Every quantity surveyor has sat through a project meeting where someone says the words "we need a risk register" - and then nothing happens for three weeks. Knowing what a risk register is supposed to do isn't the same as knowing how to actually build one, populate it with real risks, and keep it alive once the project gets busy.

This is the practical, step-by-step half of the conversation. If you want the theory - what a risk register is, why it matters, and how it fits into wider project controls - read our companion piece, What Is a Risk Register? A Construction QS Guide, first. This article picks up exactly where that one leaves off.

Below is a numbered build process you can run on any construction project, from a £500k fit-out to a £50m infrastructure scheme: how to run the identification workshop, score probability and impact consistently, prioritise what actually matters, assign named owners, build mitigation plans that survive contact with the programme, and set a review cadence that doesn't quietly die after month two.

By the end, you'll have a repeatable process you can drop into your next project kick-off meeting - not just a spreadsheet template, but the workshop script and scoring logic that makes the template mean something.

Quick Answer

To create a construction risk register: (1) run a risk identification workshop with the full project team, (2) capture and categorise every risk raised, (3) score each one for probability and impact on a 1-5 scale, (4) multiply the two scores to prioritise using a risk matrix, (5) assign a named owner to every risk, (6) write a specific mitigation and contingency plan for each one, and (7) set a fixed review cadence - typically fortnightly during construction - with clear escalation triggers for anything scoring above your threshold. The result is a live document, not a one-off exercise completed at tender stage and forgotten.

Step 1: Run a Risk Identification Workshop

Every proper risk register starts with a workshop, not a QS sitting alone with a blank spreadsheet. Risk workshops are widely regarded as the most reliable way to surface the full range of risks on a project, because no single person - however experienced - sees the whole picture. The site manager knows the ground conditions and access constraints. The design team knows where information is still outstanding. The subcontractors know where their own supply chains are fragile. Get them all in a room, or on a call, before you write a single line in the register.

Who to invite

  • Project manager or contracts manager (usually chairs the session)
  • Quantity surveyor or commercial manager (owns the register afterwards)
  • Site or construction manager
  • Design lead or lead consultant
  • Key subcontractor or supply chain representatives
  • Client representative, where appropriate for major risks

How to structure the session

Work through risk categories one at a time rather than asking an open "what could go wrong?" question, which tends to produce a short, obvious list. Categories worth working through include design, ground conditions, programme, commercial and cost, health and safety, supply chain, statutory and planning, and stakeholder or reputational risk. Ask each attendee to write risks down individually first - a short silent brainstorm - before opening up group discussion. This stops the loudest voice in the room dominating the list and surfaces risks that a quieter subcontractor representative might otherwise sit on. Capture everything raised at this stage, even risks that sound minor or unlikely; you'll filter and score them in the next two steps, not now.

Construction project team taking part in a risk identification workshop

Step 2: Capture and Categorise Every Risk

A workshop full of good risks is wasted if they're written down badly. "Weather" is not a usable risk entry - it doesn't tell anyone what might happen or why it matters. Write each entry in a cause-risk-effect format: because of [cause], [risk event] may occur, which would result in [effect on cost, time or quality]. For example: "Because the piling subcontractor has not confirmed ground investigation results, there is a risk that unforeseen ground conditions require a revised piling design, which would result in programme delay and additional cost."

Assign a category to every risk

Categorising risks makes the register easier to scan, easier to hand to a specific discipline lead, and easier to spot patterns in - if half your red risks sit in one category, that's a signal in itself. The table below shows the categories most construction risk registers use, with a typical owner for each.

Table 01 / Risk categories

Common construction risk categories and typical owners

CategoryExample riskTypical owner
DesignIncomplete information at tender stageDesign lead
Ground conditionsUnforeseen ground conditions affecting foundationsSite manager
ProgrammeCritical path delay from late subcontractor mobilisationPlanner / project manager
CommercialUnder-recovery of preliminaries on an extended programmeQuantity surveyor
Health & safetyWorking at height on an unprotected edgeSite manager / H&S advisor
Supply chainSingle-source material with a long lead timeProcurement / buyer
Statutory & planningPlanning condition discharge delayedProject manager
StakeholderLocal resident objection to working hoursClient / project manager

Categories adapted from RICS Management of Risk guidance and common industry risk register templates.

Resist the temptation to merge similar risks into one broad entry. Two risks that share a cause but have different effects - say, a permit delay that affects both the programme and a specific work package - are easier to manage, score and close out as separate lines than as one blended entry that nobody quite owns.

Step 3: Score Probability and Impact

Once every risk is written down and categorised, score it twice: once for how likely it is to happen (probability), and once for how bad it would be if it did (impact). Most construction risk registers use a 1-5 scale for each, which keeps scoring fast and consistent across a large list of risks without pretending to a precision the process doesn't really have.

The probability scale

  • 1 - Rare: unlikely to occur on this project
  • 2 - Unlikely: could occur but not expected
  • 3 - Possible: a reasonable chance of occurring
  • 4 - Likely: more likely than not to occur
  • 5 - Almost certain: expected to occur, possibly more than once

The impact scale

Impact needs defining in terms your project actually cares about - usually cost and programme, sometimes quality, safety or reputation too. Rather than leaving "catastrophic" to interpretation, put numbers against each level: for example, impact 5 might mean over four weeks' critical path delay or over £250,000 of cost, while impact 1 might mean under one week and under £10,000. Agree these thresholds with the project team before scoring starts, not risk by risk, or you'll get wildly inconsistent scores from different contributors.

Multiply probability by impact and you get a risk score from 1 to 25. This single number is what lets you compare a low-probability, high-impact risk - a major design error, say - against a high-probability, low-impact one, such as a recurring minor delivery delay, on the same scale, and rank the whole register in order.

Graphic 01 / Risk scoring

Probability × impact matrix (5×5 scoring grid)

Impact 1Impact 2Impact 3Impact 4Impact 5
Probability 5510152025
Probability 448121620
Probability 33691215
Probability 2246810
Probability 112345
Low (1-4) Medium (5-12) High (15-25)
Anything scoring 15 or above sits in the red zone - it needs a documented mitigation plan, a named owner and active monitoring at every review, not just a note in the register.

Source: APM project risk analysis guidance and common 5×5 construction risk matrices.

Step 4: Prioritise Risks Using the Risk Matrix

With every risk scored, sort the register by risk score, highest first. This is the point where a long list of risks turns into a manageable action plan, because it tells you exactly where to spend your limited time and management attention. Most projects group scores into three or four bands rather than working risk-by-risk down all 25 possible values.

  • Score 1-6 (low): monitor only - no active mitigation plan required, review at each register update
  • Score 7-11 (medium-low): assign an owner, note a simple mitigation approach, review monthly
  • Score 12-15 (medium-high): requires a documented mitigation plan and more frequent review
  • Score 16-25 (high / red): requires an immediate mitigation plan, a named owner, escalation to senior management, and weekly review as a minimum

Resist two common mistakes at this stage. The first is spending workshop time debating the difference between a score of 8 and a score of 9 - the scale is a prioritisation tool, not a precision instrument, so don't over-engineer it. The second is ignoring everything below the top band. A cluster of low-scoring risks in the same category can add up to a real problem even if no single one crosses your threshold alone, so scan for patterns as well as reading the top of the list.

Step 5: Assign a Named Risk Owner

Every risk in the register needs one named individual attached to it - not "the design team" or "the subcontractor", but a specific person who is accountable for managing that risk. This is one of the most commonly skipped steps, and it's the single biggest reason risk registers stop working: a risk with no owner is a risk nobody actually manages, however well it was scored in the workshop.

What the owner is responsible for

  • Monitoring the risk between reviews and flagging any change in status
  • Implementing the agreed mitigation actions on time
  • Reporting progress at each risk register review
  • Escalating early if the mitigation isn't working
  • Recommending when the risk can be closed or downgraded

Choose the owner based on who has the authority and information to actually act on the risk, not simply who raised it in the workshop. A programme risk sitting with a subcontractor's site foreman with no budget authority will stall; the same risk sitting with the project manager, with the foreman feeding them information, is far more likely to move.

Site manager reviewing risk register documentation on site

Step 6: Build Mitigation and Contingency Plans

A risk score without an action plan is just a well-organised list of problems. For every risk above your low-risk threshold, write down what you're actually going to do about it - and be specific enough that someone other than the person who wrote it could pick it up and act on it.

Four ways to respond to a risk

  • Avoid - change the approach so the risk no longer applies, e.g. re-sequence work to avoid a weather-exposed activity
  • Reduce - take action to lower probability or impact, e.g. commission a ground investigation to reduce design uncertainty
  • Transfer - shift the risk to another party better placed to manage it, e.g. insurance, or a back-to-back subcontract clause
  • Accept - acknowledge the risk and hold contingency for it, appropriate for low-scoring or genuinely unavoidable risks

For higher-scoring risks, link the mitigation plan to a cost and time contingency figure where possible - not a single blended contingency sum across the whole project, but a figure attached to the specific risk it covers. This is what turns the risk register from a qualitative list into something that actually informs your cost report and your client's contingency drawdown. Set a target date for each mitigation action, not just an owner, so "in progress" can't sit unchanged for six months.

Construction team discussing mitigation plans on site

Step 7: Set Your Review Cadence and Escalation Triggers

A risk register that's updated once at the start of a project and never touched again isn't a risk register - it's an archive. Build the review cadence into the programme from day one, the same way you'd programme a valuation date or a progress meeting.

How often to review

  • Weekly during high-risk phases, e.g. substructure or complex M&E commissioning
  • Fortnightly as standard practice during active construction
  • Monthly during lower-risk, steady-state phases
  • Immediately after any incident, near-miss, or major change in scope or programme

Escalation triggers

Agree upfront what triggers escalation beyond the routine review - typically, any risk crossing into your red band (15+), any owner missing a mitigation action date without explanation, or any newly identified risk that scores in the red band on first assessment. Escalation usually means the risk moves from the project-level review to a client or senior management steering group, with a clear ask: a decision, funding, or a resource the project team can't provide itself.

Close risks formally rather than letting them quietly disappear from the list - record the date closed and why (mitigated, risk period passed, or occurred and was managed). A register with a visible closed-risk history is far more credible at audit or dispute than one that only ever grows.

Table 02 / Build checklist

Risk register build process at a glance

StepKey outputTypical owner
1. Identification workshopFull list of raised risksProject manager
2. Categorise & describeCause-risk-effect entries by categoryQuantity surveyor
3. Score probability & impact1-5 scores, risk score 1-25Project team
4. PrioritiseRanked register by score bandQuantity surveyor
5. Assign ownersOne named owner per riskProject manager
6. Mitigation & contingencySpecific action, date and contingency figureRisk owner
7. Review & escalateFixed review cadence, escalation triggers agreedProject manager / QS

Cadence and escalation thresholds should be agreed at project set-up and recorded in the project execution plan.

Project team reviewing risk register updates in a site office meeting

Frequently Asked Questions

What's the difference between a risk register and a risk assessment on a construction project?

A risk assessment is typically a method statement-level document focused on health and safety hazards for a specific task or activity. A risk register is a broader, project-wide commercial and delivery tool covering cost, programme, design, supply chain and stakeholder risks, in addition to safety. Most projects need both - they serve different audiences and purposes, though a serious safety risk should also appear on the register if it could affect cost or programme.

How often should you update a construction risk register?

As a general rule, fortnightly during active construction, weekly during particularly high-risk phases like substructure or complex installations, and monthly during quieter periods. Update it immediately after any incident, near-miss, or significant change in scope, design or programme, rather than waiting for the next scheduled review.

Who should own the risk register on a construction project?

The project manager or commercial manager/QS typically holds overall ownership of the register as a document, chairing reviews and keeping it current. Individual risks within it are then assigned to named owners - who may sit anywhere on the project team - based on who has the authority to actually manage that specific risk.

How do you score probability and impact on a construction risk register?

Score each separately on a 1-5 scale, then multiply them to get a risk score from 1 to 25. Probability runs from rare (1) to almost certain (5); impact runs from insignificant (1) to catastrophic (5), ideally defined against real cost and programme thresholds agreed by the project team before scoring begins.

What software do QSs use to manage a risk register?

Many projects still run a well-structured Excel or Google Sheets register, which works fine for smaller projects with disciplined review habits. Larger or more complex projects often use dedicated risk management modules within project controls software, or standalone tools, which add automated scoring, audit trails and reporting dashboards.

How many risks should a typical construction risk register contain?

There's no fixed number - it depends on project complexity. A straightforward fit-out might run to 15-25 risks; a complex infrastructure project can run into the hundreds. What matters more than the total count is that the top 10-15 highest-scoring risks all have a named owner, a specific mitigation plan and a realistic review date.

Should low-scoring risks be removed from the register?

Not immediately. Keep them visible but move active management attention to higher-scoring risks. Low scores can change quickly if circumstances shift, and a visible low-risk section also shows a client or auditor that the register reflects genuine risk assessment rather than a curated list of only the risks the team wants to highlight.

Final Thoughts

Building a risk register is less about the spreadsheet and more about the discipline behind it: a proper workshop, honest scoring, named ownership and a review cadence that actually happens. Skip any one of those steps and the document quietly becomes decoration rather than a working tool.

If you're building your first register, don't aim for perfection at launch. Run the workshop, score what you've got, assign owners, and improve the detail at each subsequent review - a live register that's 80% right and gets reviewed every fortnight will outperform a beautifully detailed one that's opened once at tender stage and never again.

For the underlying theory and terminology - and how a risk register fits alongside wider project risk management - see our companion guide, What Is a Risk Register? A Construction QS Guide.

Want the full picture? Want the full risk management picture?

This guide covers the build process step by step. For the underlying theory, read What Is a Risk Register? A Construction QS Guide, and for how risk feeds into your commercial reporting, see our guides on Cost Value Reconciliation (CVR) and Construction Cash Flow Forecasting.