Every enterprise programme has a risk register. Very few of them are useful. The register exists, it gets updated before steering committees, and it sits in a SharePoint folder that most of the programme team has never opened. The risks on it are generic, the ratings are optimistic, and the mitigations are vague enough to mean nothing.

I've reviewed risk registers on programmes worth hundreds of millions of pounds and dirhams where the top-rated risk was something like "resource availability may be impacted by competing priorities." That's not a risk. That's a sentence. It tells you nothing about what could actually go wrong, how likely it is, or what anyone is doing about it.

A risk register that doesn't change decisions isn't a risk management tool. It's a compliance document dressed up as one.

What Makes a Risk Register Useless

The failure modes in risk management are consistent across industries and programme types.

Risks are described too vaguely to act on. "Dependency on third-party delivery" is not a risk. "Vendor X has not confirmed the API specification required for integration milestone 3, which is due in six weeks" is a risk. The difference is specificity. Vague risks produce vague mitigations and no accountability.

Every risk is rated medium. Risk ratings should reflect genuine assessment of probability and impact. When everything is medium, it means nobody has done the assessment honestly, or nobody wants to be the person who flagged a high-rated risk. Both are governance failures.

Mitigations are not actions. "Monitor closely" is not a mitigation. A mitigation is a specific action, owned by a named individual, with a deadline. If the mitigation on your risk register doesn't have those three elements, it won't get done.

The register is updated for the meeting, not between meetings. Risk management is a continuous discipline, not a fortnightly reporting exercise. Risks that emerge between steering committees should be captured and acted on immediately.

The Association for Project Management's research consistently identifies poor risk management as a leading contributor to programme failure. The gap between having a risk register and actively managing risk is where most programmes fall short.

How to Fix Your Risk Register Without Starting From Scratch

Risk Register ElementBad ExampleGood Example
Risk description"Resource constraints may impact delivery""Key integration architect leaves before milestone 4, no backup resource identified"
ProbabilityMediumHigh (contractor contract ends in 8 weeks)
ImpactMediumHigh (milestone 4 delayed by minimum 6 weeks)
Mitigation"Monitor and escalate if needed""Identify backup resource by 14 November, owned by the delivery director"
Review dateNext steering committeeFortnightly

Rewrite the top ten risks in plain language. Take the ten highest-rated risks on your current register and rewrite each one so that someone who joined the programme today could read it and understand exactly what could go wrong, why, and what's being done about it.

Force a rating distribution. If your register has fifteen risks and twelve of them are medium, something is wrong. A realistic risk register for an enterprise programme should have a mix of high, medium, and low ratings. Run a facilitated risk workshop where ratings are challenged and justified.

Assign a named owner to every risk. Not the programme team. Not the PMO. A named individual who is accountable for monitoring the risk and implementing the mitigation. That person's name on the register changes the dynamic entirely.

Make risk a standing agenda item, not a reporting item. The steering committee should spend time on the top three to five risks at every meeting: not reading through the register, but actively discussing what's changed, whether mitigations are working, and whether any risks have escalated.

The risk register is only as useful as the conversations it generates. If your steering committee isn't making decisions based on the risks in front of them, the register isn't doing its job. If your programme's risk management is producing paperwork rather than decisions, our team can restructure your approach and introduce the disciplines that make risk management genuinely useful. Book a 30-minute discovery call.

Speak to us

Is your risk register changing any decisions?

Describe the programme and the concern. We will give a direct view on whether we are the right team for the engagement.