top of page

Nobody Was Ever Promoted for a Risk Register

Somewhere in your organisation there is a spreadsheet.


It has a RAG column that has been amber since 2023. It has an owner, in the sense that somebody's name is in a cell and that person left in March. It gets reviewed quarterly, in the sense that it appears on an agenda, somebody says "any changes?", everybody looks at their laptop, and the meeting moves on to parking.


A dumpster on fire in a dark alley, burning unattended at night.
The risk was on the register. It was amber. Everyone had seen it.

That spreadsheet is your risk register. It is the document your organisation would point to if anything ever went badly wrong, as evidence that you were being sensible about it.


I spent most of August reading about risk, because I was writing a short practical course on it for people who end up owning the register without ever having been trained to. What I found instead is that almost nobody has checked whether any of it works.


Not that the evidence is mixed. Not that it is contested. There is barely any peer-reviewed research on risk registers at all. For a document sitting at the centre of governance in most organisations, that is roughly the situation you would be in if it turned out nobody had ever tested a seatbelt.


So the practical part of that course now opens by admitting it. That is a strange way to begin a session on how to do something, and I would do it again, because the alternative is dressing practice up as proof and hoping nobody checks.



What you will get out of this


  • Why your risk register is not doing the job you think it is doing

  • The one category of intervention that does have hard evidence behind it, from operating theatres and intensive care

  • The pre-mortem statistic that everybody quotes and nobody has read

  • A script for running a pre-mortem properly, with timings, that needs no authority you do not already have

  • The three places organisational risk genuinely lives, none of which is a spreadsheet

  • A register format that produces decisions instead of arguments about whether something is a three or a four

  • A free one-page template to print and use on Monday



Why risk registers do not work


The problem is not that the people filling it in are careless. It is structural, and once you see it you cannot unsee it.


A register records risk that has already been identified, already been agreed, and already been made acceptable to say out loud in front of colleagues. Three filters have run before a single word reaches the spreadsheet.


Somebody had to notice it. Somebody had to judge it worth raising. And somebody had to conclude that raising it would not cost them anything.


Everything expensive happens upstream of all three, and the register has no mechanism whatsoever for reaching upstream. It is a very tidy record of the risks nobody was afraid to mention.


There is a second problem, which is that the register asks you to score things. Likelihood multiplied by impact, on a scale of one to five, producing a number between one and twenty-five that feels enormously more precise than the two guesses that went into it.


I have sat in the meeting where two intelligent adults spend eleven minutes arguing about whether something is a three or a four. That argument feels like rigour. It is the least productive quarter of an hour in corporate life, and at the end of it the number still means nothing, because multiplying two estimates does not produce an estimate, it produces a decoration.




What the evidence is actually about


The good news is that the wider category a register belongs to has been studied properly, in places where you can measure the outcome because people either survive or they do not.


Haynes and colleagues introduced a nineteen-item surgical safety checklist across eight hospitals in eight countries, in health systems ranging from extremely well resourced to barely resourced at all. Death rates and complication rates fell in every one of them. Pronovost and colleagues did something structurally similar in intensive care with a five-step checklist for inserting a central line, and catheter-related bloodstream infections dropped to near zero and stayed there for the whole eighteen months they kept watching.


Now the part that matters for you.


Both of those checklists were made entirely of things every clinician in the room already knew. Wash your hands. Confirm the patient's name. Say out loud what you expect to be difficult. Nobody learned a single new fact. The surgeons were not, prior to 2009, unaware of handwashing.


The mechanism was the requirement, not the knowledge.


That draws a hard line through most of what gets called risk management. A document that lives in a folder is a document. A procedure that has to be completed before the meeting can move on is an intervention. Nothing about the quality of the thinking separates them, and no amount of improving the thinking will convert one into the other.


I want to be honest about how far that carries. The surgical literature does not prove your project tracker works. It shows that a class of intervention can work when it is short, compulsory, and attached to a moment of action. That is practice informed by evidence, which is a different animal from evidence about registers, and I say so out loud before I teach any of it.



The uncomfortable claim underneath all of this


Every build like this needs one claim at the centre where the evidence contradicts the received wisdom. Without it you end up gathering papers about a topic instead of papers that answer a question, and you never know when to stop reading.


For risk it turned out to be this. You cannot debias yourself by trying harder.


Morewedge and colleagues reviewed the debiasing literature and found that early attempts to reduce decision bias through training largely failed, which is precisely why the field gave up and moved towards changing incentives and the way choices are presented instead. Their own longitudinal experiments then did find real effects from training, but the training in question was structured practice with feedback, not a slide listing cognitive biases.


Awareness does almost nothing. Structured practice does a great deal.


Which means every session where somebody puts a list of biases on a screen and the room nods knowingly at confirmation bias is, in terms of anybody's actual future decisions, entertainment. Pleasant entertainment. Recognition feels like progress, in the same way that reading a book about running feels briefly like exercise.


It is also why "we should all be more risk aware" is such a comfortable thing for a leadership team to conclude at the end of a difficult conversation. It sounds like a decision. It commits nobody to anything, costs nothing, and can be agreed unanimously in under a minute.



The technique that works, and the number attached to it that does not


You have met the pre-mortem. Gather the team before the work starts, tell them to imagine it is a year from now and the project has failed catastrophically, and ask them to write down why.


The technique holds up beautifully. The statistic everybody teaches alongside it does not.


The claim is that a pre-mortem generates thirty per cent more reasons than ordinary forecasting. It is in the books, the training decks, and roughly nine hundred LinkedIn posts. It traces back to a 1989 paper by Mitchell, Russo and Pennington.


I opened that paper fully intending to cite it, the way you open the fridge fully intending to find something for dinner. What is in there is not what everybody says is in there. The temporal perspective, the imagining-yourself-forward part that the entire technique is named after, had no effect at all. What mattered was certainty. Being told the outcome had definitely happened, rather than might happen.


That is not a pedantic footnote. It changes how you run the exercise, and it explains why so many pre-mortems produce a thin, polite list of things everybody already knew and nobody was worried about.


The number I use instead comes from Veinott, Klein and Wiggins, who went to the trouble of actually evaluating the technique against alternatives. The pre-mortem cut plan confidence by 25 points. Listing pros and cons managed fourteen. Listing cons alone managed 12.4. General critique moved almost nothing at all.


Read that ordering slowly, because it is genuinely counterintuitive. Inviting people to criticise a plan barely dented their confidence in it. Telling them the plan had already failed took a quarter off. Same people, same plan, different sentence.


Bar chart of reduction in plan confidence: pre-mortem 25 points, listing pros and cons 14, listing cons only 12.4, general critique almost nothing.
Asking a room to criticise a plan barely dented its confidence. Telling the room it had already failed took a quarter off.

Underneath it sits a much older idea that has been tested far more thoroughly. Lord, Lepper and Preston showed in 1984 that instructing people to consider the opposite corrects biased judgement in a way that asking them to be fair does not. The pre-mortem is one costume worn by a very robust principle, which is why it survives being taught badly by people who have never read the paper.



How to run a pre-mortem properly


This is the section to print out.


  1. Do it before the plan is approved, not after. Once a plan has been signed off, a pre-mortem becomes a loyalty test and everybody in the room understands that immediately.

  2. Get the instruction right. Not "what are the risks", which produces a list nobody believes. Say this, in these words: it is nine months from now, this project has failed publicly and expensively, and we are all sitting in the post-mortem. Write down why.

  3. Everybody writes before anybody speaks. Four minutes, silent, on paper or in a shared document with the names hidden. This is the single most important mechanical detail in the whole exercise. The moment the most senior person in the room speaks first, the range of acceptable answers narrows and you have quietly converted a pre-mortem into a consultation.

  4. Collect in reverse seniority. Most junior person reads their list first. If you are running it without formal authority, this is easy to introduce because it sounds like good facilitation. It is also a direct intervention in the hierarchy. Both things are true and only one of them needs saying out loud.

  5. Solve nothing in the room. The urge to fix the first plausible risk will eat the entire session and you will never hear items seven through fifteen. Capture, then triage afterwards.

  6. Give it thirty-five minutes. Four to write, fifteen to collect, ten to sort, five to agree who owns what and when it comes back.


Six-step pre-mortem script with timings: run it before approval, get the instruction right, everybody writes first, collect in reverse seniority, solve nothing in the room, agree owners.
Thirty-five minutes. The instruction is the active ingredient, and most people get it wrong.

That is the whole intervention. One meeting slot, no budget, no permission required.



Where the risk actually sits


Three blind spots not captured by a risk register: your own estimates, the near miss you filed as a win, and the sentence nobody said.
None of these will ever show up in a scoring matrix.

Three places. None of them is the spreadsheet.


One. Your own estimates, which are wrong in a predictable direction


Buehler, Griffin and Ross named the planning fallacy in 1994 and it has survived three decades of attempts to knock it over. People privilege the inside view of their own particular plan over the outside view of what usually happens to plans like it.


The genuinely uncomfortable part is that experience does not fix it. You have been late before. You do not adjust. You produce the same optimistic number with the same confidence, having personally lived through the last four occasions it was wrong.


One practical wrinkle comes from Wiese, Buehler and Griffin. Planning backwards from the deadline rather than forwards from today changes the estimate you produce, and produces a better one. It costs nothing and it is faintly irritating how well it works, which is why it became the interactive tool for Module 1.


Try it on something real this week. Take a piece of work with a fixed date and, instead of listing what you will do first, second and third, start at the deadline and ask what must already be true the day before. Then the week before. Most people find a dependency they had not costed, and it usually belongs to somebody who has not yet been told they are on the critical path.


Flyvbjerg adds the dimension nobody enjoys discussing at work. Some of what looks like optimism is not optimism at all. It is strategic misrepresentation, which is the polite research term for telling a funder what the funder needs to hear in order to approve the thing. If you have ever watched a timeline get shorter between the draft and the board pack, without anything about the actual work changing, you have seen it happen in front of you.


Two. The near miss you quietly filed as a win


Dillon and Tinsley have been working on this for well over a decade and the finding is consistent across everything they have looked at.


When something almost goes wrong and then does not, people do not become more cautious. They become more confident. In their work with NASA employees, near misses were rated as successes. The event that should have functioned as a warning gets logged as evidence that the system is robust, and the next decision is taken from a higher base of confidence than the facts actually support.


This one has an easy fix and almost nobody does it. Change one question in your review meetings. Instead of asking whether anything went wrong, ask what nearly went wrong, what saved us, and whether that was a control or a coincidence.


The third part is the whole point. If the answer is that somebody happened to check their email at eleven at night, or the client happened to be on holiday, or a particular person happened to notice something on a screen they were not supposed to be looking at, you do not have a control. You have luck, and luck does not scale, cannot be delegated, and takes annual leave.


Three. The sentence nobody said


Here is where you have the most leverage and, on paper, the least authority.


Most missed risks were not missed. Somebody saw it and said nothing, which is why the first two are worth very little on their own.


Morrison and Milliken described organisational silence as a property of the organisation rather than a failing in particular people. That is both a relief and considerably more useful, because structural problems have structural handles, whereas personal failings mostly generate shame and a resolution to be braver next time that lasts until roughly Wednesday.


Detert and Edmondson went further with implicit voice theories. People self-censor according to rules that nobody ever taught them, the rules are mostly broader than reality, and they operate below the level where the person can inspect them. They do not feel like fear. They feel like professionalism. And they never get tested, because obeying one means you never find out what would have happened.


Edmondson's work in operating theatres maps onto the executive office uncomfortably well. Hierarchy, deep expertise, high stakes, and a completely reliable pattern of who speaks and who does not. What predicted whether a surgical team successfully adopted a difficult new technique was not the technical skill in the room. It was whether the team leader made it possible for a junior person to say that something was wrong.


And the standard fix makes things slightly worse. Nemeth found that appointed devil's advocates underperform authentic dissent, because the room correctly reads assigned criticism as a performance. Having heard the objections voiced by somebody who does not mean them, everybody relaxes their own scepticism. So if you have ever been asked to "play devil's advocate for a minute", you were being handed a job the evidence says does not work, in front of people who had already discounted it.



The exercise I would do first


Next time you decide not to raise something, write down the rule you are obeying. Make it a full sentence, in the second person, as though somebody had once taught it to you.


You do not question the finance numbers in front of the board.


You do not go back to a decision the chief executive has already announced.


You do not raise a resourcing problem in the same meeting as a budget conversation.


You do not put anything in writing that a client could conceivably be shown.


Then look at it in daylight. Written down, it usually turns out to be narrower than you were treating it, or true of one particular person rather than the whole organisation, or inherited from a room you were in four years ago and have not worked in since.


That is the entire discipline in miniature. Not more courage, which nobody can supply on demand at four o'clock on a Thursday. Better inspection of the rules you are already obeying without noticing.



A risk register that produces decisions


Two changes, and they are the substance of Module 5.


Drop likelihood multiplied by impact. Sort into three columns instead.


Column

What it means

What has to be written down

Watch

We are not acting yet

The specific signal that would move it to Act, and who is watching for it

Act

Somebody owns this

A named action, an owner, and a date. Not "monitor closely"

Accept

We know and we are spending nothing

Why, plus who accepted it and when


Three-column risk register format showing Watch, Act and Accept, with what each column requires.
Three columns. No scoring matrix. No arguing about whether it is a three or a four.


Anybody in the room can make that call without a scoring matrix, and it is the decision the register exists to produce. The Accept column is the one that changes the culture, because it forces a named human to own a decision that is currently hiding inside an amber cell where it cannot be attributed to anyone.


Then make something compulsory. One question that has to be answered before the meeting can move on. What nearly went wrong since we last met, and was that a control or luck.


Short, mandatory, attached to a moment of action. That is the surgical checklist logic applied to a room you actually sit in on a Tuesday.



Download: The One-Page Risk Register


Everything above, on two sides of A4, designed to be printed and taken into the meeting rather than filled in afterwards.


What is inside

Why it is there

A three-column register: watch, act and accept

Because sorting is a decision anybody can make and scoring out of twenty-five is an argument nobody can win

The standing near-miss question, with space to log it

Because the near miss you celebrated is the warning you did not hear

A five-step pre-mortem script with timings

Because the instruction is the active ingredient, and most people get it wrong

Space to capture what your own pre-mortem found

Because a list nobody wrote down is a conversation, not a control



It is free, there is no email wall, and you do not have to give me anything for it. Print it, use it, and throw it away when it stops being true.



If you do not run the meeting


Most people reading this are not chairing the governance meeting. You are building the pack for it, which turns out to be a considerably better position than it sounds.


Your leverage sits in the agenda and the template rather than in the discussion, and nobody guards those.


Add the near-miss question as a standing agenda item and nobody will object, because it sounds like diligence. Rebuild the register with watch, act and accept columns and circulate it as a formatting improvement. Put the pre-mortem into the project kick-off template so it happens by default rather than by request. Move the risks in the pre-read so they appear before the progress update rather than after it, which is the entire difference between a live conversation and a closing formality that everybody is reading on their phone.


None of that requires permission. All of it changes what the room is required to do.



Frequently asked questions


Should we keep the risk register at all?

Yes. It has genuine governance value, auditors will ask for it, and it creates a written record of who accepted what. The mistake is believing that maintaining it is the same thing as managing risk. Keep the document, and add a mechanism.

Keep the required format for the regulator and run the watch, act and accept version as the working document. The regulated artefact and the decision-making tool do not have to be the same file, and in most organisations they probably should not be.

Reframe it as a delivery risk session rather than a challenge to the decision. The instruction stays exactly the same. You are not asking whether we should do this, you are asking what will have gone wrong in nine months.

Put the question in the calendar invitation and ask them to arrive with three answers. You lose a little of the effect and keep almost all of it, and nobody has to be told to be quiet.

More, not less. Small organisations have fewer formal controls, which means a much larger share of their risk management consists of one person deciding whether to say something out loud.

Multiplying two guesses does not produce a better estimate, it produces false precision. In practice the score becomes the subject of the meeting, and the conversation about what to actually do never happens.

The figure is not what the 1989 paper found. Its actual finding was that certainty mattered and temporal perspective did not. Use the Veinott evaluation instead, where the pre-mortem cut plan confidence by twenty-five points against fourteen for listing pros and cons.



Where to start


Pick one thing. The near-miss question is the cheapest and it changes the temperature of a review meeting within two cycles.


Judgement under pressure is one of the five dimensions measured in the Connected Leader Assessment. It is free, it takes about twelve minutes, and it is built on 139 peer-reviewed papers rather than a personality theory, so it will tell you whether this is your strong suit or your blind spot before you go redesigning anybody's governance.


If you would rather work the whole territory properly, with the interactive tools and the worked examples, that is what our Skill Sprints are for. One topic, built properly, an hour or two, and you come out having made something rather than having been talked at.


And if your register has been amber since 2023, you already know which column it belongs in.


Meg ✌️


Free tools





P.S. Want to Go Deeper on Risk and Judgement?


If this resonated and you want to go further, here is the evidence the piece is built on. These are the papers that shaped my thinking on risk, judgement and why a register so rarely changes a decision, and they are well worth your time.


Every DOI below has been checked. Where a popular claim did not survive that check, I have said so in the piece rather than quietly leaving it out.


📃 Mitchell, Russo and Pennington (1989) The original pre-mortem study and the source of the misquoted statistic. Temporal perspective had no effect; certainty did. https://doi.org/10.1002/bdm.3960020103


📃 Veinott, Klein and Wiggins (2010) The evaluation of the pre-mortem against alternatives. Confidence dropped twenty-five points against fourteen for pros and cons. Open access via ISCRAM.


📃 Lord, Lepper and Preston (1984) Considering the opposite as a corrective strategy for biased judgement. https://doi.org/10.1037/0022-3514.47.6.1231


📃 Morewedge, Yoon, Scopelliti and colleagues (2015) What actually reduces decision bias. Awareness training largely failed; structured practice with feedback produced medium to large effects. https://doi.org/10.1177/2372732215600886


📃 Buehler, Griffin and Ross (1994) The paper that named the planning fallacy and showed experience does not correct it. https://doi.org/10.1037/0022-3514.67.3.366


📃 Wiese, Buehler and Griffin (2016) Backward planning from the deadline produces better completion estimates than forward planning. https://doi.org/10.1017/s1930297500007269


📃 Flyvbjerg (2006) Getting risks right in large projects, and the difference between honest optimism and strategic misrepresentation. https://doi.org/10.1177/875697280603700302


📃 Dillon and Tinsley (2008) How near misses increase rather than decrease risk-taking. https://doi.org/10.1287/mnsc.1080.0869


📃 Morrison and Milliken (2000) Organisational silence as a property of the organisation rather than of individuals. https://doi.org/10.2307/259200


📃 Detert and Edmondson (2011) Implicit voice theories: the taken-for-granted rules of self-censorship that people cannot articulate. https://doi.org/10.5465/amj.2011.61967925


📃 Edmondson (2003) Speaking up in the operating room, and how team leaders shape whether expertise reaches the conversation. https://doi.org/10.1111/1467-6486.00386


📃 Nemeth, Brown and Rogers (2001) Why assigned devil's advocates underperform authentic dissent. https://doi.org/10.1002/ejsp.58


📃 Vaughan (1999) The dark side of organisations, and the normalisation of deviance. https://doi.org/10.1146/annurev.soc.25.1.271


📃 Haynes and colleagues (2009) The surgical safety checklist trial across eight countries. https://doi.org/10.1056/NEJMsa0810119


📃 Pronovost and colleagues (2006) The central line checklist that took catheter-related infections in intensive care to near zero. https://doi.org/10.1056/NEJMoa061115



P.P.S. Why Do I Even Have the Nerve to Write This?


Fair question.


I am someone who has spent years working alongside remarkable executives, navigating chaos, translating vision into structure and figuring things out, sometimes beautifully and sometimes the very hard way. I have had the privilege of being the steady right hand to leaders who move fast, take risks and expect a lot. That environment has shaped me more than any classroom ever could.


I also happen to have an MBA, and I am studying psychology because people fascinate me. How we work. Why we disconnect. What actually holds us together when the pressure rises.


But really, none of that is the point.


I am here because I have lived the erosion and rebuilt from it. I have seen the cost of carrying too much and the relief that arrives when you finally stop disappearing inside your own competence.


So I share what I have learned in case it helps someone else. Take what is useful. Leave the rest. And remember this one truth that professionals like you often forget:


You are probably doing far better than you give yourself credit for.


Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
Post: Blog2_Post
bottom of page