Risk Management & RAID Logs

Cornerstone guide

Risk Management & RAID Logs

2 min readPublished 29 Jul 2026

Projects fail on the risks they didn't manage. Risk management is the systematic process of dealing with uncertainty so it doesn't derail delivery — and the RAID log is the tool that keeps it all in one place.

Risk vs issue

  • A risk is an uncertain future event that could affect the project (positive or negative).
  • An issue is a risk that has happened — it's real now and needs resolving. Managing risks early is far cheaper than fire-fighting issues later.

The risk management cycle

  1. Identify — brainstorm what could go wrong (and go right); log each risk clearly.
  2. Assess — score each by probability × impact to prioritise. A simple 1–5 scale on each axis gives a risk score and a heat-map.
  3. Respond — choose a strategy for each significant risk:
    • Avoid — change the plan so the risk can't occur.
    • Reduce (mitigate) — lower its probability or impact.
    • Transfer — shift it to a third party (e.g. insurance, a supplier contract).
    • Accept — tolerate it, usually with a contingency (time/money reserve) and a fallback plan. (For positive risks/opportunities: exploit, enhance, share, accept.)
  4. Monitor & review — risks change; review the register regularly and assign an owner to each.

The risk register

A living table: risk description, category, probability, impact, score, response, owner and status. It's reviewed at every progress meeting.

The RAID log

RAID is the PM's control document, combining four related lists:

  • R — Risks — uncertain future events (from the risk register).
  • A — Assumptions — things taken as true that, if wrong, become risks.
  • I — Issues — problems happening now.
  • D — Dependencies — things this project relies on (or that rely on it), internal or external. Keeping RAID current gives you and your sponsor a single, honest view of project health.

Put it to work

Start a RAID log for a current project: list your top five risks with probability × impact and a response for each, plus your key assumptions and dependencies. Practise a risk-based decision in the Practical activities.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Risk management is a core PM competency and a frequent interview and assessment-centre topic.

Technical questions
What is the difference between a risk and an issue?+

A risk is an uncertain future event; an issue is a risk that has already happened and needs resolving now.

How do you decide how to respond to a risk?+

Assess probability × impact, then avoid/reduce/transfer/accept based on severity, cost of the response and risk appetite.

Behavioural questions
Tell me about a time you identified and managed a project risk.+

Use STAR: how you spotted it, assessed probability/impact, chose a response and owner, and the outcome you protected.

Real-world scenarios
“A key supplier might miss a delivery date your project depends on.”+

Expected answer: Log it as a risk and dependency, assess impact, mitigate (add buffer/alternative supplier), assign an owner and monitor it in the RAID log.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
Project ManagerPMO AnalystProgramme Manager
Skills you're proving
Risk managementRAID logRisk registerContingency
Recommended certifications
PRINCE2 FoundationProfessional Scrum Master (PSM I)
Career progression

Essential for all PM, PMO and programme roles.

What employers expect

That you can apply recognised delivery frameworks to real projects, manage risk and stakeholders, and deliver outcomes on time and to budget.

Frequently asked questions

What does RAID stand for?

Risks, Assumptions, Issues and Dependencies — the four lists a project manager tracks to control delivery.

How do you prioritise risks?

Score each by probability × impact to get a risk score, then focus responses on the highest-scoring risks.

What are the risk response strategies?

Avoid, Reduce (mitigate), Transfer or Accept (usually with contingency) for threats; Exploit, Enhance, Share or Accept for opportunities.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.