consequence is severe even though a breach is unlikely.
- R-08, tenant noise complaints. Likelihood 4, consequence 2, rating 8, medium.
Safe Work Australia’s model code of practice on managing work health and safety risks sets out the same broad sequence of identifying hazards, assessing risks, controlling them and reviewing the controls, and for a workplace safety register the consequence scale is written in injury terms rather than dollars. The safe work method statement example uses a smaller 3 by 3 matrix for roof sheeting, rated before and after controls.
Owners and responses
A response should change the likelihood, the consequence, or both. In the example, the glazing risk has a second supplier qualified and a deposit paid on long lead units, which reduces the chance of a delay. The asbestos risk has a survey, a licensed removal contract and a $180,000 allowance, which reduces both.
Each response needs an owner who can carry it out. Put actions with dates in their own short list. The example closes with three actions due before the next review, each with an owner and a date.
Review cadence and what moved
A register earns its meeting time by showing change. Twelve risks are too many to read aloud each month, so the example summarises instead:
- Top risks this month. A bar chart of the five highest current ratings.
- Movement since last review. Three rows of was, now and why. The asbestos risk, R-03, fell from 16 to 8 with the removal contract in place and three weeks of clear air monitoring. The fire system risk, R-05, halved from 12 to 6 once temporary detection was commissioned. Dust in the baggage belts, R-09, rose from 6 to 9 after two belt faults were traced to it.
- Closed this month. Two risks retired with the reason: temporary power capacity, R-06, once the permanent supply was energised, and a crane permit delay, R-13, once the permit was issued and the lifts completed.
- Actions due. Three actions with owners and dates.
The rising row matters as much as the falling ones. A register that only ever shows ratings coming down is usually a register nobody is updating honestly, and R-09 moving up is exactly the kind of early warning the review exists to catch. The meeting reads those rows and the chart; the full register is there for anyone who wants detail. Print the review date and the next review date on every page, as the example does, so nobody works from last month’s copy.
The columns table
The table at the end of this article lists eleven columns and review fields, their definitions, and an entry from the terminal refurbishment register. The note on what a risk register is covers the term in general, the project charter example shows the short day one risk list that usually comes before a full register, and the guide on how to write meeting minutes covers recording the decisions taken at each review.
Common mistakes
Scales with no thresholds. The matrix produces confident numbers that mean nothing.
Committee owners. “Project team” owns nothing.
Responses that change nothing. “Monitor closely” is a status, not a response.
Renumbering IDs. Earlier reports stop making sense.
Reviewing everything, every time. Read what moved, what closed and what is extreme.
Build it
A risk register is tables plus one chart. Documents here have 45 component types; charts come in six types, bar, horizontal bar, line, area, pie and donut, so the top risks can be a bar chart, and the Document group includes a stamp block, which suits a “reviewed” mark under the header. A four page register sits in the flow scale of two to five pages, below the six page long scale where a table of contents is used, so it does not need one.
Documents do not print citations, so if the scales follow a standard or policy, name it in the text. The AI chat edits text only, so it can reword a risk or a response while scores, tables and chart values are changed in the builder. The page on data tables in a document shows the table block, and the tutorial on document builder components covers the chart, table and stamp blocks.
| Column | Definition | Example entry |
|---|---|---|
| ID | A permanent reference that is never reused, even after a risk closes | R-02 |
| Risk | The event that might happen, in a few words | Glazing delivery slips |
| Cause | Why it might happen | Single supplier |
| Likelihood | A score from 1 to 5 against the written likelihood scale | 3, possible: could happen in any given month of the works |
| Consequence | A score from 1 to 5 against the written cost and time thresholds | 4, major: $150,000 to $500,000 or 1 to 2 months |
| Rating | Likelihood times consequence, placed in a band | 12, high |
| Owner | One role accountable for managing the risk | Procurement lead |
| Response | What is being done to reduce the likelihood or the consequence | Second supplier qualified, deposit paid on long lead units |
| Status | Open, treated, monitor or closed | Open |
| Movement | Previous rating, current rating and why it changed | R-03 asbestos: was 16, now 8, after a survey and a licensed removal contract |
| Review date | When the register was last reviewed and when it is next due | Reviewed 12 September 2026, next review 10 October 2026 |
A finished example
A risk register is a spreadsheet until someone has to read it out at a meeting, and then it needs a scale, a matrix, owners and a summary of what changed. This one defines its five point scales on page one, rates twelve risks in a table, charts the top five and lists the three that moved since last month.
Read the risk register template that works as a monthly meeting documentQuestions people ask
What is the difference between a risk and an issue?
A risk is something that might happen; an issue is something that has happened and needs dealing with now. When a risk occurs, record it as an issue with actions and dates, and close or rescore the risk. Keeping both in one list blurs priorities, because an issue always needs attention this week while most risks need watching.
Should I use a 5 by 5 or a 3 by 3 matrix?
A 5 by 5 matrix gives finer distinctions and suits larger projects or organisations with enough risks to separate. A 3 by 3 matrix is quicker to rate and honest for small projects, where the difference between a 3 and a 4 is guesswork. The example refurbishment register uses 5 by 5; the roof sheeting safe work method statement example uses 3 by 3.
How often should a risk register be reviewed?
Match the review to how fast the risks change. Active construction and system rollouts often review monthly, an operational register for a whole business quarterly. The example is reviewed at the monthly project meeting, with the next review date printed on every page. Whatever the cycle, extreme risks should never wait until the next scheduled review for action.
Who should own a risk?
One role that can actually act on it, not a committee and not the person who happened to raise it. The owner monitors the risk, carries out or chases the response, and reports changes. In the example, the glazing delay belongs to the procurement lead and the airside access risk to the security manager, because those roles control the response.
What is a residual rating?
The rating after the planned response has taken effect, as opposed to the inherent rating before any treatment. Some registers show both columns. The example records the effect through its movement table instead: the asbestos risk entered at 16 and sits at 8 after a survey, a licensed removal contract and a $180,000 allowance. Either approach works if it is applied consistently.
Can a risk register be kept in a spreadsheet?
Yes, and many are. A spreadsheet is good for sorting and filtering. The problem appears when the register has to be read at a meeting or sent to a sponsor, because a raw sheet has no scales, no matrix and no summary of what changed. A short document with the scales, the top risks and the movement section is easier to review.
Written by
Indunil Asanka · Co-founder
Builds the generation pipelines behind OneCraft: the slide, flyer and poster layout engines, the document grid and the render workers that turn a written brief into a finished file.
LinkedIn profileWritten and checked by the OneCraft team. Last checked .
Make your own document
Describe what you need and the generator writes and designs it, then you edit anything you like.
See what it can makeRead next
How to write a project status report
A project status report gives the sponsor one status word and the reason for it, then what was done, what comes next, where the money stands against forecast, the risks that moved, and the decisions only they can make. Put all of that on page one; everything after it is supporting detail for the people who need it.
How to write a project charter
A project charter authorises a project on a few pages: the problem and a measurable objective, what is in and out of scope, the deliverables, who is on the team and what each may decide, the budget cap, key milestones, the first risks and the sponsor's signature. It fixes the deal; the project plan that follows schedules the work.
How to write meeting minutes
Minutes are a record of decisions and actions, not a transcript. A good set can be read in two minutes by somebody who was not there, and tells them what was decided, who owns what, and by when.
For the steps inside the builder, read the guideon this topic.