Risk and Resilience

A Risk Register Is Not a Risk Management System

Why documenting project risks is insufficient, and how leaders create active ownership, triggers, responses and practical portfolio-level resilience.

EraNorth Insights · 8 min read

Risk is managed when exposure changes through decisions and action, not when uncertainty is recorded in a spreadsheet.

Many projects can produce an impressive risk register. Risks are described, scored, colour-coded and assigned to owners. The document is reviewed monthly and presented as evidence of mature governance. Yet the same risks continue to age, response actions remain unfunded and warning signals are noticed only after the risks become issues.

The organisation has a record of uncertainty, but not a functioning risk-management system.

The Strategic Context

Projects and programs exist to change the organisation. They introduce uncertainty into capital commitments, operations, customers, technology, suppliers and stakeholder relationships. Risk management should help leaders make those choices with informed exposure, not merely reduce the number of surprises.

Risk includes threats and opportunities. Avoiding every threat can make the portfolio strategically timid; pursuing every opportunity can concentrate exposure beyond organisational capacity. The executive objective is to take the right risks deliberately and maintain the ability to respond as evidence changes.

A register is useful because it creates a common record. Its value depends on the system around it: appetite, ownership, triggers, responses, funding, escalation, review and learning.

What Leaders Commonly Misread

The first misreading is that identification equals management. Naming a risk does not change its probability or consequence.

The second is treating a risk score as an objective fact. Probability and impact assessments often depend on judgement, incomplete information and ordinal categories. Multiplying scores can assist prioritisation, but it does not create mathematical precision.

The third is assigning ownership without authority. A named owner who cannot obtain resources, change a plan or escalate a decision is a custodian of information, not a manager of exposure.

The fourth is equating a declining number of risks with improving control. Risks may be combined, closed prematurely or converted into issues. A smaller register can conceal rising exposure.

Reframing the Issue

Risk management should be reframed as an active control loop:

Understand objectives → identify uncertainty → assess exposure → choose a response → fund and implement action → monitor triggers → reassess residual risk → learn

The loop matters because risk changes. Design matures, suppliers perform, markets move and assumptions fail. A quarterly register refresh cannot govern an exposure whose trigger may emerge tomorrow.

Risk appetite and tolerance provide the decision boundary. Appetite expresses the type and amount of risk the organisation is prepared to pursue or retain in seeking value. Tolerance establishes the variation or exposure beyond which escalation or action is required. Without these boundaries, risk scores generate discussion but not decisions.

Risk Descriptions Must Support Action

A useful risk description connects cause, uncertain event and consequence. This avoids statements that are merely issues, impacts or vague concerns.

For example: because a critical supplier has not demonstrated stable process capability, there is a possibility that production components will fail acceptance, causing rework, delayed commissioning and loss of operational capacity.

This structure reveals possible controls. Leaders can investigate supplier capability, qualify an alternative, change inspection, adjust inventory, redesign the component or accept the exposure. “Supplier risk: high” offers little guidance.

Risk breakdown structures can help identify patterns across commercial, technical, schedule, operational and external domains. Their purpose is not exhaustive classification. It is to prevent attention from clustering around the most familiar risks.

Responses Need Resources and Triggers

A response is not complete because an action appears in the register. It requires:

  • A responsible owner with authority.
  • Resources and schedule allowance.
  • A defined trigger or review point.
  • Expected reduction in probability or consequence.
  • Residual and secondary risks.
  • A contingency or fallback where appropriate.

Threat responses may avoid, reduce, transfer or accept exposure. Opportunity responses may exploit, enhance, share or accept potential upside. These labels are less important than the economic logic.

Every response consumes something: capital, time, flexibility, attention or potential benefit. Leaders should compare the expected reduction in exposure with the cost and consequences of the control.

Related article: Change Control Is Capital Allocation in Disguise

Risks Become Issues, but Governance Must Continue

A risk is an uncertain event or condition. An issue is present and requires resolution. The conversion should trigger a change in governance: assessment of immediate impact, decision options, accountable action and escalation where thresholds are exceeded.

Organisations often maintain separate risk and issue logs but fail to preserve the relationship. When a risk occurs, leaders should examine whether the response was implemented, the trigger was missed, the assessment was wrong or the event was outside the identified model. Each answer creates different learning.

Issue management should not close the risk automatically. The event may create residual or secondary exposure that persists after the immediate problem is addressed.

Portfolio Risk Is More Than the Sum of Project Risks

Individual project registers rarely reveal concentration. Several initiatives may rely on the same supplier, technology, regulatory decision, specialist workforce or operational transition window. Each project may assess the dependency as tolerable while the portfolio exposure is unacceptable.

Portfolio leaders should aggregate by common cause and constraint, not merely by risk score. They should also examine correlations: a market disruption, cyber event or policy change may affect multiple investments simultaneously.

Related article: The Hidden Portfolio Cost of Multitasking

Decision Framework

For each material risk, governing bodies should test:

TestExecutive question
ObjectiveWhich outcome is exposed?
CauseWhat condition creates the uncertainty?
ConsequenceWhat value, obligation or capability could be affected?
ResponseWhat action changes the exposure, and at what cost?
AuthorityCan the owner make or obtain the required decision?
TriggerWhat signal requires action or escalation?
Residual exposureWhat remains after the response, and who accepts it?

At portfolio level, add two questions: where are risks concentrated, and which response in one initiative changes exposure elsewhere?

Risk escalation should be based on authority and consequence, not fear. Teams should retain manageable delivery risks while escalating matters that exceed tolerance, cross organisational boundaries or require trade-offs outside their mandate.

From Strategy to Execution

Immediately, review the highest exposures for active, funded responses and decision-capable owners. Remove vague descriptions and identify specific triggers.

Over the medium term, connect risk actions to schedules, budgets and work packages. Review cycles should reflect how quickly the exposure can change. Portfolio reporting should group risks by shared causes, dependencies and constrained resources.

Long-term capability requires feedback from realised risks and successful opportunities. The organisation should test whether assessments, triggers and responses were useful, then modify standards and decision thresholds. ISO 31000:2018 remains a published reference at the time of drafting, although a revision is under development; its status should be checked again before publication.

Signals to Monitor

Leaders should intervene when:

  • High-rated risks have no funded response.
  • Owners cannot explain the next action or escalation threshold.
  • Scores change but the underlying exposure does not.
  • Risks remain unchanged across many reporting cycles.
  • Issues appear without reference to previously identified triggers.
  • Multiple projects depend on the same unrecognised constraint.
  • Contingency is used without reassessing residual exposure.

Questions for the Leadership Team

  1. Which risks are we deliberately taking to create value?
  2. Which owners lack the authority or resources to manage their assigned exposure?
  3. What trigger would cause us to change direction rather than continue monitoring?
  4. Where does the portfolio concentrate risk around one supplier, technology or capability?
  5. Are controls reducing exposure or merely producing documentation?
  6. Who has explicitly accepted the material residual risks?

Closing Perspective

A risk register is evidence that uncertainty has been considered. It is not evidence that exposure is controlled. Active risk governance connects objectives, authority, resources, triggers and decisions in a continuous loop. Leaders should judge the system by whether it changes behaviour before events become urgent, not by how complete the spreadsheet appears.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.