Project Controls in the AI EraRisk management, Monte Carlo and change control · Lesson 13 of 22
Risk registers that drive action
Video lecture
Risk registers that drive action
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 'Weather' is not a risk
Open almost any risk register and you'll find entries like these. Weather. Permits. Resources. Supply chain. They look like risks. They're not. They're topics. You can't assign an owner to 'weather', you can't estimate its impact, and you can't tell when it's been dealt with. In this lecture you'll learn to write risks that can actually be managed, using a cause, event and effect structure, to assess them consistently, to choose the right response strategy for threats and opportunities, and to link each significant risk to the cost, schedule and contingency it affects. By the end you'll be able to turn a list of vague worries into a register that drives action every week, rather than a document that gets updated once and forgotten.
0:54 Why it matters
Why does this matter? Because risk management is about making uncertainty visible early enough to do something about it. A risk you spot in design costs a conversation. The same risk spotted on site costs rework, delay and often a dispute. But a register only helps if it drives action. The ones that work are linked: each significant risk points at the control account and schedule activities it affects, has a cost and time impact range, and connects to contingency. The ones that fail are lists produced in a workshop at the start, then updated once a quarter because someone asks. Here's a simple test: when did a risk entry last cause somebody to do something differently?
1:45 The concept: a clear risk statement
Here's the structure. Because, then the cause. There is a risk that, then the uncertain event. Which would, then the effect on your objectives. For example: because the grid operator's approval process is new, there is a risk that connection approval is delayed beyond month six, which would delay energisation and revenue by up to two months and add standby costs. Now you know what to watch, who might own it, what to do about it and roughly how much it matters. Think of it like a doctor's diagnosis. 'You feel unwell' is a topic. 'Because of this, there's a risk of that, which would cause these symptoms' is a diagnosis you can treat. And remember, risks can be positive too. An opportunity is an uncertain event that would help your objectives.
2:42 Assess and respond
Next, assess. Most teams start with a probability and impact matrix, and that's fine, if the scales are defined in concrete terms. High impact might mean more than two hundred and fifty thousand or more than four weeks' delay. Without definitions, one person's 'high' is another's 'medium' and the scores mean nothing. Then plan a response. For threats: avoid, by changing the plan. Transfer, through insurance or contract. Mitigate, by reducing probability or impact. Accept, actively with contingency or passively. Or escalate, if it's outside the project's authority. For opportunities, the mirror images: exploit, share, enhance, accept or escalate. Every high risk gets an owner with enough authority, and at least one action with a date.
3:32 Worked example one: rewriting vague risks
Let's rewrite one. The register says 'Permits'. I ask: which permit, and what's uncertain about it? The answer: the road-closure permit for the western section. The council has a new online process, and nobody on the team has used it yet. So: because the council's road-closure process is new to the team, there is a risk that the permit for the western section is not granted before week twelve, which would delay the drainage works by up to three weeks and push the critical path. Owner: planning lead. Trigger: no acknowledgement within thirty days of submission. Action: a pre-application meeting with the council by the fifteenth of April. In two minutes, a word has become something you can manage.
4:24 Worked example two: a Riyadh logistics park
Now the realistic scenario. A fictional logistics park developer near Riyadh identified sixty-four risks in a workshop. The register became a document nobody read. The controls lead introduced three rules. One: every risk must be written as cause, event, effect. Two: every high risk must have at least one action with a date. Three: the steering committee sees only the top ten by score, plus anything new or escalated. That's it. Within two months, the number of risk actions completed each period had tripled, and two major risks, utility capacity and a customs clearance delay, were closed early through mitigation. Nothing clever. Just a register designed for decisions rather than for completeness.
5:13 Watch me do it: a register that scores itself
Let me show you the register I'd build in a spreadsheet, and the same logic works in SharePoint lists, Jira or a dedicated risk tool. Columns for ID, the cause-event-effect statement, owner, probability from one to five, cost impact and time impact. Impact scores come from lookups against the defined scales, so nobody debates what 'high' means. The score is probability times the higher of the two impact scores, and a rating column converts that into low, medium, high or very high. Then two columns I find invaluable: last updated date, and days since update. Anything open and not touched in thirty days turns amber. Finally, a filtered view: top ten by score, plus anything new or escalated. That's the page the steering committee sees.
6:07 Link risk to cost and schedule
A risk register becomes a controls tool when each significant risk is linked. Linked to the WBS or control account it affects. Given a cost and schedule impact range, with a minimum, most likely and maximum, not a single guess. Linked to contingency, so every drawdown references a risk ID. And mapped to specific schedule activities, so it can feed quantitative analysis in the next lesson. That's what lets you answer questions like: do we have enough contingency left for the risks that remain? Which risks threaten the handover date? And that's also what lets any AI or analytics tool do something useful with your register, because the links give it structure.
6:56 Common mistakes and AI
The common mistakes. Topics instead of risk statements. Registers updated once at the start and then ignored. No owners, or owners without the authority to act. Only threats, with opportunities never considered. Scoring that everyone interprets differently. And confusing issues, which are already happening, with risks, which might happen. Now AI. Language models are genuinely good at suggesting risks from similar past projects, detecting duplicates, rewriting vague entries into cause, event and effect, and flagging stale risks. Use them. But an AI-generated risk list is a prompt for discussion, not a finished register. The human owner validates every suggestion, because only people who know the project can judge whether a risk is real.
7:45 Recap and try this now
Let's recap. A risk is an uncertain event that would affect your objectives, written as cause, event and effect. Assess it with scales defined in concrete terms. Choose a response: for threats, avoid, transfer, mitigate, accept or escalate, and for opportunities, exploit, share, enhance, accept or escalate. Give every significant risk an owner with authority and a dated action, and link it to the WBS, an impact range, contingency and the schedule. Keep it alive by reviewing the top risks at every project meeting, asking whether probability or impact has changed, whether actions are done and whether any trigger has fired. Your try-this-now: take five vague risks from a project you know, such as weather or permits, and rewrite them as cause, event and effect statements, each with an owner and one action.
Risk in one sentence
A risk is an uncertain event or condition that, if it occurs, affects at least one objective. Threats have negative effects; opportunities have positive ones. Risk management is about making uncertainty visible early enough to act.
A clear risk statement
Use cause–event–effect wording so the risk can be managed:
Because the grid operator's approval process is new (cause), there is a risk that connection approval is delayed beyond month 6 (event), which would delay energisation and revenue by up to 2 months and add standby costs (effect).
"Weather" or "Permits" are not risks; they are topics.
The risk process
- Identify through workshops, lessons learned, assumptions review, checklists and interviews.
- Assess probability and impact (qualitatively first).
- Plan responses and assign owners.
- Implement responses and track them as actions.
- Monitor each period: new risks, closed risks, trends, triggers.
Qualitative assessment: probability–impact matrix
| Probability \ Impact | Very low | Low | Medium | High | Very high |
|---|---|---|---|---|---|
| Very high | M | H | H | VH | VH |
| High | L | M | H | H | VH |
| Medium | L | M | M | H | H |
| Low | VL | L | M | M | H |
| Very low | VL | VL | L | L | M |
Define scales in concrete terms for your project (e.g., "High impact = cost > $250k or delay > 4 weeks") so scoring is consistent.
Response strategies
| For threats | For opportunities |
|---|---|
| Avoid – change the plan to eliminate it | Exploit – make sure it happens |
| Transfer – shift impact (insurance, contract) | Share – partner with someone better placed |
| Mitigate – reduce probability or impact | Enhance – increase probability or impact |
| Accept – actively (contingency) or passively | Accept |
| Escalate – outside the project's authority | Escalate |
Risk register template
ID | Cause–event–effect | Owner | P (1–5) | I cost | I time | Score | Response type | Actions (owner/date) | Trigger | Residual P/I | Status
R-07 | Because ... there is a risk that ... which would ... | Grid lead | 4 | $180k | 8 wks | H | Mitigate | Early submission pack (JA, 15-Apr); weekly follow-up | No response by day 30 | 2 / $180k / 8 wks | OpenWorked example
Illustrative. A fictional logistics park developer near Riyadh identified 64 risks in a workshop. The register became a document nobody read. The controls lead introduced three rules: every risk must be written as cause–event–effect; every high risk must have at least one action with a date; the steering committee sees only the top ten by score plus any new or escalated risks. Within two months, the number of actions completed per period tripled and two major risks (utility capacity and a customs clearance delay) were closed early through mitigation.
Linking risk to cost and schedule
A risk register becomes a controls tool when each significant risk is:
- linked to the WBS/control account it affects;
- given a cost and/or schedule impact range (min, most likely, max);
- linked to contingency (so drawdowns reference risk IDs);
- mapped to specific schedule activities for quantitative analysis.
Common mistakes
- Topics instead of risk statements.
- Registers updated once at the start and then ignored.
- No owners, or owners without authority.
- Only threats; opportunities never considered.
- Scoring that everyone interprets differently.
- Confusing issues (already happening) with risks (may happen).
AI assistance
Language models can suggest risks from similar past projects, detect duplicate entries, rewrite vague entries into cause–event–effect format and flag stale risks with no updates. Human owners must validate every suggestion; an AI-generated risk list is a prompt for discussion, not a finished register.
Keeping the register alive
Review the top risks at every project meeting, not just in a quarterly workshop. Ask owners three questions: has probability or impact changed, have planned actions been completed, and has any trigger fired? Close risks that have passed and add new ones as the project moves into new phases, since the risks of commissioning are very different from those of design.
Hands-on: a self-scoring risk register in Excel
Put your impact scale on a sheet called Scales (thresholds ascending, score 1–5) and look up both impacts:
Columns: A ID | B Cause–event–effect | C Owner | D P (1–5) | E Cost impact | F Time impact (weeks)
G Cost score =XLOOKUP(E2, Scales!$A$2:$A$6, Scales!$B$2:$B$6, , -1) (next smaller threshold)
H Time score =XLOOKUP(F2, Scales!$C$2:$C$6, Scales!$D$2:$D$6, , -1)
I Score =D2*MAX(G2:H2)
J Rating =IFS(I2>=15,"VH",I2>=10,"H",I2>=5,"M",TRUE,"L")
K Last updated | L Days stale =TODAY()-K2 | M Stale? =IF(AND(N2="Open",L2>30),"STALE","")
N Status | O Action (owner/date) | P Linked WBS | Q Linked activity | R Min | S ML | T Max
Data validation: B must contain "Because" and "risk that" (custom rule: =AND(ISNUMBER(SEARCH("because",B2)),ISNUMBER(SEARCH("risk that",B2))))(XLOOKUP is available in Microsoft 365 Excel; use LOOKUP or INDEX/MATCH in older versions.)
Prompt template: rewriting vague entries (approved AI tool only)
Rewrite each risk entry below as: "Because <cause>, there is a risk that <event>, which would <effect on cost/time/quality>."
Rules: do not invent facts; where cause or effect is unknown, write [TO CONFIRM]; suggest one trigger and one
mitigation action per risk; mark each suggestion "for owner validation".
Entries:
1. Permits – western section
2. Supplier delay – switchgearHow to measure success
- Share of open risks written as cause–event–effect (target 100%).
- Actions completed on time each period, and number of stale risks (target falling).
- Share of significant risks linked to a WBS element, an impact range and a schedule activity.
Key takeaways
- Write risks as cause–event–effect so they can be managed.
- Use defined probability and impact scales for consistent scoring.
- Every significant risk needs an owner, response actions, triggers and links to WBS, contingency and schedule.
- Consider opportunities as well as threats, and separate issues from risks.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Rewrite five vague risks from a project you know (e.g., 'weather', 'permits') into cause–event–effect statements with an owner and one action each.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.