Residual risk: the difference between having a risk register and managing risk
- lorenaflorian0
- Jul 21
- 6 min read
Updated: Jul 24

A project does not become safe because a mitigation action has been assigned. It does not become low risk because someone has coloured a dashboard green and it certainly does not become controlled simply because a risk register has been updated.
The real test of effective risk management is whether leaders understand the residual risk that remains after planned controls and treatments have been implemented. Residual risk is what should be governed.
What is residual risk?
Residual risk is the level of exposure that remains after a project has applied its planned risk responses. Every material risk should therefore be assessed twice:
Inherent risk: the likelihood and impact before controls or treatments are applied.
Residual risk: the likelihood and impact expected after the treatments are fully implemented and operating effectively.
This distinction matters because many project teams confuse the completion of an action with the reduction of the risk. For example, a project may identify a risk that a critical specialist resource could leave before the design phase is completed. The team may assign an action to recruit a replacement or secure a contractor.
That action may be marked complete. However, the residual risk may still be high if:
the replacement has not yet started
knowledge transfer has not occurred
the new resource lacks the necessary authority or experience
The treatment may be complete on paper. The risk may not be controlled in practice.

Why residual risk matters
Residual risk forces a more honest conversation about whether the project is genuinely within the organisation’s risk appetite. A project can have excellent mitigation plans and still carry a significant residual exposure. This is common where risks relate to:
regulatory approvals
key-person dependency
supplier capability
cyber security
Ethical use of AI
stakeholder resistance
market volatility
complex integration
public safety
operational readiness
benefits realisation
The question is not simply, “What are we doing about the risk?”
The more important questions are:
“What exposure remains after those actions?”
“Is that remaining exposure acceptable?”
“Who has authority to accept it?”
“What decision is needed if it is not acceptable?”
Residual risk enables decision-makers to distinguish between manageable uncertainty and exposure that requires escalation, contingency funding, a change in approach, or even a decision to pause or stop the work.

Start with a well-written risk
A weakly written risk produces weak analysis and ineffective treatment.
A useful risk statement should make the relationship between cause, event and effect clear:
Because [cause], there is a risk that [uncertain event], resulting in [effect on objectives].
For example:
Because the project relies on a single executive to approve the operating model, there is a risk that approval will not be available before the design gate, resulting in a delay to implementation, increased supplier costs and deferred benefits.
Or another way to capture is starting with the event, then cause and effect, so this would be written as there is a risk that [uncertain event], because [cause], resulting in [effect on objectives].
For example:
Approval will not be available before the design gate because the project relies on a single executive to approve the operating model, resulting in a delay to implementation, increased supplier costs and deferred benefits.
Using either of these approaches is stronger than writing:
Executive approval risk.
The first two options gives the team something practical to manage. It identifies the underlying cause, the event to monitor and the consequences to protect against.

Identify the full risk picture
Effective risk identification is not a one-off workshop at the start of the project. It is a continuing management discipline.
Project teams should identify risks through a range of lenses:
strategic and benefits risks
scope, requirements and design risks
schedule and dependency risks
cost and funding risks
resource and capability risks
supplier and procurement risks
stakeholder and change adoption risks
safety, security and regulatory risks
data, AI, technology and integration risks
environmental, social and sustainability risks
transition and business-as-usual risks
The strongest teams do not only ask, “What could go wrong?”
They link to other registers in the B-RADICAL and also ask:
What assumptions must remain true?
What dependencies could fail?
What early warning signs would tell us the risk is increasing?
What could make the controls ineffective?
What risks will be transferred into operations at handover?
What opportunities could improve outcomes if actively pursued?

Treat risks, but do not assume they disappear
For threats, the standard treatment choices are to:
Prevent the risk by changing the scope, approach or decision.
Reduce the likelihood or impact through controls and preventative actions.
Accept the exposure where it is within appetite and no proportionate further action is justified.
Contingency is linked to accepting but having a contingency plan should the event occur
Transfer part of the exposure through insurance, contracts or other arrangements.
A good treatment plan should be specific. It should identify:
the control or action
the owner accountable for the risk
the action owner responsible for completing the treatment
due dates or review date if a long way in the future
required resources or funding
evidence that the treatment is working
contingency actions if the risk occurs
The important point is that a treatment should address the cause, likelihood, impact or recovery capability. A generic action such as “monitor closely” is rarely a treatment. It is usually an instruction to continue watching the problem develop.

Assess residual risk honestly
Residual risk should only be reassessed once the project understands the likely effectiveness of the controls.
This means asking:
Has the action actually been completed?
Is the control operating as designed?
Has it been independently tested or evidenced?
Does it address the real cause of the risk?
Has the proximity of the risk changed?
Has the impact changed because the project is now closer to a critical milestone?
Has the treatment created secondary risks?
For each significant risk, record both the inherent and residual probability and impact.
For example:
Measure | Before treatment | After treatment |
Probability | High | Medium |
Impact | High | High |
Overall exposure | Severe | High |
This is an important result. The risk has reduced, but it remains high.
It should not be reported as green simply because the mitigation action is progressing.
Manage more than probability and impact
Probability and impact remain essential, but they are not enough on their own.
Strong risk registers also include:
Proximity: when the risk may occur.
Velocity: how quickly it will affect objectives if it occurs.
Trend: whether exposure is increasing, stable or decreasing.
Triggers: observable early warning indicators.
Dependencies: linked projects, suppliers, approvals or decisions.
Contingency: what the team will do if the risk event occurs.
Escalation threshold: when the project manager must raise the risk to the sponsor or board.
A high-impact risk due in eighteen months may require a different response to a medium-impact risk that could disrupt a go-live next week.
Risk is not just about size. It is also about timing, speed and decision urgency.

Report risks to support decisions
Risk reporting should not be a long list of red, amber and green items.
Senior leaders need a concise, decision-focused view of exposure.
A useful project report should show:
Overall risk position
Is the project’s residual exposure within appetite and tolerance?
Top residual risks
What are the most significant remaining threats and opportunities?
Movement since the last report
Which risks have increased, reduced, materialised or closed?
Control effectiveness
Are treatments complete, overdue, untested or failing?
Forecast impact
What could happen to scope, cost, schedule, quality, sustainability, benefits or reputation if the risk materialises?
Decisions required
What does the sponsor, steering committee or project board need to approve, prioritise or resolve?
A good risk report allows leaders to answer four questions quickly:
What are we most exposed to?
What has changed?
Are the controls working?
What decision is needed now?

The minimum risk register standard
For material risks, a project risk register should include at least:
unique risk identifier
cause, event and effect description
risk category
inherent probability and impact
planned residual probability and impact
risk owner
risk action owner
treatment actions and due dates
proximity and velocity
triggers or early warning indicators
contingency or fallback response
status and trend
linked issues, assumptions, dependencies, benefits and change requests
escalation requirement and decision date
evidence of control effectiveness
This creates traceability between the project’s risks, decisions, plans, controls and governance.

Risk management is a leadership discipline
Effective risk management is not about creating fear, bureaucracy or unnecessary reporting.
It is about creating enough transparency for the right people to make timely decisions.
The strongest project leaders make it safe for risks to be raised early. They challenge optimistic assumptions. They distinguish between actions being completed and risks actually reducing. They escalate residual exposure before it becomes an issue.
Because bad news does not get better over time, a risk register should therefore never be treated as an administrative artefact. It is a live management tool that helps protect the project’s objectives, benefits, reputation and investment.
The critical discipline is simple:
Do not ask whether the mitigation action is complete.
Ask what risk remains after the mitigation action is complete.
That is residual risk. And that is where effective project control begins.

The PMLogic team have supported many organisations improve achievement of their strategic goals by improving risk practices, from organisational Board to project delivery levels. We do this by coaching, training, establishing new practices, chairing Audit and Risk Committees and contributing to global risk management frameworks such as Management of Risk (MoR®).
Please contact one of the team for assistance.

.png)



Comments