07 · Project and strategy M&E
Risk registers and risk monitoring
A risk register is the visible residue of a risk management process; kept without the process, it is a spreadsheet of anxieties. The register earns its place when each entry states a cause, an event and a consequence, carries a named owner and a live treatment, and is wired to early-warning indicators the monitoring system already collects.
Last updated · Reviewed against 4 cited sources
A process, not a spreadsheet
Most projects have a risk register because a template demanded one. It was filled at proposal stage, scored in an afternoon, and has been photocopied forward through every quarterly report since. This artefact satisfies audits and protects nobody.
The corrective is to start from the process the register is supposed to record. The international reference here is ISO 31000, which frames risk management as an organisational discipline built on principles, a supporting framework, and a continuing process — establishing scope and context, assessing risks, treating them, and monitoring, reviewing and communicating throughout — rather than a one-off registration exercise [1]. Project-level risk management is likewise established practice within the delivery profession’s own standard of record [3]. For working detail this page leans on the UK Government’s Orange Book, which has the advantage of being open text: it defines risk in terms of the effect of uncertainty on objectives, and builds its guidance around main principles — risk management should be integrated into the organisation’s activities and decision-making, collaborative and informed by the best available information, structured through defined processes, and continually improved — with risk appetite as the calibrating concept running through all of them [2].
Two consequences of the definition are worth stating plainly, because both are routinely lost:
- Risk is defined against objectives. A project without clearly stated objectives cannot assess risk, because there is nothing for uncertainty to threaten. The register inherits its structure from what the project is trying to achieve — which is why delivery risks and results risks belong in the same register, threatening different levels of the same objective chain.
- Uncertainty cuts both ways. The framing includes opportunity as well as threat. In practice, registers that attempt to track opportunities and threats in one grid usually do neither well; the pragmatic norm is a threat register with opportunity noted where treatment choices create it.
Register anatomy: the risk statement carries everything
The unit of the register is the risk statement, and the grammar that makes a statement workable has three parts:
Because of <cause — a present, verifiable condition>, <event — the uncertain thing that may occur> may occur, leading to <consequence — the effect on objectives>.
Each part does a job. The cause is what treatment acts on — you cannot mitigate an event directly, only the conditions that make it likely. The event is what monitoring watches for. The consequence is what makes prioritisation possible, because it names the objective at stake.
| Weak statement | What is wrong | Repaired statement |
|---|---|---|
| Budget risk | A category, not a risk — no cause, event or consequence | Because construction is priced in foreign currency while the grant is fixed in local currency, exchange depreciation may raise works costs beyond budget, leading to descoping of two sites |
| Community may not participate | Event only — untreatable without a cause | Because sensitisation was cut from the inception phase, target households may decline enrolment, leading to under-achievement of the coverage target |
| Staff turnover | A fact of life, not an uncertain event | Because M&E officer pay lags the local market, both field data roles may fall vacant in the same quarter, leading to a broken outcome-survey round |
Around the statement, the register row carries: a unique ID; the owner — one named person with authority to act, never a unit; the current treatment (avoid, reduce, transfer, accept) and the specific actions in flight; the scores before and after treatment; the review date; and the linked early-warning indicator where one exists. A row missing an owner or a review date is not yet a register entry — it is a worry with a number.
Scoring: useful triage, dubious arithmetic
The standard scoring device is the likelihood × impact matrix — typically five ordinal bands on each axis, with the product or the cell position setting priority. It is worth using and worth distrusting in equal measure.
Use it because triage is real: a portfolio of forty risks needs an honest answer to “which five do we actively manage”, and a shared scoring frame with written band definitions (what counts as “likely”; what impact threshold means “severe”) makes that conversation disciplined rather than loudest-voice-wins.
Distrust it because the numbers are ordinal labels, not quantities. A likelihood of “4” is not twice a “2”; multiplying the ranks produces a number with the appearance of measurement and none of its properties, and matrices can rank a frequent-moderate risk above a rare-catastrophic one that any sane portfolio view would prioritise. The pragmatic mitigations: define bands in real units (probability ranges, money, weeks of delay) so scorers anchor on the same meanings; score consequence against the objective named in the statement, not general dread; treat matrix position as an agenda-sorter, never as an input to further calculation; and take genuinely quantifiable exposures — cost and schedule risk on major works above all — out of the matrix and into quantitative risk analysis, where established cost-estimating practice puts them [4].
Risk appetite is what makes any score actionable. A score of 16 means nothing until the organisation has said what level of risk it is prepared to carry in pursuit of which objectives — the Orange Book’s central governance idea [2]. Appetite statements convert the heat map’s colours into decisions: above this line, escalate; in this band, treat actively; below it, accept and watch. Without them, every risk committee meeting re-litigates thresholds from scratch.
Key risk indicators: where the register meets M&E
Here is the genuine interface between risk management and monitoring, and it is chronically under-built. Most registers are monitored by recollection: once a quarter, someone asks the room whether the risks have changed. A key risk indicator (KRI) replaces recollection with data — a measurable quantity, tracked routinely, whose movement signals that a risk’s likelihood is shifting before the event occurs.
The construction rule follows directly from the risk-statement grammar: the KRI measures the cause, not the event. For the exchange-rate risk above, the KRI is the monthly exchange rate against a written trigger value. For the enrolment risk, it is weekly registration counts against the phased target. For the staffing risk, it is vacancies and time-to-fill from the HR system. When the trigger trips, the register’s escalation path fires — the owner acts, before the consequence, not after it.
Three practical points:
- Reuse the monitoring system. Most KRIs are already collected — enrolment counts, stock levels, budget burn, reporting completeness. Wiring them to the register is a routing exercise, not a new data collection burden, and it is exactly the kind of connection an M&E information system should carry.
- Every high-priority risk should have either a KRI or a written statement of why none is feasible. The residue — risks watchable only by judgement — is where review meetings should spend their scarce attention.
- KRIs are indicators, and everything the indicator-design cluster says about definitions, data sources and quality applies to them; the quality-criteria page’s tests transfer directly.
One adjacent artefact needs a boundary line: the assumptions column that results frameworks carry expresses related logic — conditions outside programme control on which the results chain depends — but it lives in framework territory that this site leaves to its sibling; see the logframe explainer at monival.com. The working relationship is simple: a monitored assumption that starts failing usually deserves promotion to the risk register, where it acquires an owner and a treatment.
Cadence, escalation, and retiring risks
A register is alive when three rhythms run:
- Review cadence by priority, not by calendar convenience. Top-band risks reviewed at every project meeting; middle band monthly or quarterly; watch-list semi-annually. Each review updates score, treatment status and KRI reading — and the review date stamps the row, so staleness is visible.
- Escalation with thresholds. Risks that breach appetite move up a governance level — from project to portfolio to board — with the appetite statement, not persuasion, deciding when [2]. De-escalation is equally explicit when treatment brings exposure back inside appetite.
- Retirement with a record. Risks whose window has passed, or whose cause has been eliminated, are closed with a dated note — never silently deleted. The closed section of the register is the project’s risk memory, and the input to the lessons process the learning-and-adaptive-management page covers.
The anti-pattern all of this defends against is the stale register: the same fifteen risks, the same scores, photocopied through eight quarterly reports. A stale register is worse than none, because it manufactures assurance — governance bodies see a risk artefact and reasonably conclude the process behind it is running. If the register cannot be kept alive, the honest move is to shrink it until it can be: five risks with owners, treatments, KRIs and real review dates outperform forty rows of legacy anxiety.
Checklist for a register that changes decisions
- Every entry states cause, event and consequence; every entry has one named owner and a review date.
- Scoring bands are defined in real units, and a written risk appetite converts scores into escalation thresholds.
- Matrix scores are used for triage only; major cost and schedule exposures get quantitative analysis instead of ordinal arithmetic.
- Each top-band risk carries a KRI wired to routine monitoring, with a written trigger — or a note on why none is feasible.
- Review cadence is tiered by priority; risks are retired with dated records, never deleted.
- The register is one shared artefact across delivery and results — and the date of its last substantive edit is somebody’s business.
Sources
- ISO 31000:2018 — Risk Management: Guidelines — International Organization for Standardization, 2018.The international reference standard for risk management principles and process. Paywalled; cited for its existence and high-level structure only.
- The Orange Book: Management of Risk — Principles and Concepts — HM Treasury and Government Finance Function, United Kingdom, 2023.The open, freely available public-sector risk framework this page leans on for its working detail: principles, appetite, and governance.
- A Guide to the Project Management Body of Knowledge (PMBOK® Guide) — Seventh Edition and The Standard for Project Management — Project Management Institute, 2021.The delivery profession's standard, within which project risk management sits as established practice. Paywalled; cited for existence and structure only.
- Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO-20-195G) — U.S. Government Accountability Office, 2020.Treats risk and uncertainty analysis as part of credible cost estimating — the quantitative end of the risk discipline.