Unit 5 / 11

Risk Management and Risk Registration

Gains:

  • Ability to understand the concepts of risk, probability, impact, risk score and response strategy (avoidance, mitigation, transfer, acceptance) and produce a draft risk record with the support of artificial intelligence
  • Ability to use artificial intelligence for risk identification, classification, trigger identification and mitigation action drafting and keeping the risk record alive
  • Understanding that the probability and impact values produced by artificial intelligence require expert calibration, and that risk ownership and the final decision belong to humans.

The future is uncertain in every project; Uncertainty means risk. A risk is an uncertain event or condition that, if realized, will affect the project's objectives (time, cost, scope, quality). Risks can be negative (threat) or positive (opportunity), but in everyday language we mostly mean threats. What separates a good project manager from a mediocre one is often risk management: seeing problems before they arise, reducing their likelihood, and planning ahead for what to do when they happen. At the heart of this unit is the risk register: a living document where all risks, their likelihood, impacts, owners and response plans are kept. AI is very helpful in risk identification and draft scoring; But probability and impact estimates require agency-specific judgment, and risk ownership always remains human.

Anatomy of the risk register

A risk log line typically includes: risk description (in cause-event-effect format: “if supplier is late, integration fails to start, delivery slips”), category (technical, resource, external, financial, legal), probability (chance of occurrence; e.g. 1-5 or %), impact (magnitude of loss if occurrence; 1-5), risk score (probability × impact), trigger (early sign that risk is approaching), response strategy, risk owner (person tasked with monitoring that risk), and status.

Risk score = probability × impact is a simple but powerful prioritization tool. A risk with a probability of 4 and an impact of 5 (score 20) deserves much more attention than a risk with a probability of 2 and an impact of 2 (score 4). Risks are placed in red/yellow/green zones on a risk matrix (probability-impact grid) based on this score.

There are four basic response strategies (for threats):

  • Avoidance: Completely changing/removing the job that creates the risk.
  • Mitigate: Reducing the likelihood or impact (e.g. finding a replacement supplier).
  • Transfer: Transferring the risk to someone else (insurance, contract clause, subcontractor).
  • Accept: To take the risk; but allocate a contingency plan and budget/time allocation.

area

example

Who fills it?

Risk definition

"If the key developer leaves, development slows down."

PM + team

Probability (1-5)

3

expert judgment

Effect (1-5)

4

expert judgment

score

12

Account (AI helps)

trigger

"Coming to work decline, interview rumor"

risk taker

Reply

Mitigation: information sharing, backup person

PM + has

Owner

team leader

sends PM

Step by step: Risk logging with AI

  1. Risk brainstorming. Give the AI ​​the anonymous project context and have it generate possible risks category by category. AI is good at reminding us of risks that humans would jump at.
  2. Put it in cause-event-effect format. Put each risk in the format “because of X, if Y happens, there will be impact Z”; Ambiguous risks cannot be managed.
  3. Draft scoring. Ask the AI ​​for probability/impact plots, but calibrate them with expert judgment. The AI's number is a starting point, not reality.
  4. Identify the trigger. For every significant risk, “how do we know it's coming?” Answer the question.
  5. Response plan draft. Ask the AI ​​to suggest the appropriate 4 strategies and concrete action for each high-scoring risk.
  6. Assign an owner and keep it alive. Give every risk an owner; Review the risk register weekly. The risk register is a living document, not written once and forgotten.
Tip: Summarize the risk log into “top 5 risks” and include it in each status report. This way, risks remain visible and surprises are reduced.

three mini cases

Case 1 — Missed risk caught. A PMO specialist handed the completed 18-line risk register to AI and asked, "What typical risks might I have missed?" he asked. AI; It reminded 5 risks such as "third party license renewal", "data migration loss risk" and "key personnel dependency". The expert added 3 of them. Two months later, the licensing risk occurred, but the plan was ready.

Case 2 — Calibration difference. One PM questioned the "probability of 2" value the AI ​​gave to a risk. Delays were common in the team's history with this supplier; the actual probability was closer to 4. The score increased from 6 to 12, and the risk moved from the "to watch" list to the "active precaution" list. Lesson: AI's probability prediction should be corrected by agency data.

Case 3 — Unclaimed risk. A team identified the risks well but failed to take ownership. A risk occurred, no one was watching, the trigger escaped and the project was 3 weeks late. Lesson: risk without owner is risk without monitoring; AI produces risks, but the human owner assigns them.

Weak prompt / Strong prompt

Weak prompt:

List the risks for my project.

Without context, without categories and without format; A general list appears, most of which are unrelated to your project.

Powerful prompt:

Your role: a risk management specialist.Context: [anonymous project summary: industry, duration, team, technology, constraints].Task: Generate risk by category (technical, resource, external/supplier, financial, legal, scope).For each risk:- Description in cause-event-effect format- Probability (1-5) and impact (1-5) DRAFT value + short justification- Early trigger sign- Recommended response strategy (avoid/mitigate/transfer/accept) and 1 concrete actionNote: Probability/impact values are DRAFT; I will calibrate it with institutional data. Don't give fake numbers, write your reasons. Output: table.

This prompt is powerful: it includes category, format, draft scoring warning, and calibration note.

Additional templates:

# Blind spot finderSee my risk log below. Remind me, category by category, of the risks that are COMMON in such projects but are NOT on my list. Don't repeat existing ones.

# Trigger generatorSuggest 3 early warning signs (triggers) for risk: [risk]. For each sign, also write down with which data/indicator I can track it.

# Response plan deepenerEvaluate all four strategies for this high-scoring risk (avoid/mitigate/transfer/accept); compare the cost and impact of each, explaining which one you recommend and why. Remember that the final decision is mine.

Common mistakes

  • Writing vague risk: “Risk of delay” cannot be managed; "integration slips if supplier X is delayed" is manageable.
  • Mistaking the AI ​​score for real: Likelihood/impact is institution specific; It should not be used without calibration.
  • Not assigning an owner: Unowned risk is not monitored.
  • Not identifying a trigger: Without early signs, the risk will catch you off guard.
  • Freezing the risk register: The project changes, the risks change; If the record is not updated it dies.
  • Just looking at threats: Opportunities (work completed early, resources becoming cheaper) can also be managed.
Caution: AI may label a risk as “low probability”; But if that risk occurs frequently in your organization, AI's generalization will mislead you. Always test scores against your own historical data.

In summary

Risk management is the art of seeing problems before they explode, and the risk register is the living document at the heart of this. Each risk is identified in a cause-event-effect format, scored by probability and impact, its trigger and response strategy (avoid/mitigate/transfer/accept) are determined, and it is assigned an owner. AI is powerful at risk brainstorming and draft scoring; It reminds you of blind spots. However, expert calibration of probability/impact values, risk ownership and final response decision always rest with the human.

Application task

Generate a draft category-by-category risk register from AI for your project (anonymize context). Choose the 5 highest scoring risks; Calibrate the probability/impact value of each with your own historical data, write a trigger and response action, and assign an owner. Then check the risks you missed with the "blind spot finder" template.

checklist

  • [ ] I wrote the risks in cause-event-effect format.
  • [ ] I calibrated the probability/impact values ​​with my institution yield.
  • [ ] I prioritized risks by score (risk matrix).
  • [ ] I have identified triggers and response strategies for each significant risk.
  • [ ] I assigned an owner to each risk.
  • [ ] I planned to keep the risk log live and add it to the status report.