Project Controls in the AI EraRisk management, Monte Carlo and change control · Lesson 13 of 22

Risk registers that drive action

Article · 13 min · 9 min lecture

Video lecture

Risk registers that drive action

10 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 10

'Weather' is not a risk

  • Cause, event, effect
  • Assess, respond, own, monitor
  • Link risk to cost, schedule and contingency

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Risk in one sentence

A risk is an uncertain event or condition that, if it occurs, affects at least one objective. Threats have negative effects; opportunities have positive ones. Risk management is about making uncertainty visible early enough to act.

A clear risk statement

Use cause–event–effect wording so the risk can be managed:

Because the grid operator's approval process is new (cause), there is a risk that connection approval is delayed beyond month 6 (event), which would delay energisation and revenue by up to 2 months and add standby costs (effect).

"Weather" or "Permits" are not risks; they are topics.

The risk process

  1. Identify through workshops, lessons learned, assumptions review, checklists and interviews.
  2. Assess probability and impact (qualitatively first).
  3. Plan responses and assign owners.
  4. Implement responses and track them as actions.
  5. Monitor each period: new risks, closed risks, trends, triggers.

Qualitative assessment: probability–impact matrix

Probability \ ImpactVery lowLowMediumHighVery high
Very highMHHVHVH
HighLMHHVH
MediumLMMHH
LowVLLMMH
Very lowVLVLLLM

Define scales in concrete terms for your project (e.g., "High impact = cost > $250k or delay > 4 weeks") so scoring is consistent.

Response strategies

For threatsFor opportunities
Avoid – change the plan to eliminate itExploit – make sure it happens
Transfer – shift impact (insurance, contract)Share – partner with someone better placed
Mitigate – reduce probability or impactEnhance – increase probability or impact
Accept – actively (contingency) or passivelyAccept
Escalate – outside the project's authorityEscalate

Risk register template

ID | Cause–event–effect | Owner | P (1–5) | I cost | I time | Score | Response type | Actions (owner/date) | Trigger | Residual P/I | Status
R-07 | Because ... there is a risk that ... which would ... | Grid lead | 4 | $180k | 8 wks | H | Mitigate | Early submission pack (JA, 15-Apr); weekly follow-up | No response by day 30 | 2 / $180k / 8 wks | Open

Worked example

Illustrative. A fictional logistics park developer near Riyadh identified 64 risks in a workshop. The register became a document nobody read. The controls lead introduced three rules: every risk must be written as cause–event–effect; every high risk must have at least one action with a date; the steering committee sees only the top ten by score plus any new or escalated risks. Within two months, the number of actions completed per period tripled and two major risks (utility capacity and a customs clearance delay) were closed early through mitigation.

Linking risk to cost and schedule

A risk register becomes a controls tool when each significant risk is:

  • linked to the WBS/control account it affects;
  • given a cost and/or schedule impact range (min, most likely, max);
  • linked to contingency (so drawdowns reference risk IDs);
  • mapped to specific schedule activities for quantitative analysis.

Common mistakes

  • Topics instead of risk statements.
  • Registers updated once at the start and then ignored.
  • No owners, or owners without authority.
  • Only threats; opportunities never considered.
  • Scoring that everyone interprets differently.
  • Confusing issues (already happening) with risks (may happen).

AI assistance

Language models can suggest risks from similar past projects, detect duplicate entries, rewrite vague entries into cause–event–effect format and flag stale risks with no updates. Human owners must validate every suggestion; an AI-generated risk list is a prompt for discussion, not a finished register.

Keeping the register alive

Review the top risks at every project meeting, not just in a quarterly workshop. Ask owners three questions: has probability or impact changed, have planned actions been completed, and has any trigger fired? Close risks that have passed and add new ones as the project moves into new phases, since the risks of commissioning are very different from those of design.

Hands-on: a self-scoring risk register in Excel

Put your impact scale on a sheet called Scales (thresholds ascending, score 1–5) and look up both impacts:

Columns: A ID | B Cause–event–effect | C Owner | D P (1–5) | E Cost impact | F Time impact (weeks)
G Cost score   =XLOOKUP(E2, Scales!$A$2:$A$6, Scales!$B$2:$B$6, , -1)   (next smaller threshold)
H Time score   =XLOOKUP(F2, Scales!$C$2:$C$6, Scales!$D$2:$D$6, , -1)
I Score        =D2*MAX(G2:H2)
J Rating       =IFS(I2>=15,"VH",I2>=10,"H",I2>=5,"M",TRUE,"L")
K Last updated | L Days stale =TODAY()-K2 | M Stale? =IF(AND(N2="Open",L2>30),"STALE","")
N Status | O Action (owner/date) | P Linked WBS | Q Linked activity | R Min | S ML | T Max
Data validation: B must contain "Because" and "risk that" (custom rule: =AND(ISNUMBER(SEARCH("because",B2)),ISNUMBER(SEARCH("risk that",B2))))

(XLOOKUP is available in Microsoft 365 Excel; use LOOKUP or INDEX/MATCH in older versions.)

Prompt template: rewriting vague entries (approved AI tool only)

Rewrite each risk entry below as: "Because <cause>, there is a risk that <event>, which would <effect on cost/time/quality>."
Rules: do not invent facts; where cause or effect is unknown, write [TO CONFIRM]; suggest one trigger and one
mitigation action per risk; mark each suggestion "for owner validation".
Entries:
1. Permits – western section
2. Supplier delay – switchgear

How to measure success

  • Share of open risks written as cause–event–effect (target 100%).
  • Actions completed on time each period, and number of stale risks (target falling).
  • Share of significant risks linked to a WBS element, an impact range and a schedule activity.

Key takeaways

  • Write risks as cause–event–effect so they can be managed.
  • Use defined probability and impact scales for consistent scoring.
  • Every significant risk needs an owner, response actions, triggers and links to WBS, contingency and schedule.
  • Consider opportunities as well as threats, and separate issues from risks.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which is a well-formed risk statement?
  2. Buying insurance against a construction accident is an example of which threat response?
  3. A problem is already occurring and affecting cost. How should it be handled?
  4. What makes a risk register useful for controls rather than a compliance document?

Put it into practice

Rewrite five vague risks from a project you know (e.g., 'weather', 'permits') into cause–event–effect statements with an owner and one action each.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.