
Construction projects face uncertainty in design, cost, time, quality, safety, procurement, and site conditions. A risk register turns general concerns into actions with owners, deadlines, and evidence of completion.
Identify risks systematically
Review scope, tender assumptions, drawings, methods, contract conditions, site constraints, stakeholders, and lessons from previous projects. Use cross-functional workshops to avoid a single-department view.
Describe cause, event, and impact
Write risks using a clear cause-event-impact structure. Avoid vague descriptions such as bad weather; identify the affected work, exposure period, and likely time or cost consequence.
Assess probability and impact
Use agreed scales for probability and impacts on cost, schedule, quality, safety, and reputation. Record inherent risk and residual risk after mitigation.
Select a response strategy
Responses may avoid, reduce, transfer, or accept risk. Each action requires an owner, due date, cost, trigger, and deliverable. Contingency does not replace mitigation.
Connect risk to cost and schedule
Major risks should influence contingency, float, procurement, methods, and design decisions. A risk without a link to the project plan remains an administrative entry.
Review regularly
Update the register in routine meetings, close risks with evidence, and add new risks when conditions change. Track opportunities that may save time or cost as well.
Minimum risk-register fields
| Field | Required content |
|---|---|
| ID and category | Unique code and cost, time, quality, HSE, contract, or stakeholder category |
| Risk statement | Cause, event, and impact |
| Assessment | Probability, impact, inherent and residual score |
| Response | Action, owner, cost, deadline, and trigger |
| Status | Open, monitoring, escalated, realised, or closed with evidence |
Contingency, triggers, and escalation
Link major risks to contingency, float, procurement, methods, and design decisions. Use minimum, most-likely, and maximum scenarios where exposure is material. Define triggers such as late approvals, price movement, low productivity, changed site conditions, or supplier failure, with clear escalation authority.
Supporting products
Strengthen project risk controls with the Anti-Stalled Project Package and QS Services Quantity Surveying & Cost Management.
Conclusion
An effective risk register supports decisions and action. Every major risk needs a precise description, active owner, measurable response, and direct connection to cost and schedule.
Professional implementation framework
A risk register converts uncertainty into measurable management action. A list containing generic descriptions without causes, impacts, owners, responses, cost, dates, and status cannot control a project.
Roles and accountability
The project manager sets the process and escalation threshold; the risk coordinator maintains the register; risk owners are accountable for responses; discipline leads identify technical exposure; planning and cost control quantify time and cost; procurement and contracts manage commercial risks; management approves contingency and major decisions.
Mandatory inputs and hold points
Use the contract, WBS, baseline, cost plan, design register, procurement schedule, interface register, site information, stakeholder map, assumptions, lessons learned, and change log. Write risks as cause-event-impact statements so responses address the source.
Every hold point must be recorded in the Inspection and Test Plan. Work must not proceed on verbal approval alone when the next activity will conceal or remove inspection evidence.
Control sequence
- Identify risks through cross-functional workshops and document reviews, separating risks, existing issues, assumptions, opportunities, and routine actions.
- Assess probability and impact with the approved matrix, including time, cost, quality, safety, and reputation where relevant.
- Assign risk and action owners, strategy, due date, mitigation cost, trigger, and residual rating.
- Integrate actions with the schedule, budget, procurement, design actions, and meeting actions so responses are executed.
- Review routinely, close by evidence, escalate above threshold, and use exposure trends to manage contingency.
Acceptance criteria
Each entry has an ID, category, cause, event, impact, initial score, owner, response, action, date, trigger, residual score, status, and review evidence. Critical risks include contingency and escalation.
Convert each criterion into a checklist item supported by a measurement, compliant/noncompliant status, location, date, document revision, inspector, and photograph. Terms such as good or adequate are not acceptable without a defined measure or reference.
Quality records and handover
Retain the controlled register, scoring matrix, workshop minutes, action log, mitigation evidence, contingency decisions, risk reports, links to changes or issues, and close-out notes.
Index records by area and date so they remain traceable during changes, claims, defects, and owner reviews. Incomplete documents become outstanding items with an owner and target closure date.
Risk and nonconformance
Process failures include subjective scoring, assigning every risk to the project manager, unfunded actions, stale registers, and recording current issues as risks. Use challenge reviews and sample audits of allegedly completed actions.
Do not conceal a finding with subsequent work. Identify the area, review the cause, approve corrective action, and reinspect. A repair is closed only when objective evidence confirms that the required function and quality have been restored.
Work close-out
At phase close, remove obsolete risks, transfer residual exposure to the receiving party, reconcile contingency, and document lessons for future estimates and projects.
