Consulting Engagement Risk Register Template
Three documents and two sheets that trace every register row to something your own intake pass already found, not a generic risk list.
Free download · No account needed
Risk Register · how to read one row
Five cells, and the rule that keeps the first one honest
| Column | What it has to name |
|---|---|
| Source Ref | A specific request, Coverage Map row or log entry, never a category |
| Lens | Data quality, sponsor engagement or decision culture, read off that same source |
| Owner | Exactly one named person, never a function or a team |
| Trigger | An observable event, stated as a number or a date, never a vague sense of trouble |
| Status | Open until the source itself resolves, not until a milestone simply passes |
A row with no Source Ref does not go on the register. It goes back to intake as an open question instead.
Every project risk register template on page one ships the same five columns: ID, category, description, likelihood, impact. Fill it from a brainstorm, one guess per standard category, scope risk, budget risk, resource risk, and it is done in twenty minutes. One competing checklist says outright how it expects you to source the risks: pull them from team brainstorms, data from past projects, and stakeholder input. None of that traces to this specific engagement, which is why a register built that way has nothing real to check against later.
This pack works from the opposite direction. Every register row names a Source Ref that resolves to something the intake pass already produced: a request still open past its agreed date, a Coverage Map question still Partial or Contested, a pattern in who actually answers. PMI's Lexicon of Project Management Terms defines a trigger condition as an event that indicates a risk is about to occur, which only works when the row is watching something concrete. A category label like scope risk has nothing to trigger against.
Osprey Fenn Advisory ran intake this way on a plant-cost review for Marlstone Foods. Ten requests closed with an average of 1.4 chases each, but two sat on a third or fourth chase with no substantive answer. The Coverage Map showed 7 of 12 engagement questions still Partial, Contested or None, 58 percent. That produced six register rows, not six categories. One tracked the chase pattern itself, one flagged a delegate answering for the named sponsor, and four traced to specific Coverage Map questions, one of which had no coverage at all.
What's in the pack
Risk Register
Every row keyed to a Source Ref from the Gap and Request List or Coverage Map intake already produced, never a category with nothing behind it.
Early Warning Indicators
A baseline and a fire threshold for every risk whose evidence is a number that moves, recomputed on a weekly cadence rather than read once and left stale.
Risk Note
The internal record of every judgment call: what intake found and did not become a risk, and what a High versus a Medium actually means on this register.
Mitigation Plan
One section per open row, a dated action and a named owner, closed rather than deleted once the risk it tracks actually resolves.
Client-facing Summary
The one-page rewrite for the sponsor: what could slow the engagement down as a fact about the work, with a dated ask wherever a row needs the approver a kickoff already named, not a delegate.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and send what an intake pass already found, or download the Word documents and CSV sheets and fill them in yourself.
- 2
Read the intake findings first
River reads the Gap and Request List, the Coverage Map and the Assumption Log before writing a single row, and drops any candidate with no real source.
- 3
Trace each row to its source
One lens at a time: data quality from the coverage gaps, sponsor engagement from who actually answers, decision culture from the chase counts already logged.
- 4
Let the automation recheck it
A scheduled run rechecks every Early Warning Indicator against its own linked source each week, so a crossed threshold surfaces between milestones instead of at the next one.
Frequently asked questions
Is this template free?
Yes. The zip is Word documents and CSV sheets, no account and no card needed. Edit with AI is the other branch: it creates a free River account, installs this pack as a private Space, and starts tracing register rows from whatever intake material you send.
What format are the downloaded files?
Each document downloads as a .docx file and each sheet as .csv, so all five open directly in Word, Pages, Google Docs, Excel, Numbers or Sheets without a conversion step. Append ?format=pdf to the download link if you want the documents as PDF instead.
How is this different from a standard project risk register template?
A standard template gives you five columns and a category list, scope risk, budget risk, resource risk, and expects you to brainstorm what goes in each. This pack requires a Source Ref on every row that resolves to a specific item an intake pass already produced, so a category with no real evidence behind it never reaches the sheet at all.
Why does the Early Warning Indicators sheet need its own automation?
Because a lagging measure like a missed date only moves after the damage is done. COSO's Enterprise Risk Management framework distinguishes that from a leading indicator, which signals a developing risk before results already reflect it, and this pack's automation recomputes each reading weekly.
What if intake found nothing for one of the three lenses?
Then that lens stays empty, and the Risk Note says so directly. Data quality, sponsor engagement and decision culture are the shapes intake signals most often take, not a quota every register has to fill with something regardless of whether the evidence supports it.
How is this different from the engagement status report?
The status report is the recurring, sponsor-facing cadence artifact with its own derived color status. This register is the standing record of what could derail the engagement, set at intake and rechecked on its own slower cycle, and a register row can inform a status update without the two ever merging.
Can I use this without a completed intake pass?
Yes, with a caveat the Risk Note states up front. The register gets built from whatever material you have sent so far, not a finished pass, and it should be revisited once a real Coverage Map and Gap and Request List exist to trace rows against.
Trace the risk before you write it
Take the Word documents and CSV sheets blank, or send River your intake findings and get a Risk Register that names its sources instead of its categories.
Edit with AI