What risk governance must protect
A control system for uncertainty, not a list of worries.
The Business Case justifies the investment. The PID controls delivery. Risk governance protects the continuing viability of both by making uncertainty visible, owned and subject to decision.
Viability
Which approved assumptions could uncertainty invalidate?Exposure
What is the risk before and after the planned response?Accountability
Who owns the exposure and who delivers each action?Tolerance
At what point must the risk leave project-level control?Evidence
Can reviewers trace how exposure and decisions changed?The Risk Management Strategy defines the rules: appetite, scoring, ownership, reporting and escalation. The Risk Register applies those rules to individual exposures and records how responses and decisions change over time.
Inherent risk shows the exposure before action. Residual risk shows what remains after the planned response. A completed action does not prove that the remaining exposure is within tolerance.
Copyable Risk Management Strategy template
Define the rules before scoring the risks.
Copy this structure into Word or your organisation's approved template. Replace every prompt with project-specific evidence, remove drafting guidance and align the scoring model with the organisation's risk framework.
Document details
[Insert title]
[Insert organisation]
[Insert name and role]
[Insert name and role]
[Insert version and date]
[Insert decision or meeting reference]
[Insert routine review frequency]
[Insert date or stage boundary]
Document control and approval
| Version | Date | Author | Change made | Approved by |
|---|---|---|---|---|
| [Version] | [Date] | [Name] | [Describe the change] | [Approver] |
1. Purpose and scope
Connect uncertainty to the approved investment.
Define why structured risk management is required, which decisions and assumptions it protects, and where responsibility begins and ends.
[Explain how risk governance protects Business Case assumptions, delivery tolerances, strategic objectives and benefit realisation.]
[Define the lifecycle stages, organisational units, suppliers, workstreams and operational interfaces covered.]
[Explain how project risks connect with programme, portfolio, corporate and operational risk frameworks.]
[State the routine reviews and events that require the strategy to be reconsidered.]
Risk governance principles
[Define the expected behaviours. These may include early identification, honest disclosure, proportionate response, clear accountability, mandatory escalation and continuous lifecycle management.]
[State the practices that would weaken control, such as suppressing high risks, vague ownership, delayed escalation or closing risks without evidence.]
Purpose and governance scrutiny questions
- Is the link to Business Case viability explicit?
- Are the lifecycle and organisational boundaries clear?
- Are project, programme, portfolio and operational interfaces defined?
- Does the strategy cover threats and opportunities?
- Are the principles specific enough to influence behaviour and decisions?
- Would the team know what must be escalated and why?
2. Risk identification
Surface uncertainty throughout the lifecycle.
Risk identification must continue through planning, procurement, change, transition and benefits realisation. Do not treat the initiation workshop as the complete risk process.
[State the workshops, assumptions analysis, dependency reviews, lessons, market engagement and other techniques to be used.]
[State when structured reviews occur and who is responsible for convening them.]
[Define the categories used for consistent analysis, such as strategic, commercial, financial, operational, technical, regulatory, reputational and benefits.]
[Explain how cost savings, accelerated benefits, performance improvements and strategic advantages will be identified.]
Required risk description structure
[Because of a specific condition, dependency or uncertainty...]
[There is a possibility that a defined event may occur...]
[Which would affect cost, time, scope, quality, benefits, reputation or strategic viability in a measurable way.]
Risk identification scrutiny questions
- Is identification continuous rather than limited to workshops?
- Are Business Case assumptions used as a source of risk?
- Are strategic, commercial, financial, operational and benefits risks covered?
- Are opportunities identified deliberately?
- Are risks written as cause, event and impact rather than vague concerns?
- Are current issues kept out of the risk population?
3. Risk assessment and scoring
Make exposure comparable.
Define a scoring system that separates raw exposure from the exposure remaining after response. Ambiguous scales produce false precision and inconsistent decisions.
Probability scale
| Score | Definition | Indicative probability |
|---|---|---|
| 1 | [Insert organisation-approved definition] | [Insert percentage range if used] |
| 2 | [Insert organisation-approved definition] | [Insert percentage range if used] |
| 3 | [Insert organisation-approved definition] | [Insert percentage range if used] |
| 4 | [Insert organisation-approved definition] | [Insert percentage range if used] |
| 5 | [Insert organisation-approved definition] | [Insert percentage range if used] |
Impact criteria
| Score | Cost | Time | Scope or quality | Benefits or reputation |
|---|---|---|---|---|
| 1 | [Threshold] | [Threshold] | [Threshold] | [Threshold] |
| 2 | [Threshold] | [Threshold] | [Threshold] | [Threshold] |
| 3 | [Threshold] | [Threshold] | [Threshold] | [Threshold] |
| 4 | [Threshold] | [Threshold] | [Threshold] | [Threshold] |
| 5 | [Threshold] | [Threshold] | [Threshold] | [Threshold] |
[State how probability and impact produce the overall rating, and how multiple impact dimensions are treated.]
[Define low, medium, high and critical bands and the required governance response for each.]
[State when exposure is scored before any planned response.]
[State when and how exposure is rescored after response planning or implementation.]
Assessment and scoring scrutiny questions
- Are probability and impact scales defined unambiguously?
- Would two independent reviewers score the same risk consistently?
- Are inherent and residual exposure recorded separately?
- Is proximity considered where timing affects the response?
- Are materiality thresholds explicit?
- Does the rating method support meaningful comparison and aggregation?
4. Response and ownership
Convert awareness into controlled action.
Recording a risk does not manage it. Select a deliberate response, assign accountability at the right level and define actions capable of changing exposure.
Response strategies
| Risk type | Available strategies | Selection basis |
|---|---|---|
| Threat | Avoid, reduce, transfer, share or accept | [Compare response cost, feasibility and reduction in exposure] |
| Opportunity | Exploit, enhance, share or accept | [Compare required action with the additional value available] |
[Name the individual accountable for monitoring and managing the exposure. Confirm that their authority matches the potential impact.]
[Name the individual responsible for implementing each response action.]
[State how response costs are authorised, budgeted and controlled.]
[State how new uncertainty created by the response will be identified and assessed.]
Response and ownership scrutiny questions
- Has an explicit response strategy been selected for every material risk?
- Are actions specific, funded, time-bound and proportionate?
- Is contractual transfer supported by the actual commercial arrangement?
- Is residual exposure recalculated rather than assumed?
- Is the risk owner accountable for exposure, not merely administration?
- Does the action owner have the capacity to deliver the response?
5. Appetite, tolerance and escalation
Define the boundary of delegated control.
Risk appetite describes the uncertainty the organisation is prepared to accept. Tolerance converts that position into measurable boundaries. When residual exposure exceeds those boundaries, escalation is mandatory.
Risk appetite and tolerance framework
| Dimension | Appetite statement | Tolerance threshold | Early warning | Escalation authority |
|---|---|---|---|---|
| Cost | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
| Time | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
| Scope | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
| Quality | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
| Benefits | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
| Reputation or compliance | [Accepted uncertainty] | [Measurable threshold] | [Approaching tolerance trigger] | [Named role or body] |
[State how and when a risk moves from project control to the Project Board, programme, portfolio or corporate level.]
[State the exposure, trend, response options, recommendation and decision required.]
[Name who may accept residual exposure at each level.]
[State where acceptance, rejection, conditions, delegated action and review dates are recorded.]
Appetite, tolerance and escalation scrutiny questions
- Are appetite and tolerance translated into measurable thresholds?
- Is residual exposure compared explicitly with tolerance?
- Does a breach trigger mandatory escalation?
- Is the receiving governance authority named?
- Are acceptance decisions, conditions and dates recorded?
- Can the Board see aggregated and systemic exposure, not only individual risks?
6. Lifecycle integration and auditability
Keep risk governance alive as the context changes.
Exposure changes through initiation, procurement, delivery, transition and benefit realisation. Define when risks are reassessed, transferred and retained after project closure.
Lifecycle controls
| Control point | Required risk activity | Evidence | Decision or owner |
|---|---|---|---|
| Initiation and approval | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Stage planning | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Commercial or supplier decision | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Material change | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Stage boundary | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Transition and closure | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
| Benefits review | [Identify, reassess, escalate or transfer] | [Register, report or decision record] | [Named role or body] |
[Identify the Risk Register, dashboards, escalation records, Board minutes and supporting analysis.]
[State where records are held, who may update them and how historical versions are retained.]
[State who tests the completeness, scoring, ownership, escalation and traceability of risk governance.]
[State how lessons, recurring themes and assurance findings change future identification and control.]
Lifecycle and auditability scrutiny questions
- Are stage boundaries formal risk review points?
- Do changes to scope, cost, schedule or commercial position trigger reassessment?
- Are risks to benefit realisation retained after delivery where necessary?
- Is ownership transferred formally into operational control?
- Are lessons and recurring patterns used to improve identification?
- Can historical exposure and decisions be reconstructed?
Copyable Risk Register template
Build the operational instrument.
Use one row for each discrete threat or opportunity. Use one controlled column for each governance field. Do not merge identification, response, escalation and audit information into one narrative cell.
1. Identification fields
| Field | What to record |
|---|---|
| Risk ID | Unique, immutable reference |
| Risk Title | Concise label for reporting |
| Risk Description | Cause, uncertain event and measurable impact |
| Risk Category | Approved strategic, commercial, financial, operational, technical, regulatory, benefits or other category |
| Date Identified | Date the exposure entered the register |
| Identified By | Originator for traceability |
| Risk Type | Threat or opportunity |
2. Inherent assessment fields
| Field | What to record |
|---|---|
| Probability (Inherent) | Score before response |
| Impact (Inherent) | Score before response |
| Overall Inherent Rating | Calculated rating using the approved matrix |
| Impact Type | Cost, time, scope, quality, benefits, reputation or other approved dimension |
| Proximity | Expected timeframe for materialisation |
| Velocity | Speed at which impact develops once triggered, where relevant |
3. Response planning fields
| Field | What to record |
|---|---|
| Response Strategy | Avoid, reduce, transfer, share, accept, exploit or enhance |
| Response Description | Specific actions expected to change exposure |
| Risk Owner | Individual accountable for exposure |
| Risk Action Owner | Individual responsible for delivering the action |
| Target Date for Action | Committed completion date |
| Mitigation Status | Controlled status such as not started, in progress, complete or overdue |
4. Residual assessment fields
| Field | What to record |
|---|---|
| Probability (Residual) | Reassessed probability |
| Impact (Residual) | Reassessed impact |
| Overall Residual Rating | Calculated rating after the planned response |
| Residual Within Tolerance? | Yes or no against the defined threshold |
| Secondary Risk | Any new exposure created by the response |
5. Escalation and governance fields
| Field | What to record |
|---|---|
| Escalation Required? | Yes or no |
| Date Escalated | Formal escalation date |
| Escalated To | Named governance body or role |
| Board Decision or Direction | Decision, conditions and required action |
| Risk Accepted by Board? | Formal acceptance status |
| Date of Decision | Decision date and reference |
6. Status and audit trail fields
| Field | What to record |
|---|---|
| Current Status | Open, closed, escalated, transferred or another controlled status |
| Date Closed | Formal closure date |
| Closure Rationale | Evidence explaining why no further control is required |
| Last Reviewed Date | Most recent review date |
| Next Review Date | Next scheduled review |
| Review Forum | Body or meeting that reviewed the risk |
| Last Updated By | Named person responsible for the update |
Risk Register architecture scrutiny questions
- Does every risk have an immutable identifier?
- Does each description state cause, uncertain event and impact?
- Are inherent and residual ratings both present?
- Are risk owner and action owner recorded separately?
- Are escalation and Board decisions captured in the same controlled record?
- Is closure supported by a rationale and review evidence?
7. Reporting and Excel controls
Make the register usable under scrutiny.
The register should behave as a controlled dataset. Its technical design must protect the scoring model, expose material residual risk and feed governance reporting without manual contradiction.
Register controls
[Use controlled lists for probability, impact, category, response, status and escalation fields.]
[Lock rating calculations and other controlled logic.]
[Highlight high residual exposure, tolerance breaches and overdue actions.]
[Enable analysis by owner, category, status, trend, proximity and governance level.]
Governance reporting schedule
| Report or view | Frequency or trigger | Audience | Decision supported |
|---|---|---|---|
| Top residual risks | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
| Tolerance breaches | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
| Emerging risks | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
| Overdue response actions | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
| Exposure by category | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
| Risk trend and movement | [Frequency or trigger] | [Named role or body] | [Decision, escalation or action] |
Reporting and control scrutiny questions
- Can the register produce a current top-risk view without manual reinterpretation?
- Are tolerance breaches and overdue actions immediately visible?
- Can exposure be analysed by category, owner and trend?
- Do Board reports reconcile with the controlled register?
- Are updates attributable and timestamped?
- Does reporting support a decision rather than simply describe activity?
Final quality check
Test whether the system evidences control.
Final risk governance quality check
- Does risk governance protect explicit Business Case assumptions?
- Are appetite and tolerance defined in measurable terms?
- Are threats and opportunities both included?
- Are risks written as cause, event and impact?
- Are issues kept separate from risks?
- Are inherent and residual exposure assessed separately?
- Is every material risk owned at the appropriate level?
- Does every response action have a responsible owner and date?
- Is residual exposure compared with tolerance?
- Do tolerance breaches trigger formal escalation?
- Are Board acceptance decisions recorded?
- Can aggregated and systemic exposure be seen?
- Are risks reassessed at stage boundaries and after material change?
- Are post-project risks transferred to named operational owners?
- Can an independent reviewer reconstruct exposure and decisions over time?
If any answer is no, the risk governance system is not ready to evidence control.
Want the editable Word version?
Use the full Risk Governance Guide.
The page above gives you a complete structure you can use immediately. The editable 21-page Word guide goes further with reviewer focus notes, common failure warnings, removable prompts, section quality checks, detailed governance rationale and Excel register design guidance.
The resource unlocks shortly after the trial period.
Explore Prepare2Lead membershipIncluded with paid Prepare2Lead membership, from $97 a month.Important note
This working template supports structured risk governance. It does not replace your organisation's approved risk framework, scoring model, assurance requirements or professional judgement.
Never use artificial intelligence to invent risks, likelihoods, impacts, owners, responses, tolerances or governance decisions. It can help organise verified material, but accountability remains with the risk owners, Senior Responsible Owner and approving body.