Risk Register Template Permalink
Use this template to run a project risk register in Quire: score each risk on a 5x5 matrix, give it one owner, hold the mitigation actions as subtasks, and review the whole thing on a fixed rhythm.
You can visit the Risk Register project and duplicate it to your workspace, so you don’t need to build everything from scratch.
You can also explore more ready-to-use templates to speed up your workflow.
Understand Risk Registers
A risk register is a living list of what could go wrong on your project and what you are doing about each one. The word doing most of the work there is living. A register that looks the same in November as it did in August is one nobody is using, and it is worse than having none, because it looks like risk is being managed.
Risks are grouped into sections by category, which makes clustering visible. Five risks sitting in one category usually means one structural problem rather than five separate ones.
Six sections hold the risks themselves, covering budget and cost, schedule and delivery, resource and people, technical and quality, vendor and third party, and external, market and compliance. A seventh section at the bottom holds the review cadence. The Category field offers seven options, splitting external and market from compliance and legal, so you can still tell those two apart when filtering.
The template ships with twenty sample risks written out in full, so you can see the shape of a good entry before replacing them with your own.
Score Risks with the 5x5 Matrix
Rate Likelihood from 1 to 5, rate Impact from 1 to 5, multiply them, and put the result in Risk Score. That number is what you sort by, and sorting by it is the single most useful thing you will do with the register.
| ↓ Likelihood / Impact → | 1 Negligible | 2 Minor | 3 Moderate | 4 Major | 5 Severe |
|---|---|---|---|---|---|
| 5 Almost Certain | 5 | 10 | 15 | 20 | 25 |
| 4 Likely | 4 | 8 | 12 | 16 | 20 |
| 3 Possible | 3 | 6 | 9 | 12 | 15 |
| 2 Unlikely | 2 | 4 | 6 | 8 | 10 |
| 1 Rare | 1 | 2 | 3 | 4 | 5 |
Note: Risk Score is a number you type, not a formula. Quire formulas cannot multiply two Select fields, so the trade-off is a manual multiplication in exchange for keeping the Likelihood and Impact labels readable rather than storing them as bare numbers.
Risk Levels
The score lands in one of four bands, and each band obliges you to do something different. This is what stops scoring from being an academic exercise.
| Band | Score | What it requires |
|---|---|---|
| Low | 1-4 | Accept and note. Review quarterly. No action plan needed. |
| Medium | 5-9 | Named owner and a documented response. Review monthly. |
| High | 10-14 | Named owner and a funded mitigation plan with dates. Review weekly. |
| Critical | 15-25 | Escalate to sponsor, reserve contingency, report to the steering group. |
Two Scoring Mistakes
Everything scores a 4. If most of the register sits in High, the scale has stopped discriminating and you no longer have a priority list. Force a spread. Something has to be a 1.
Scoring the wrong impact. Score the impact on the project objective, not the general drama of the event. A supplier going bankrupt sounds severe, but if two other suppliers can cover it, the project impact is Minor.
Read the Register in Table View
Table view is only available in the Professional, Premium, Enterprise plans. More information can be found on our pricing page.
Table view is where this template lives. It puts every scoring field in a column so you can compare entries at a glance, which List view cannot do.
Sort by Risk Score descending and the register becomes a ranked worklist. You can edit field values directly in the table, which is what makes a monthly re-scoring pass quick enough that people actually do it.
Custom Fields
Eight custom fields carry the assessment:
| Field | Type | What it is for |
|---|---|---|
| Risk ID | Text | A stable reference such as R-01, so a risk can be cited in notes without the full title |
| Category | Select | Which part of the project is exposed |
| Likelihood | Select | 1 Rare through 5 Almost Certain |
| Impact | Select | 1 Negligible through 5 Severe |
| Risk Score | Number | Likelihood times Impact, 1 to 25 |
| Risk Level | Select | The score bucketed into Low, Medium, High, Critical |
| Response Strategy | Select | Avoid, Mitigate, Transfer, Accept, Escalate |
| Date Identified | Date | Useful for finding entries nobody has revisited |
Write a Risk Entry
Every sample risk in the template follows the same four-part shape in its description. Copy it.
- Risk statement: what could happen, with a number attached wherever possible
- Trigger or early warning: the observable signal that this is becoming real
- Consequence if realized: what it does to the project, which is what justifies the Impact score
- Current response: the strategy plus the specific actions
“Cloud spend could rise from $42k to $58k monthly” is workable, because you can tell when it is happening. “Costs might increase” is not. The trigger matters just as much: without an observable signal you are relying on somebody noticing, and noticing is not a control.
One Owner Each
Assign exactly one person to every risk. Not a team, not a role. Shared ownership of a risk produces no ownership, and an unowned risk is the most reliable predictor of a register going stale.
The owner is not necessarily the person doing the mitigation work. They are the person accountable for the response existing, staying current, and getting escalated when it stops working.
Mitigation as Subtasks
The concrete steps live as subtasks under each risk, with their own assignees and due dates. This is the line between a register that changes things and one that merely describes them.
There is a test for whether a response is real: if it cannot be written as a task with an owner and a due date, it is not a mitigation, it is a wish. “Monitor the situation” and “communicate closely with the vendor” both fail.
Response Strategies
Every risk needs exactly one Response Strategy:
- Avoid: change the plan so the risk cannot occur. Cheapest when available, but it usually costs scope.
- Mitigate: reduce the likelihood, the impact, or both. The default for most High risks.
- Transfer: move the financial consequence elsewhere through insurance, fixed-price contracts, or penalty clauses. It moves the cost, not the disruption, so you still lose the time.
- Accept: acknowledge it, budget for it, do nothing further. Valid for Low risks, but it needs a documented decision. Accept is a choice, not the absence of one.
- Escalate: push it to the sponsor when it sits outside your authority. Bring a recommendation and it is not passing the buck.
Track the Response Workflow
In the Free Subscription plan, you can have up to 5 statuses in each project, and this template uses 6. Merge Analyzing into Planning Response after duplicating, or upgrade your subscription plan to keep all six. More information can be found on our pricing page.
A risk itself never completes. Your handling of it does, and the six statuses track that: Identified, Analyzing, Planning Response, Mitigating, Monitoring, and Closed.
Board view groups everything by status and shows the scoring fields on each card. Mitigation subtasks appear alongside the risks, so filter to the top level when you want the risks on their own.
Closed means the exposure is permanently gone, not that you stopped worrying about it. If it can still occur, it belongs in Monitoring.
Tags
Five tags cut across the categories and answer questions the scoring fields cannot:
- Trigger Fired: the early warning has already activated, so look at these first
- Launch Blocker: will stop the release if unresolved
- Escalated to Sponsor: outside the team’s authority
- Contingency Reserved: budget is set aside for this one
- Needs Re-scoring: the situation changed since the last assessment
Review on a Cadence
The governance section at the bottom of the register holds the reviews as recurring tasks, so they arrive on the schedule whether or not anyone remembers them.
Four rhythms, each with a different job:
| Rhythm | What happens |
|---|---|
| Weekly | High and Critical only, sorted by score. About 30 minutes. |
| Fortnightly | Twenty minutes at the end of sprint planning to add what is missing. |
| Monthly | Re-score the whole register and close what no longer applies. |
| Quarterly | A one-page report to the steering group. |
At the weekly review, ask three questions of each risk:
- Has the score changed, and does the Risk Level need updating?
- Is the mitigation actually moving, or has it been in progress for three weeks?
- Has the trigger fired?
A review that ends with no field changed anywhere on the register is a review that did not happen.
Tip: When you close a risk, write down whether it occurred, how the actual impact compared to the predicted one, and whether you would score it the same way again. That last question is the part that makes the next project easier, and skipping it is why plenty of teams score risks no better in year five than in year one.
Read more on our blog about how to score a risk and keep the register alive.
Frequently Asked Questions
What is a risk register?
A risk register is a living list of what could go wrong on a project and what you are doing about each one, with a likelihood, an impact, an owner, and a response for every entry. If nothing on it changed at the last review, the review did not happen.
What should a risk register include?
A risk statement, a likelihood rating, an impact rating, a combined score, one named owner, and a response strategy. A stable risk ID, a category, and a date identified make it substantially more useful.
How do you score risk likelihood and impact?
Rate each from 1 to 5 and multiply. Likelihood runs from Rare to Almost Certain, impact from Negligible to Severe. Score the impact on the project objective, not the general drama of the event.
What is a 5x5 risk matrix?
A grid with likelihood and impact each rated 1 to 5, giving scores from 1 to 25. The score is then bucketed into bands, and each band carries a different obligation, which is what turns a number into a required action.
What are the five risk response strategies?
Avoid, Mitigate, Transfer, Accept, and Escalate. Transfer moves the financial consequence but not the disruption, and Accept is a documented decision rather than the absence of one.
Who should own a risk in a risk register?
One named person, never a team or a role. The owner is accountable for the response existing and staying current, not necessarily for doing the mitigation work, which is assigned separately on the subtasks.
How often should a risk register be reviewed?
Weekly for High and Critical entries, fortnightly to add what is missing, monthly to re-score everything, and quarterly to report to the steering group. The template holds these as recurring tasks so they appear on the schedule by themselves.
How do I create a risk register in Quire?
Duplicate the Risk Register template, switch to Table view, and sort by Risk Score descending. Read a few sample risks to learn the four-part entry shape, then delete the samples, keep the fields and sections, and add about five of your own.
Is there a ready-made risk register template in Quire?
Yes. Visit the Risk Register project and duplicate it to your workspace to get the eight custom fields, six-stage workflow, category sections, five tags, and recurring review tasks already set up.