Building a Risk Register That Actually Gets Used
Most risk registers die in month two. Here is the format, cadence and ownership model that keeps risk live on a construction job.
Project names, parties and commercially sensitive figures referenced in this article have been anonymised or generalised. Examples reflect real situations encountered across multiple projects; they are not attributed to any specific client, contractor or contract.

A risk register is not a deliverable for the client. It is a working tool for the project leadership team, and if it is not opened weekly it is dead. Most registers I audit have not been touched since the kick-off workshop. They sit on the project shared drive, full of generic risks copy-pasted from a template, doing nothing.
Three principles keep a register alive on a construction job. Every risk has a single named owner — not a discipline, a person. Every risk has a trigger condition that tells you when to escalate. And every risk has a dollar and a day attached to it, even if the number is rough. Without those three, the register is a wishlist of fears, not a management tool.
Format matters less than people think. A spreadsheet with twelve columns works. The columns I use are: risk ID, category, description, owner, trigger, probability (1–5), impact (1–5), score, rating, response strategy, status, last reviewed. Anything more becomes admin; anything less hides the response.
Score probability and impact on a 1–5 scale and visualise it as a heat map. The point of the heat map is not precision; it is to force the team to argue about which risks belong in the red zone. Those arguments are where mitigation strategies are actually built. A heat map that everyone agrees on without debate is a heat map nobody is taking seriously.
Response strategy follows the standard four — avoid, transfer, mitigate, accept — but the discipline is to commit to a specific action with a specific owner and date. 'Mitigate' is not a strategy; 'pre-order steel sub-frame and hold on site by 30 March, owned by Procurement Lead' is a strategy. The register tracks the action, not the intention.
Cadence is non-negotiable. Review the top ten risks at every weekly project meeting. Move them, close them, add new ones. A register that does not change is a register no one reads. Once a month run a deeper review with the leadership team and add quantified contingency to the cost forecast based on the open risk exposure.
Where most registers fail is in the link to the schedule and the cost forecast. A risk that delays the critical path by 14 days should appear as a 14-day contingency in the schedule. A risk that costs $200k if it materialises, at 40% probability, should appear as $80k in the contingency reserve. If the register and the forecast are not connected, the forecast is fiction.
Close risks aggressively. The register loses credibility fastest when it accumulates stale entries that the team has worked around. A risk that has not materialised by its trigger date should be re-scored or closed; a risk whose mitigation has been completed should be closed and the lessons captured. A clean, current register of fifteen live risks is worth more than a bloated register of eighty.
Construction project manager (PMP, MCIOB) with 20+ years on infrastructure, commercial and industrial builds across the GCC and NZ. Writes about the controls, contracts and field practices that actually move projects.
Read full bio →