This guide explains how to create an effective project risk log. It provides a practical method for defining the purpose, gathering reliable evidence, completing the work, checking the result and maintaining the output.

The aim is to produce something that supports a real decision or management action, not merely to complete a template. Agree the intended user, scope and completion criteria before collecting detail. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit.

Clarify the purpose and scope

Write one sentence that explains why the work is required and what should become possible when it is complete. Identify the organisation, project, product, market, team or reporting period covered, and record important exclusions. Define who will approve the result, who will maintain it and which decision, meeting or operational process will use it.

Gather reliable inputs

Collect evidence before drawing conclusions. Use authoritative and current information, record limitations and distinguish confirmed facts from estimates or opinions. Typical inputs include:

  • Approved project scope, plan and governance
  • Current status, meeting and change information
  • Named owners and escalation routes
  • Agreed rating, priority and status definitions
  • Relevant commercial and operational constraints

Create a light evidence trail for important figures and judgements. This makes review faster, reduces argument about versions and helps a future owner update the work without reconstructing the original reasoning.

Define the fields before collecting entries

Field How to use it
Risk ID Use a controlled definition and make the value reviewable.
Cause-event-effect statement Use a controlled definition and make the value reviewable.
Likelihood Use a controlled definition and make the value reviewable.
Impact Use a controlled definition and make the value reviewable.
Owner Use a controlled definition and make the value reviewable.
Response Use a controlled definition and make the value reviewable.
Residual rating Use a controlled definition and make the value reviewable.
Review date Use a controlled definition and make the value reviewable.

Apply the method

  1. Define scoring and escalation rules. Agree a precise definition before adding detail. Record the scope, thresholds, exclusions and completion criteria so every contributor applies the same interpretation. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Record the result before continuing so later decisions do not depend on memory.
  2. Write each risk as cause, uncertain event and effect. Use specific and testable language. Remove duplication, avoid vague labels and include enough context for someone who did not attend the original discussion. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Where contributors disagree, preserve the competing evidence and identify who will resolve the judgement.
  3. Score inherent exposure. Apply explicit criteria and a consistent baseline. Segment the evidence where averages could hide important differences, and show uncertainty instead of presenting false precision. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Use proportionate detail and include only information that changes a decision, action, rating or design.
  4. Assign one accountable owner. Name one accountable person with sufficient authority. Make the expected output, due date, decision rights and escalation route explicit. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Confirm that the result can support the next activity without creating hidden assumptions.
  5. Plan proportionate responses. Define the expected output, the accountable owner and the acceptance criteria. Use the evidence gathered earlier and record any judgement that a reviewer may need to challenge. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Link the result to affected owners, measures, milestones or controls where relevant.
  6. Review residual exposure and trends. Use an agreed review cadence and update the result whenever material evidence changes. Focus attention on exceptions, deteriorating trends, overdue commitments and decisions requiring escalation. Apply agreed thresholds, distinguish uncertainty from events that have already occurred, and make ownership, response and escalation explicit. Do not treat completion of the activity as proof that the intended outcome has been achieved.

Challenge the result

Review the draft with people who hold different perspectives. Ask what evidence could disprove the conclusion, which stakeholders remain unheard and which assumptions create the greatest uncertainty. Test whether another reviewer could reproduce the reasoning and whether the output still works under a credible adverse scenario. Show uncertainty honestly instead of disguising it through false precision.

Apply a five-part quality test: clarity, evidence, ownership, action and cadence. The result should state what it covers, show why each material judgement exists, name accountable owners, trigger clear next steps and define when it will be reviewed. Revise any element that fails before relying on the output.

A practical example

A supplier may miss a testing date because its manufacturing slot remains unconfirmed. The team records the cause, uncertain event and schedule effect, assigns the commercial lead, plans an alternative source and sets an escalation date.

Keep the example proportionate to the decision. Add detail only where it changes an assessment, priority or action. Excessive narrative can hide what leaders need, while insufficient context can make different teams interpret the same entry or conclusion differently.

Common mistakes to avoid

  • Using vague or duplicate entries
  • Leaving records without accountable owners
  • Changing dates or ratings without preserving history
  • Closing entries without evidence
  • Treating the log as a substitute for management action

Most failures occur when teams treat the output as a one-off document. Build review into an existing governance or management rhythm, update it when evidence changes and close actions only after the agreed completion test has been met.

Completion checklist

  • The scope, reader and decision are explicit
  • Evidence supports every material conclusion
  • One accountable owner can maintain the output
  • Facts, assumptions and recommendations are distinguishable
  • The next action, review date and success measure are visible

Once these checks pass, approve the output, communicate how it will be used and schedule the next review. Its value comes from the decisions, actions and behaviours it improves, not from the existence of the document, analysis or configuration itself.

Explore related guidance in risk and resilience.