TOOLS & ARTIFACTS · LESSON 04.01intermediate

Risk Register — deep dive.

Beyond P×I: residual risk, contingency reserves, secondary risks.

↳ tl;dr

Foundations covered the basics. This lesson goes deeper: residual risk (what's left after your response), secondary risks (new risks your response creates), and contingency reserves(the budget / time you set aside for risks that occur).

Residual risk

Even after mitigation, some risk remains. That remaining risk is residual. Document it explicitly — sponsors need to know mitigation reduced the risk, not eliminated it. "Mitigated to 30% probability with $X spent" is honest; "mitigated" alone is misleading.

Secondary risks

Your response can create new risks. Hiring a backup vendor to mitigate vendor failure introduces a new risk: vendor coordination overhead. Outsourcing security review reduces compliance risk but introduces dependency on the auditor's timeline. Track secondary risks in the same register — they're first-class risks now.

contingency vs management reserve

Contingency reserve covers identifiedrisks (you knew this might happen). Management reserve covers unknown unknowns (you don't know what you don't know). Both are part of the budget. Senior PMs negotiate for both; junior PMs often get neither.

Risk-adjusted estimates

Expected Monetary Value (EMV) = probability × impact (in dollars). Sum across all risks for the contingency reserve target. A 30% chance of a $100K hit = $30K reserved. Not all risks need this calc — apply to high-impact items where the number actually informs the decision.

// practice this

Practice in the Risk Register lab

The Risk Register tool lab tests these concepts in scenarios — score residual risk, allocate contingency, and defend the reserve number to a sponsor.

// sources

Sources cited

  1. [01]
    A Guide to the Project Management Body of Knowledge (PMBOK Guide), 7th Edition

    Project Management Institute (PMI) · 2021 · retrieved 2026-04

    PMI's flagship reference. 7e shifted from process groups to performance domains.

// sources

Further reading

  1. [01]
    A Guide to the Project Management Body of Knowledge (PMBOK Guide), 7th Edition

    Project Management Institute (PMI) · 2021 · retrieved 2026-04

    PMI's flagship reference. 7e shifted from process groups to performance domains.