A risk register that nobody reads is just a spreadsheet with anxiety in it.
Most project risk management dies the same death. Someone builds a beautiful workbook with forty columns: risk ID, category, sub-category, probability score, impact score, risk owner, secondary owner, mitigation, contingency, residual probability, residual impact, review date, status, and a colour-coded heat cell that recalculates itself. It looks rigorous. It feels like control. And then three weeks into the project it has not been touched, because filling it in is a chore and reading it is worse. The risks that actually sink the project were never the ones in row 14. They were the ones nobody wanted to type out loud.
I want to make the case for the opposite approach. Lightweight, human, fast. Something you can do on a whiteboard or the back of a notebook, that fits in your head, and that you will actually keep doing. The whole discipline reduces to four verbs: spot, rate, respond, review. A small 3x3 grid beats a 40-column sheet, not because detail is bad, but because the detail you never maintain is worse than the simplicity you do.
Why the big register fails
The register optimises for the audit, not for the decision. A forty-column sheet is built to prove that risk management happened. It answers the question a governance board asks at the end: "did you have a process?" It is much worse at answering the question you actually face on a Tuesday: "what should I worry about this week, and what am I doing about it?" Those are different jobs. The first rewards completeness. The second rewards focus, and focus means leaving most things off the list.
Detail creates false confidence. When you assign a risk a probability of 0.35 and an impact of 7, you have produced a number that looks like knowledge. It is not. You guessed 0.35. You could just as honestly have written "maybe." Kahneman and Tversky spent careers showing how badly humans estimate probabilities, and how readily a precise-looking figure anchors us into believing we know more than we do. A 3x3 grid is honest about the resolution of your knowledge. Low, medium, high is roughly as accurate as you can be, so pretending to two decimal places just adds noise and steals time.
Maintenance cost is the silent killer. Every column is a small tax you pay on every update. Multiply forty columns by twenty risks by weekly reviews and you have built a part-time job nobody was hired for. So the reviews stop. The register goes stale. And a stale register is more dangerous than no register, because it gives everyone permission to stop thinking; the document, they assume, is handling it.
Spot: name the things that could go wrong
Risk management starts as a conversation, not a form. The most valuable fifteen minutes you can spend is getting the team in a room and asking one blunt question: what could stop us hitting this? Not "what are the project risks" in the abstract, which produces bland answers like "scope creep" and "resource constraints." Ask what specifically, on this project, keeps you up. The honest answers are concrete: "the client's legal team has never approved anything in under three weeks" or "only Marco knows how the billing integration works and he is on leave in July."
Cast wide, then cut. Brainstorm without filtering first; you want the quiet risks to surface, the ones people hesitate to say because they sound like criticism. Then be ruthless about what makes the list. If you cannot imagine it actually happening on this project, it does not belong. You are not trying to catalogue every conceivable misfortune. You are trying to name the handful that deserve attention. For most projects that is somewhere between five and ten live risks at any time. More than a dozen and you are not managing risks, you are collecting them.
A useful prompt is to walk the spine of the work and ask where it is thin:
- People: who is the single point of failure?
- Dependencies: what are we waiting on from someone we do not control?
- The unknown: where are we doing something for the first time?
- The assumption: what are we taking for granted that, if wrong, breaks the plan?
Rate: the 3x3 grid
Two questions, three levels each. How likely is it? How bad would it be? Low, medium, high on each axis. Plot the risk on a 3x3 grid and its position tells you almost everything you need to know about how much energy it deserves. The top-right corner, high-likelihood and high-impact, is where you live. The bottom-left, unlikely and minor, you note and forget. Everything else is judgement.
The grid forces a decision, which is the point. A position on the matrix is not a description, it is an instruction. Red corner means act now. Amber band means plan a response and keep an eye on it. Green corner means accept it and move on. You do not need a weighted score to tell you that the thing that is both likely and catastrophic deserves more of your time than the thing that is neither. The grid just makes that obvious to everyone looking at it, including the stakeholder who has never read a project document in their life.
Respond: four moves, then a card
There are only four things you can ever do with a risk. Avoid it (change the plan so it cannot happen), reduce it (lower the likelihood or the impact), transfer it (insurance, a contract clause, someone else's balance sheet), or accept it (decide it is cheap enough to simply live with). Every fancy mitigation strategy collapses into one of those four. Naming which one you are choosing is more than half the work, because it stops the vague "we'll keep an eye on it" non-response that protects nobody.
For the risks that matter, write a card. Not a row in a sheet, a card. Index-sized, one risk per card, and it says only what you would need in a hurry: what the early warning sign is, what you will do when you see it, and who owns the doing. That last part is non-negotiable. A risk without a named owner is a risk that belongs to everyone, which means it belongs to no one. Toyota's production system made this a habit on the factory floor; when something went wrong, it was always clear who pulled the cord and what happened next. You want the same clarity before anything goes wrong.
A good trigger is observable. "If the project starts going badly" is not a trigger. "If the sandbox integration is still failing on 25 May" is. The discipline of writing a trigger you could actually observe is what turns a worry into a plan. It also hands you the moment of permission to act, so you do not spend three weeks privately fretting before anyone admits out loud that the thing is happening.
Review: keep it alive
Risk is not a phase, it is a heartbeat. The single biggest difference between teams that manage risk and teams that file it is that the first group looks at the list again. Five minutes at the start of a weekly check-in. Run the cards: has any trigger fired? Has anything moved on the grid? Is there a new risk that was not there last week, and is there an old one we can finally close because the danger has passed? That last move matters as much as adding new ones. A list that only grows becomes wallpaper. A list that closes things feels alive, and people keep using it.
Total exposure should fall over time, and you can see it. Early in a project you are surrounded by unknowns, so exposure is high. As you make decisions, prove out the risky parts, and retire dependencies, the total should come down. If you plot it, you get a risk burndown, and a burndown that is flat or rising is telling you something real: you are not actually resolving uncertainty, you are just accumulating it. That picture is worth more than any single number in a register.
What you give up, and what you keep
You do give something up with the lightweight approach, and it is worth being honest about it. On a nuclear plant, an aircraft programme, or anything where a missed risk costs lives or hundreds of millions, the heavyweight register earns its keep, and the regulators will quite reasonably insist on it. Quantified models, Monte Carlo simulations, full residual-risk tracking: those tools exist for good reasons in the places that need them. Most of us are not building those things. We are running a marketing launch, a software release, a house renovation, a research project, and for those the elaborate machinery is a costume, not a safeguard.
What you keep is the thing that actually protects you: attention. Risk management has never really been about the document. It is about a team that has looked uncertainty in the eye, named it plainly, decided who does what when it shows up, and agreed to check again next week. A 3x3 grid and a handful of cards do that. A forty-column spreadsheet mostly performs that, and performance is exactly what fails you on the day a real risk walks through the door.
So if you hate spreadsheets, good news: the spreadsheet was never the point. Spot the handful of things that could genuinely go wrong. Rate them on a grid small enough to hold in your head. Respond by choosing one of four moves and naming an owner. Review it weekly, and close things as they pass. Four verbs, a small grid, a few cards. Keep it light enough that you will actually keep doing it, because the only risk process that works is the one you do not abandon.