Projects fail on the risks they didn't manage. Risk management is the systematic process of dealing with uncertainty so it doesn't derail delivery — and the RAID log is the tool that keeps it all in one place.
Risk vs issue
- A risk is an uncertain future event that could affect the project (positive or negative).
- An issue is a risk that has happened — it's real now and needs resolving. Managing risks early is far cheaper than fire-fighting issues later.
The risk management cycle
- Identify — brainstorm what could go wrong (and go right); log each risk clearly.
- Assess — score each by probability × impact to prioritise. A simple 1–5 scale on each axis gives a risk score and a heat-map.
- Respond — choose a strategy for each significant risk:
- Avoid — change the plan so the risk can't occur.
- Reduce (mitigate) — lower its probability or impact.
- Transfer — shift it to a third party (e.g. insurance, a supplier contract).
- Accept — tolerate it, usually with a contingency (time/money reserve) and a fallback plan. (For positive risks/opportunities: exploit, enhance, share, accept.)
- Monitor & review — risks change; review the register regularly and assign an owner to each.
The risk register
A living table: risk description, category, probability, impact, score, response, owner and status. It's reviewed at every progress meeting.
The RAID log
RAID is the PM's control document, combining four related lists:
- R — Risks — uncertain future events (from the risk register).
- A — Assumptions — things taken as true that, if wrong, become risks.
- I — Issues — problems happening now.
- D — Dependencies — things this project relies on (or that rely on it), internal or external. Keeping RAID current gives you and your sponsor a single, honest view of project health.
Put it to work
Start a RAID log for a current project: list your top five risks with probability × impact and a response for each, plus your key assumptions and dependencies. Practise a risk-based decision in the Practical activities.
