Risk Register Template: Score It, Rate It, and Actually Review It in 2026
A risk register is one list of everything that could go wrong on a project, scored so the worst items sort themselves to the top and owned so somebody is watching each one. A good risk register template ships that structure already working: a rated probability and impact, a score that multiplies them, an owner, a response strategy, a review date, and a status. The four versions below are exactly that, free to download with no email gate.
The register is not the point. The review is. Almost every dead register died the same way: it was built in week one, presented at kickoff, and never opened again, so the risks it listed arrived anyway and surprised everyone. What follows is the structure, the scoring, and the review habit that keeps one alive, plus a live version you can type into right now without signing up for anything.
Try this risk register live. No signup.
This is a real, editable register, not a screenshot. Change a probability, flip a status, rewrite a risk, pick a different response strategy. Your edits stay in this tab. When you want to keep one, a click makes it yours.
| Risk | Category | Probability | Impact | Owner | Response | Review by | Status |
|---|---|---|---|---|---|---|---|
Sandbox only, edits don't persist. Want to keep your work? Start your 7-day free trial →
Four risk register templates, free to download
Every version below is a real working sheet exported from the product itself, filled with realistic example risks so you can see how each column is meant to be used before you replace them with your own. Each one is a spreadsheet file that opens in Excel and in the free browser tools, and the download link is right on the card with no email gate in front of it.

Scored Risk Register
The full working register for an active project, and the one most people mean by "risk register". Probability and Impact are rated 1 to 5, the Score column multiplies them with a live formula, and the Rating column turns that number into red, amber or green on its own, so the register ranks itself as you type instead of waiting for someone to re-sort it. Category, Response Strategy, Owner, Review By and Status complete the row. Use this one when the project is big enough that risks must be ranked rather than merely listed, or when a client or a project office expects quantified exposure rather than a paragraph of reassurance.

Simple Risk Register
The lightweight version, with words instead of numbers: Likelihood and Impact are simply Low, Medium or High, and the row carries a mitigation, an owner, a review date and a status. Use it on a small project where a scoring formula is more machinery than the work deserves, but "what could go wrong, who is watching it, and when do we look again" still needs a written answer. The review-date column is the quiet discipline here: a register where every row has a next-look date cannot silently rot. Graduate to the scored version when you have more risks than you can hold in your head.

Construction Risk Register
The same scoring, organized the way a build actually runs. Every risk is tagged to the phase it threatens, from sitework through structure and services to finishes and closeout, and carries the control measure that reduces it rather than a vague mitigation note. The example rows are the real ones: weather against the slab pour, rock below the footing line, truss delivery against the frame date, an inspection that fails first pass, selections the owner has not confirmed. Filter by phase and the weekly site walk and the register are finally looking at the same list.

Program Risk Register
The roll-up register for a program office running several related workstreams. Each risk carries a reference id, the workstream it sits in, an inherent score before mitigation and a residual score after it, and an escalation flag. The inherent-versus-residual pair is the useful part: it shows whether the mitigation is actually buying anything, which is the question a steering group should be asking. Filter to the escalated rows and the steering meeting reads the short list that needs a decision instead of the full log, which is how those meetings stay under an hour.
How to build a risk register that survives past kickoff
Write each risk as an event with a consequence
The difference between a useful register and a wall of nouns is specificity. "Resourcing risk" tells nobody anything. "Our only database engineer is on leave for all of August and the migration is scheduled for August 12" can be acted on today. A good entry names the event, the consequence, and the time window, in one or two plain sentences. If you cannot state the consequence, you have not understood the risk yet, and writing the row is the cheapest place to discover that.
Score probability and impact on the same 1 to 5 scale
Rate how likely the event is from 1 to 5, rate how badly it would hurt from 1 to 5, and multiply the two. That product, between 1 and 25, is the score that ranks your register. The scale is arbitrary and that is fine: its job is to make risks comparable to each other, not to predict the future. What matters is that everyone rates against the same definitions, so agree up front what a 4 impact means in money, days, or reputation before anyone starts typing numbers into the column.
Turn the score into a color, and let it re-rate itself
A number is easy to skim past. A red row is not. Band the scores once, for example 15 and above red, 8 to 14 amber, below 8 green, and let the rating follow the score automatically. In the downloads the Rating column is already banded that way. Built live in Wisegrid, a one-line formula converted to a column formula rates every row including new ones, and conditional formatting fills the whole row red, so a risk that gets worse announces itself the instant somebody changes a probability.
Give every risk one owner and one response strategy
A risk owned by "the team" is owned by nobody. Assign each row to one named person, and pick the strategy explicitly: mitigate (reduce it), avoid (change the plan so it cannot happen), transfer (insure or contract it away), or accept (decide consciously to carry it). The owner is not necessarily the person who fixes the problem. Their job is making sure it never gets forgotten. Naming the strategy also stops the register from quietly treating every risk as something somebody will get to eventually.
Put a review date on every open risk
This is the single column that decides whether the register lives or dies. A risk without a next-look date is a note. A risk with one is a commitment. Set the date proportionate to the score, so a red risk comes back in a week and a green one in a month, and move it forward every time you look. In Wisegrid an automation reads that column directly: on the review date, if the status is not Closed, it emails whoever is in the Owner column, and keeps a run history of every nudge it sent.
Review on a cadence, in a meeting that already exists
Do not create a risk meeting. Put a ten-minute pass through the register into a meeting the team already attends, and walk it in score order: what changed, what is stale, what escalates, what can close. Close resolved risks aggressively and date every update so staleness is visible at a glance. Fifteen well-tended rows will catch more trouble than two hundred abandoned ones, and a register that is genuinely current is the only one a sponsor will ever learn to trust.
Keep one register, where the team already works
A register split across a slide appendix, a file on somebody’s desktop, and a chat thread is three registers, which is zero registers. Keep a single copy everyone can open and edit, and make it the artifact the review actually scrolls through. This is where a live sheet beats a static file: the same register gains owner contacts, dropdowns, real date columns, an intake form so anyone can raise a risk without editing the sheet, and a shared view that shows a sponsor only the red rows.
The probability and impact matrix, in one table
The scoring matrix behind every scored register is just multiplication. Probability runs 1 (very unlikely) to 5 (near certain). Impact runs 1 (barely noticeable) to 5 (the project fails or somebody gets hurt). Multiply and you get a score from 1 to 25, which sorts the register. The usual bands are 15 and above red (act now, and escalate), 8 to 14 amber (mitigate and watch on a short cycle), and below 8 green (accept and review occasionally).
Two things make the matrix work in practice. First, write the definitions down: a 4 impact should mean something concrete, such as more than two weeks of delay or more than ten percent of budget, so two people rating the same risk land in the same place. Second, score the risk as it stands today, with the mitigations you have actually done, not the ones you intend to do. Registers drift optimistic exactly there, and one everybody privately discounts is worse than none at all.
On a program the honest version splits the score in two: inherent before mitigation, residual after it. The gap between them is what your mitigation is actually buying, and a risk whose two scores are identical is a risk you are only watching. The program-level download carries both columns for that conversation.
The four risk response strategies, and when to use each
Mitigate means reduce the probability or the impact while still doing the work: pre-order the long-lead item, add a rehearsal, cross-train a second person. It is the default and the most common. Avoid means change the plan so the risk cannot occur at all: drop the feature, move the date out of the freeze window, choose the component that does not need certification. Avoidance is underused because it costs scope, but on a red risk it is often the cheapest answer available.
Transfer means move the consequence to somebody better placed to carry it: insurance, a fixed-price contract, a penalty clause, a vendor commitment in writing. Transfer moves the money, not the problem, so a transferred risk still needs an owner and a review date. Accept means deciding consciously to carry it, ideally with a contingency set aside and a trigger that tells you when to act. Accept is a legitimate answer. What is not legitimate is an unwritten accept, which is simply a risk nobody looked at.
Risk register, RAID log, or issue log: which do you need?
A risk register holds only risks, usually scored, and is often the artifact a client or a project office formally asks for. A RAID log is broader and more operational: it adds assumptions, issues and dependencies to the same list so the team has one place to look for everything threatening the plan. An issue log holds only problems that are already happening. The distinction that matters is time: a risk might happen, an issue is happening. When a risk materializes, close the risk row and open an issue that references it, so the record shows what you saw coming.
On most projects one scored register plus a short issue list does the whole job. On a program the two coexist: the register holds the formally assessed and escalated risks, and a RAID log runs the week-to-week working list.
Frequently asked questions
What is a risk register?
A risk register is a single list of the things that could go wrong on a project, each one written as an event with a consequence, rated for how likely and how damaging it is, assigned to a named owner, given a response strategy, and carrying a date when it gets looked at again. Its purpose is not documentation. It is to make sure the worst items stay visible and someone is actively watching each one.
What should a risk register include?
Nine columns cover it: the risk itself, a category, a probability rating, an impact rating, the score those two produce, a rating or traffic light derived from the score, an owner, the response strategy, and a review date with a status. The scored download on this page ships exactly those columns with the score and rating already calculating. Anything beyond that list is usually organization-specific reporting rather than something the team needs to work the risk.
How do you calculate a risk score?
Multiply probability by impact. Rate each from 1 to 5 and the product gives a score from 1 to 25, which is what ranks the register. Common bands are 15 and above red, 8 to 14 amber, and below 8 green. In a live sheet that is one formula, Probability times Impact, converted to a column formula so every row scores itself, and a second one-line formula that turns the score into the color band.
What is the difference between a risk register and a RAID log?
A risk register tracks only risks, usually with probability and impact scoring, and is often the formal artifact a client or a project office asks for. A RAID log is broader and more operational: it adds assumptions, issues and dependencies to the same list. On a program the two coexist, with the register holding the formally assessed risks and the RAID log running the working list. On most projects a single scored register does both jobs.
What are the four risk response strategies?
Mitigate, avoid, transfer and accept. Mitigate reduces the probability or the impact while you carry on. Avoid changes the plan so the risk cannot occur. Transfer moves the consequence to somebody better placed to carry it, through insurance or a contract. Accept means deciding consciously to live with it, ideally with contingency set aside. Recording which one you chose is what stops a register from silently assuming every risk is being worked on.
How often should a risk register be reviewed?
Update it whenever something changes, and review it as a team on a fixed cadence, weekly for most projects. Set individual review dates in proportion to score, so a red risk returns within a week and a green one within a month. Cadence matters less than consistency: a register walked for ten minutes every single week catches far more trouble than one audited in depth once a quarter and ignored in between.
Why keep the risk register in Wisegrid instead of a spreadsheet file?
A file goes stale in a folder. The live version scores and rates every row as you type, fills high-rated rows red on its own, emails each risk owner on the review date when the risk is still open, takes new risks through a form so anyone can raise one without editing the sheet, and rolls the open count and category split onto a dashboard that updates itself. The free downloads above are yours either way.
Run it live instead of in a file.
The downloads above are yours either way. In Wisegrid the same template becomes a working sheet with owner contacts, status dropdowns, reminders, and dashboards. 7-day free trial, no credit card required.