Most risk register examples show you an empty table and a list of column headers. That is helpful for about five minutes, and then you are back to the same question: what does a register look like when it is actually being used?
This article shows a worked register for a plausible project, an office relocation, with ten risks scored, mitigated, and tracked. The scenario is deliberately ordinary: no mega-programme, no defence contract, just a mid-sized team moving premises on a deadline. If you can manage risk well on a project like this, you can manage it on anything.
The Scenario
A 60-person professional services firm is moving from one leased office to another in the same city. The lease on the current premises expires on 31 March. The project has a budget of £180,000 covering fit-out, IT migration, furniture and removal costs. The project manager has four months and a small internal team. Disruption to client work is the board's primary concern.
The Register
Each risk has an identifier, a title, a category, a type (threat or opportunity), probability and impact scores from 1 to 5, the resulting P×I score, a response strategy, and a status. This is the register as it stands at the mid-point of the project, so some risks have been mitigated and others are still open.
| ID | Title | Category | Type | P | I | P×I | Strategy | Status |
|---|---|---|---|---|---|---|---|---|
| R-001 | Fit-out contractor overruns deadline | Schedule | Threat | 3 | 5 | 15 | Reduce | Escalated |
| R-002 | Server room not ready for IT migration | IT | Threat | 3 | 4 | 12 | Reduce | Open |
| R-003 | Staff resist hot-desking layout | People | Threat | 4 | 3 | 12 | Reduce | Open |
| R-004 | Lease break clause triggered early | Financial | Threat | 2 | 5 | 10 | Transfer | Mitigated |
| R-005 | Key supplier goes into administration | Supply Chain | Threat | 1 | 4 | 4 | Contingency | Open |
| R-006 | Client data exposed during server move | IT | Threat | 2 | 5 | 10 | Avoid | Mitigated |
| R-007 | New premises fail fire safety inspection | Compliance | Threat | 2 | 4 | 8 | Reduce | Open |
| R-008 | Moving weekend coincides with client deadline | Schedule | Threat | 3 | 4 | 12 | Reduce | Open |
| R-009 | Negotiate lower rent on extended lease term | Financial | Opportunity | 3 | 3 | 9 | Enhance | Open |
| R-010 | Faster broadband at new site cuts VPN costs | IT | Opportunity | 4 | 2 | 8 | Exploit | Open |
That is the overview. Three things to notice before we walk through the detail.
- R-001 has escalated. Its P×I of 15 crossed the threshold and the programme manager has been notified automatically.
- R-004 and R-006 are already mitigated. Their response actions are complete and the residual score has been accepted.
- R-009 and R-010 are opportunities, not threats. The response strategies (enhance, exploit) reflect that the project manager is actively trying to make these happen, not prevent them.
R-001: Fit-Out Contractor Overruns Deadline
- Description
- The fit-out contractor has a track record of overrunning on comparable jobs. If the fit-out is not complete by 15 March, the IT migration cannot begin and the lease expiry becomes a hard constraint with no fallback.
- Category
- Schedule
- Type
- Threat
- Probability
- 3 — the contractor's record shows overruns on two of the last four jobs, but the scope here is smaller.
- Impact
- 5 — without a completed fit-out the move cannot happen, and the current lease cannot be extended.
- P×I
- 15 — above the escalation threshold of 15. This risk has been escalated to the programme manager.
- Response strategy
- Reduce
The mitigation plan has three response actions.
| Action | Owner | Due | Weight | Status |
|---|---|---|---|---|
| Agree liquidated damages clause in contract | Project Manager | 15 Nov | 20% | Complete |
| Weekly progress inspection with photo evidence | Facilities Lead | Ongoing | 50% | In progress |
| Identify backup contractor and get indicative quote | Project Manager | 30 Nov | 30% | Complete |
Two of the three actions are complete, but the weekly inspection — carrying half the mitigation weight — is ongoing. The residual risk forecast sits at P2 × I4 = 8, down from 15, but it will not reach that level until the inspections confirm the contractor is on track. The risk stays escalated until the residual score drops below the threshold.
R-006: Client Data Exposed During Server Move
- Description
- Physical servers containing client data will be transported between premises. If a server is lost, damaged, or accessed during transit, the firm faces a data breach with regulatory and reputational consequences.
- Category
- IT
- Type
- Threat
- Probability
- 2 — the move is a single journey across the city with a specialist logistics firm, but the data is sensitive enough that even a low probability demands action.
- Impact
- 5 — regulatory penalty, client notification, potential contract termination.
- P×I
- 10
- Response strategy
- Avoid — eliminate the risk event entirely rather than reducing it.
The mitigation plan has two response actions, both complete.
| Action | Owner | Due | Weight | Status |
|---|---|---|---|---|
| Migrate all client data to cloud hosting before the move | IT Manager | 28 Feb | 80% | Complete |
| Wipe and decommission physical servers before transit | IT Manager | 07 Mar | 20% | Complete |
By migrating to the cloud before the move, the project manager avoided the risk entirely. There is no client data on the physical servers during transit, so the risk event cannot occur. The residual score is P1 × I1 = 1, and the risk has been accepted and closed.
This is the difference between reduce and avoid. Reduce lowers the probability or the impact. Avoid removes the conditions that make the risk possible in the first place. The response strategy field on each risk makes this distinction explicit.
R-009: Negotiate Lower Rent on Extended Lease Term
- Description
- The new landlord has indicated willingness to negotiate a reduced rate in exchange for a five-year commitment rather than the standard three. If the firm commits, the saving over the term could be significant.
- Category
- Financial
- Type
- Opportunity
- Probability
- 3 — the landlord has signalled interest but no terms have been drafted.
- Impact
- 3 — meaningful saving but not transformational.
- P×I
- 9
- Response strategy
- Enhance — increase the probability of the opportunity materialising.
The response action is for the finance director to prepare a proposal with comparable market rates and present it before the lease is signed. The action is open, due 20 December, and carries 100% of the mitigation weight because it is the only lever.
Opportunities are often left out of risk registers entirely, or filed as threats with awkward wording. A register that separates threats from opportunities and gives each its own response vocabulary (enhance, exploit, share, reject for opportunities; reduce, avoid, transfer, accept, contingency for threats) produces clearer plans and better decisions.
What Makes This Register Work
Five things separate a register that drives decisions from one that gathers dust.
- Consistent scoring
- Every risk is scored on the same 1 to 5 scales, with written definitions of what each number means. A 3 on one risk means the same thing as a 3 on another.
- Explicit response strategies
- Each risk names its strategy (reduce, avoid, transfer, accept, contingency, or the opportunity equivalents). This forces the project manager to decide how they are dealing with the risk, not just that they are aware of it.
- Weighted mitigation actions
- Each action carries a percentage weight showing how much of the risk reduction it is expected to deliver. This makes progress measurable: 60% of actions complete with 70% of the weight means the risk is genuinely moving, not just busy.
- Residual risk tracking
- Every risk has a forecast residual score showing what the exposure will be after the mitigation plan is fully implemented. This is the number the programme manager watches, not the raw score.
- Automatic escalation
- When P×I crosses the threshold, the right person is notified without the project manager having to chase. R-001 escalated automatically at 15.
From Example to Working Register
This example uses the same structure that KinetiRisk builds for every project. The probability times impact scoring, the response strategies, the weighted mitigations and the automatic escalation are all part of the product rather than something you configure from scratch.
If you are starting from an existing spreadsheet, you can import it as a CSV and KinetiRisk maps the columns automatically. If you are starting from scratch, the AI proposes scores with its reasoning so you are not staring at a blank cell deciding whether something is a 3 or a 4. Either way, the register you end up with looks like the one above, not like the empty template you started from. We wrote separately about how to build a register your team actually uses.
Build a register like this one in minutes. KinetiRisk scores risks, drafts mitigation plans, and escalates automatically, on a free plan that never expires.
Start free See how it worksThe Free plan gives you one project, 25 AI analyses a month, the full analysis including mitigation planning and reasoning, automatic escalation alerts, review reminders and the hierarchical category tree. No card, no time limit.
Frequently Asked Questions
What should a risk register include?
At a minimum: a unique identifier, a title, a description, probability and impact scores, a risk owner, a response strategy and a status. A working register also tracks mitigation actions with owners and due dates, the residual risk score after mitigation, and an escalation threshold that triggers automatically when a risk becomes critical.
How many risks should a project risk register have?
There is no fixed number. A small project might have 8 to 15 risks; a complex programme could have over 100. The important thing is that every risk is genuinely relevant to the project and scored consistently. A register with 10 well-described, properly scored risks is more useful than one with 50 vague entries.
What is the difference between a risk register and a RAID log?
A RAID log tracks risks, assumptions, issues and dependencies together in one place. A risk register focuses on risks alone, with deeper detail: probability and impact scoring, response strategies, mitigation actions and residual risk tracking. Most project managers who outgrow a RAID log move to a dedicated risk register.
Should opportunities go in a risk register?
Yes. An opportunity is a risk with a positive impact. It should be scored the same way, with its own response strategy: exploit, enhance, share or reject rather than the threat equivalents. Keeping opportunities in the same register ensures they get the same rigour as threats.
How often should a risk register be updated?
At least once a week on an active project. Scores, owners and mitigations change as the project progresses. A register that is updated monthly is a historical record, not a management tool. Setting review reminders on individual risks or a cadence for the whole project prevents the register from going stale.
A risk register is only as good as the decisions it drives. If yours is a spreadsheet that nobody opens between meetings, it is not the register that needs improving, it is the tool. The example above shows what a register looks like when it is genuinely in use: scored consistently, mitigated with clear actions, escalated when it matters, and tracked through to closure.