ProjectBalm
All resources
Guide

Using a Risk Register in Your Organization

A practical introduction to project risk management—and how a well-maintained risk register helps you deliver with greater confidence.

If you have ever managed a project, you know all about risks. They are the questions that keep you awake at night: What if the vendor delivers late? What if quality is lower than expected? What if the estimates are wrong?

When a risk is realized, deadlines get missed, schedules get blown, or something else goes badly wrong. The project suffers—and so can your professional reputation.

It does not have to be this way. Studies show that risk management techniques lead to better project outcomes. You can take back control and deliver to time, budget, scope, and quality. But project risk management is hard—and that is where we can help.

Understanding risk

Project risk management is a staple process in many organizations and an increasingly important component of regulatory compliance. Experience shows, however, that the concept is still not always well understood.

A useful definition

Risk is uncertainty that matters.

Every project—especially in a competitive business environment—deals with uncertainty. But not all uncertainties matter. We are usually concerned with uncertainties that may result in monetary loss, capability delays, overspend, injury, share-price reduction, reputational damage, and similar consequences.

This aligns with the Project Management Body of Knowledge (PMBOK), which defines project risk as an uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives.

Why you must manage risk

Because risk is everywhere, it can be tempting to ignore it. That approach can be dangerous: risks may present a severe threat to your project and your business.

66%average software project budget overrun
33%average software project schedule overrun
17%of projects may threaten the organization’s existence

A large McKinsey study found that the average software project exceeded its budget by 66%, overran its schedule by 33%, and delivered a 17% shortfall in benefits. The average nonsoftware project underdelivered benefits by an extraordinary 133%.

Except in the case of sabotage, an unwelcome deviation from the project plan—cost, schedule, or benefits—is necessarily due to uncertainty. In other words, it results from risks being realized, whether they were identified ahead of time or not.

A realized project risk can reduce profitability, damage reputation, lower share price, and even destroy a company. Few organizations can afford to ignore them.

The risk management process

Formal processes such as PMBOK and PRINCE2 differ in detail, but they are broadly compatible with the ISO 31000 risk management standard and follow the same best-practice cycle.

01

Identify

Identify the risks relevant to your project through brainstorms, workshops, checklists, interviews, and surveys. Involve people with subject-matter expertise and record each risk in your project risk register.

02

Assess

Assess each risk using probability and impact. Multiplying the two—numerically or with a matrix—produces the risk exposure, also known as the level of risk.

03

Respond

Choose a response that is appropriate, achievable, and affordable. You may avoid, accept, mitigate, or transfer a risk, then create an action plan to carry out that response.

04

Monitor

Make risk management part of ongoing project governance. Add new risks, update assessments as information changes, track response plans, and report risk status regularly.

Risk management is not a one-time activity. A weekly project meeting might allocate time to review the register, add new risks, change assessments as information emerges, track response plans, and prepare required reporting.

The risk management plan

Most project governance standards require a risk management plan. Its purpose is to describe how risk will be managed on the project.

Introduction

Describe the purpose of the plan, give an overview of its contents, and include document identification, history, and approval information.

Project objectives

Document the project’s functional scope, duration, cost, and quality objectives.

Risk scope

Define what is included in the risk process and identify any objectives or types of risk that are excluded.

Risk process

Describe the process, tools, and resources you will use, including any tailoring required for this project.

Roles and responsibilities

Clarify who prepares and approves the plan, runs workshops, develops responses, maintains the register, reports status, and oversees adherence.

Probability and impact

Define the assessment scales for the project, including any project-specific thresholds such as dollar ranges for cost impact.

Risk categorization

Set out how risks will be grouped—for example technical, management, organizational, commercial, or external.

Typical responsibilities include preparing and approving the plan, organizing workshops, developing response plans, maintaining the register, reporting status, and ensuring the agreed process is followed.

Categories can also follow a work breakdown structure, cost breakdown structure, or organization breakdown structure—whatever makes the risks easier to understand and manage.

The risk register

A risk register is at the heart of the risk management process. It is a record of the risks identified for a project, organization, or product, used to help identify, analyze, and manage those risks.

Maintaining a risk register is a common regulatory requirement and is often necessary for compliance with project and organizational governance standards. Exact configurations vary, but most registers include these elements:

IdentifierA unique code used to refer to the risk.
DescriptionAn explanation of the risk, including its trigger and consequences.
ProbabilityA qualitative or quantitative estimate of likelihood.
ImpactAn estimate of the consequences if the risk is triggered.
Risk levelThe risk rating or score, calculated from probability and impact.
AuthorThe person who raised the risk.
OwnerThe person responsible for managing the risk.
TreatmentThe strategy selected for dealing with the risk.
Residual riskThe level of risk remaining after treatment is applied.
A ProjectBalm risk register showing risks, owners, status, probability, impact, and risk level
A structured risk register keeps ownership, assessment, and treatment visible in one place.

The risk matrix

A risk matrix models risk outcomes using color gradients in a tabular structure. It normally has two dimensions—probability and impact—with the intersection showing the level of risk.

During assessment, the matrix helps teams determine the level of each risk quickly. During monitoring, risk counts or identifiers can be mapped onto the model to provide a simple view of the project’s overall exposure.

ProjectBalm dashboard featuring a color-coded risk matrix and project risk charts
A risk matrix makes overall exposure easier to understand and communicate.

Introducing Risk Register by ProjectBalm

If this sounds like a lot of work, you are not alone. Risk Register automates best-practice risk management techniques through an elegant interface that works within Jira.

It helps teams identify, analyze, treat, and monitor risks more easily and effectively. Experienced practitioners get a tool that supports the way they want to work, while newcomers can follow world-class documentation through the complete process using simple examples.

Risk Register is compatible with standards such as ISO 31000 and can support governance, risk, and compliance programs including Sarbanes-Oxley and PCI.

A great solution at a great price

Many organizations are implementing tools to automate risk management, and many vendors charge steep rates. By leveraging Jira’s infrastructure, ProjectBalm delivers a fully featured product at a fraction of the price of major competitors—with transparent pricing and no mandatory consultation before you can see the software.

Risk Register by ProjectBalm

Take the sting out of risk management.

Bring best-practice risk management into Jira and give your team a clearer view of every project risk.

Try it now