BBRACKLEYProject Management
Project Risk Management: Best Practices That Move the Needle
Risk & Controls9 min read·18 July 2026

Project Risk Management: Best Practices That Move the Needle

Risk management has a compliance problem. On countless projects it has been reduced to a ritual: a register created at kickoff, populated with generic risks, reviewed cursorily at status meetings, and consulted seriously only after something has already gone wrong. This is not risk management; it is the appearance of it, and it offers no protection.

Real risk management is a continuous, disciplined process of identifying what could go wrong, understanding how likely and how damaging each threat is, and doing something deliberate about the ones that matter. The practices below separate risk management that reduces exposure from the version that merely records it.

Identify risks specifically, not generically

A register full of vague entries — "resource constraints", "scope creep", "supplier issues" — is nearly useless, because a risk you cannot picture concretely is a risk you cannot manage. Effective identification is specific: not "supplier issues" but "the long-lead switchgear order may slip beyond the installation window, delaying commissioning." A well-stated risk names the cause, the event, and the effect, and in doing so half-suggests its own response.

Assess with honesty about probability and impact

Every risk should be assessed for how likely it is and how damaging it would be, because the two together determine how much attention it deserves. The discipline here is honesty — the temptation to downplay probability on risks the team would rather not confront is strong and corrosive. A risk matrix that ranks threats by combined severity focuses limited effort on the genuine priorities rather than spreading it thinly across everything.

Assign ownership and real responses

A risk without an owner is a risk nobody is managing. Each significant threat should be assigned to a named individual accountable for watching it and driving its response. And the response must be a genuine action, not a hope.

  • Avoid — change the plan to remove the risk entirely.
  • Reduce — act to lower the probability or the impact.
  • Transfer — shift the risk to a party better placed to bear it, through insurance or contract.
  • Accept — consciously decide to live with the risk, with a contingency ready if it occurs.

Keep it alive

Risk profiles change constantly as a project progresses — old risks recede, new ones emerge, and the severity of existing ones shifts. Risk management that is not continuously revisited decays into a snapshot of concerns that are no longer current. A living discipline reviews risks regularly, retires those that have passed, and stays alert to the new threats every phase introduces. The register is a tool of that discipline, never a substitute for it.

A risk register is not risk management any more than a menu is a meal. The value is in the identifying, deciding, owning, and acting — done continuously.

Key takeaways

  • 1State risks specifically — cause, event, and effect — so they can actually be managed.
  • 2Assess probability and impact honestly to focus effort on genuine priorities.
  • 3Assign every significant risk an owner and a real response, not a hope.
  • 4Revisit risks continuously; a register reviewed once is already out of date.

Frequently asked questions

What is the difference between a risk and an issue?

A risk is a potential future event that may or may not occur; an issue is something that has already happened and must be dealt with. Good risk management aims to address risks before they become issues.

Should positive risks be managed too?

Yes. Opportunities — positive risks — deserve the same discipline as threats, with responses aimed at exploiting or enhancing them. Managing only downside risk leaves value on the table.

From insight to impact

Bring Brackley’s expertise to your own projects. Book a free consultation with a senior consultant and put this thinking to work.