top of page

Residual risk: the difference between having a risk register and managing risk

Updated: Jul 24


A project does not become safe because a mitigation action has been assigned. It does not become low risk because someone has coloured a dashboard green and it certainly does not become controlled simply because a risk register has been updated.


The real test of effective risk management is whether leaders understand the residual risk that remains after planned controls and treatments have been implemented. Residual risk is what should be governed.


What is residual risk?


Residual risk is the level of exposure that remains after a project has applied its planned risk responses. Every material risk should therefore be assessed twice:


  1. Inherent risk: the likelihood and impact before controls or treatments are applied.

  2. Residual risk: the likelihood and impact expected after the treatments are fully implemented and operating effectively.


This distinction matters because many project teams confuse the completion of an action with the reduction of the risk. For example, a project may identify a risk that a critical specialist resource could leave before the design phase is completed. The team may assign an action to recruit a replacement or secure a contractor.


That action may be marked complete. However, the residual risk may still be high if:


  • the replacement has not yet started

  • knowledge transfer has not occurred

  • the new resource lacks the necessary authority or experience


The treatment may be complete on paper. The risk may not be controlled in practice.


business analysis desk
business analysis desk

Why residual risk matters


Residual risk forces a more honest conversation about whether the project is genuinely within the organisation’s risk appetite. A project can have excellent mitigation plans and still carry a significant residual exposure. This is common where risks relate to:


  • regulatory approvals

  • key-person dependency

  • supplier capability

  • cyber security

  • Ethical use of AI

  • stakeholder resistance

  • market volatility

  • complex integration

  • public safety

  • operational readiness

  • benefits realisation


The question is not simply, “What are we doing about the risk?”


The more important questions are:


  • “What exposure remains after those actions?”

  • “Is that remaining exposure acceptable?”

  • “Who has authority to accept it?”

  • “What decision is needed if it is not acceptable?”


Residual risk enables decision-makers to distinguish between manageable uncertainty and exposure that requires escalation, contingency funding, a change in approach, or even a decision to pause or stop the work.


office meeting discussion
office meeting discussion

Start with a well-written risk


A weakly written risk produces weak analysis and ineffective treatment.


A useful risk statement should make the relationship between cause, event and effect clear:


Because [cause], there is a risk that [uncertain event], resulting in [effect on objectives].


For example:


Because the project relies on a single executive to approve the operating model, there is a risk that approval will not be available before the design gate, resulting in a delay to implementation, increased supplier costs and deferred benefits.


Or another way to capture is starting with the event, then cause and effect, so this would be written as there is a risk that [uncertain event], because [cause], resulting in [effect on objectives].


For example:


Approval will not be available before the design gate because the project relies on a single executive to approve the operating model, resulting in a delay to implementation, increased supplier costs and deferred benefits.

 

Using either of these approaches is stronger than writing:

Executive approval risk.


The first two options gives the team something practical to manage. It identifies the underlying cause, the event to monitor and the consequences to protect against.


writing on paper
writing on paper

Identify the full risk picture


Effective risk identification is not a one-off workshop at the start of the project. It is a continuing management discipline.


Project teams should identify risks through a range of lenses:

  • strategic and benefits risks

  • scope, requirements and design risks

  • schedule and dependency risks

  • cost and funding risks

  • resource and capability risks

  • supplier and procurement risks

  • stakeholder and change adoption risks

  • safety, security and regulatory risks

  • data, AI, technology and integration risks

  • environmental, social and sustainability risks

  • transition and business-as-usual risks


The strongest teams do not only ask, “What could go wrong?”


They link to other registers in the B-RADICAL and also ask:


  • What assumptions must remain true?

  • What dependencies could fail?

  • What early warning signs would tell us the risk is increasing?

  • What could make the controls ineffective?

  • What risks will be transferred into operations at handover?

  • What opportunities could improve outcomes if actively pursued?


typing on laptop
typing on laptop

Treat risks, but do not assume they disappear


For threats, the standard treatment choices are to:


  • Prevent the risk by changing the scope, approach or decision.

  • Reduce the likelihood or impact through controls and preventative actions.

  • Accept the exposure where it is within appetite and no proportionate further action is justified.

  • Contingency is linked to accepting but having a contingency plan should the event occur

  • Transfer part of the exposure through insurance, contracts or other arrangements.


A good treatment plan should be specific. It should identify:


  • the control or action

  • the owner accountable for the risk

  • the action owner responsible for completing the treatment

  • due dates or review date if a long way in the future

  • required resources or funding

  • evidence that the treatment is working

  • contingency actions if the risk occurs


The important point is that a treatment should address the cause, likelihood, impact or recovery capability. A generic action such as “monitor closely” is rarely a treatment. It is usually an instruction to continue watching the problem develop.


business meeting discussion
business meeting discussion

Assess residual risk honestly


Residual risk should only be reassessed once the project understands the likely effectiveness of the controls.


This means asking:

  • Has the action actually been completed?

  • Is the control operating as designed?

  • Has it been independently tested or evidenced?

  • Does it address the real cause of the risk?

  • Has the proximity of the risk changed?

  • Has the impact changed because the project is now closer to a critical milestone?

  • Has the treatment created secondary risks?


For each significant risk, record both the inherent and residual probability and impact.


For example:

Measure

Before treatment

After treatment

Probability

High

Medium

Impact

High

High

Overall exposure

Severe

High


This is an important result. The risk has reduced, but it remains high.


It should not be reported as green simply because the mitigation action is progressing.


Manage more than probability and impact


Probability and impact remain essential, but they are not enough on their own.


Strong risk registers also include:


  • Proximity: when the risk may occur.

  • Velocity: how quickly it will affect objectives if it occurs.

  • Trend: whether exposure is increasing, stable or decreasing.

  • Triggers: observable early warning indicators.

  • Dependencies: linked projects, suppliers, approvals or decisions.

  • Contingency: what the team will do if the risk event occurs.

  • Escalation threshold: when the project manager must raise the risk to the sponsor or board.


A high-impact risk due in eighteen months may require a different response to a medium-impact risk that could disrupt a go-live next week.


Risk is not just about size. It is also about timing, speed and decision urgency.


calendar pages
calendar pages

Report risks to support decisions


Risk reporting should not be a long list of red, amber and green items.


Senior leaders need a concise, decision-focused view of exposure.


A useful project report should show:


  1. Overall risk position

    Is the project’s residual exposure within appetite and tolerance?


  2. Top residual risks

    What are the most significant remaining threats and opportunities?


  3. Movement since the last report

    Which risks have increased, reduced, materialised or closed?


  4. Control effectiveness

    Are treatments complete, overdue, untested or failing?


  5. Forecast impact

    What could happen to scope, cost, schedule, quality, sustainability, benefits or reputation if the risk materialises?


  6. Decisions required

    What does the sponsor, steering committee or project board need to approve, prioritise or resolve?


A good risk report allows leaders to answer four questions quickly:


  • What are we most exposed to?

  • What has changed?

  • Are the controls working?

  • What decision is needed now?


presenter's gestures
presenter's gestures

The minimum risk register standard


For material risks, a project risk register should include at least:


  • unique risk identifier

  • cause, event and effect description

  • risk category

  • inherent probability and impact

  • planned residual probability and impact

  • risk owner

  • risk action owner

  • treatment actions and due dates

  • proximity and velocity

  • triggers or early warning indicators

  • contingency or fallback response

  • status and trend

  • linked issues, assumptions, dependencies, benefits and change requests

  • escalation requirement and decision date

  • evidence of control effectiveness


This creates traceability between the project’s risks, decisions, plans, controls and governance.


woman in office
woman in office

Risk management is a leadership discipline


Effective risk management is not about creating fear, bureaucracy or unnecessary reporting.


It is about creating enough transparency for the right people to make timely decisions.


The strongest project leaders make it safe for risks to be raised early. They challenge optimistic assumptions. They distinguish between actions being completed and risks actually reducing. They escalate residual exposure before it becomes an issue.


Because bad news does not get better over time, a risk register should therefore never be treated as an administrative artefact. It is a live management tool that helps protect the project’s objectives, benefits, reputation and investment.


The critical discipline is simple:


Do not ask whether the mitigation action is complete.

Ask what risk remains after the mitigation action is complete.


That is residual risk. And that is where effective project control begins.


business meeting panel
business meeting panel

The PMLogic team have supported many organisations improve achievement of their strategic goals by improving risk practices, from organisational Board to project delivery levels. We do this by coaching, training, establishing new practices, chairing Audit and Risk Committees and contributing to global risk management frameworks such as Management of Risk (MoR®).


Please contact one of the team for assistance. 



PMLogic team

Comments


bottom of page