Template · Management
Risk register with probability and impact scoring
Score each project risk by probability and impact, track its response and residual score, and see open risks on a heat map.
Downloads are included in the $19.85 yearly membership. Sign in
XLSXCSVODSXMLNumbers| Risk register with probability and impact scoring | |||||||||||
| Example data — replace the blue input cells with your own. | |||||||||||
| OPEN RISKS | HIGH OR CRITICAL (INHERENT) | AVERAGE RESIDUAL SCORE (OPEN) | REVIEWS OVERDUE | ||||||||
| 13 | 8 | 4.8 | 1 | ||||||||
| Settings | |||||||||||
| As of date (for overdue reviews) | Oct 9, 2026 | OK: probability and impact are between 1 and 5 | |||||||||
| Risk register (blue cells are inputs; scores and ratings are formulas) | |||||||||||
| ID | Risk description | Category | Owner | Probability (1-5) | Impact (1-5) | Score | Rating | Response | Mitigation action | Residual probability | Residual impact |
| R01 | Vendor API changes delay the integration build | Vendor | Vendor manager | 4 | 4 | 16 | Critical | Mitigate | Pin the API version and agree 60 days' change notice in the contract | 2 | 3 |
| R02 | Data migration finds more duplicate customer records than planned | Technical | Tech lead | 4 | 3 | 12 | High | Mitigate | Run two profiling passes and agree a merge rule with Operations | 2 | 2 |
| R03 | Key engineer leaves before go-live | People | Project manager | 3 | 4 | 12 | High | Mitigate | Name a backup for each module and document the build | 2 | 3 |
| R04 | Security review is not complete before the launch date | Compliance | Security lead | 3 | 5 | 15 | High | Mitigate | Book the penetration test for November and agree a fix window | 2 | 4 |
| R05 | Go-live window clashes with the year-end billing run | Schedule | Ops manager | 3 | 4 | 12 | High | Avoid | Move the cut-over to the first weekend after the billing run | 1 | 4 |
Showing the first 16 of 111 rows and 12 of 17 columns. Cells with formulas show the formula on hover.
| Heat map | ||||||
| Open risks by probability and impact, before and after the mitigation. Colors follow the rating thresholds on Scales. | ||||||
| Inherent risk: open risks by probability (rows) and impact (columns) | ||||||
| Impact: 1 minimal to 5 severe | ||||||
| Level | Probability | 1 | 2 | 3 | 4 | 5 |
| 5 | Almost certain | 0 | 0 | 0 | 0 | 0 |
| 4 | Likely | 0 | 0 | 3 | 1 | 0 |
| 3 | Possible | 0 | 1 | 2 | 3 | 1 |
| 2 | Unlikely | 0 | 0 | 1 | 1 | 0 |
| 1 | Rare | 0 | 0 | 0 | 0 | 0 |
| Residual risk: open risks by residual probability (rows) and residual impact (columns) | ||||||
| Residual impact: 1 minimal to 5 severe | ||||||
| Level | Probability | 1 | 2 | 3 | 4 | 5 |
| 5 | Almost certain | 0 | 0 | 0 | 0 | 0 |
Showing the first 16 of 27 rows and 7 of 7 columns. Cells with formulas show the formula on hover.
| Scales | |||
| Definitions for probability and impact, the rating thresholds and the risk categories. | |||
| Rating thresholds (score = probability x impact) | |||
| Rating | Lowest score | Highest score | Typical response |
| Low | 1 | 4 | Accept, or monitor at each review |
| Medium | 5 | 9 | Mitigate with a named action |
| High | 10 | 15 | Mitigate now and report to the sponsor |
| Critical | 16 | 25 | Avoid or transfer, with sponsor sign-off |
| Probability levels | |||
| Level | Label | Definition | |
| 1 | Rare | Less than 10% chance in the life of the project | |
| 2 | Unlikely | 10% to 30% chance | |
| 3 | Possible | 30% to 50% chance | |
| 4 | Likely | 50% to 80% chance |
Showing the first 16 of 34 rows and 4 of 4 columns. Cells with formulas show the formula on hover.
| Risk register with probability and impact scoring |
| Notes: what this workbook does, how to use it and the method behind it. |
| What it does |
| Records each project risk with an owner, a probability and an impact score, the response and the mitigation, and the score once the mitigation is in place. A heat map shows where open risks sit. |
| How to use it |
| 1. On the Scales tab, check the probability and impact definitions and the rating thresholds; change them to suit your project. |
| 2. On the Register tab, set the as-of date in the settings block. |
| 3. Enter each risk's description, category, owner, probability (1 to 5) and impact (1 to 5). |
| 4. Choose a response and a mitigation action, then enter the residual probability and impact and a review date. |
| 5. Read the tiles at the top and the Heat map tab. Close a risk by setting its status to Closed. |
| Formulas and method |
| Score = probability x impact (1 to 25). Residual score = residual probability x residual impact. |
| Rating: Critical at or above the Critical threshold, then High, Medium, and Low below the Medium threshold. The thresholds are on the Scales tab. |
Showing the first 16 of 32 rows and 1 of 1 columns. Cells with formulas show the formula on hover.
What does this template do?
A risk register records what could go wrong in a project, who owns each risk, how likely it is, how much it would matter and what is being done about it. This template is for project managers, PMO staff and risk owners who review risks at a set cadence.
Each risk is scored as probability multiplied by impact, both on 1 to 5 scales, and the score falls in a rating band: Low, Medium, High or Critical. The register scores each risk again after the mitigation, so the inherent and residual ratings can be compared. A review flag compares each open risk's review date with an as-of date you set. The heat maps count open risks in a five-by-five grid, before and after mitigation.
The Scales tab holds the probability and impact definitions and the rating thresholds, all of which you can change. The example is a fictional software rollout with fifteen risks. Two are closed, to show how they leave the open counts.
What’s inside
- Score equals probability times impact, rated Low, Medium, High or Critical from thresholds you set
- Residual score and rating after the response, shown beside the inherent score
- Review flag marks an open risk as Overdue when its review date is before the as-of date
- Inherent and residual heat maps, with cell colors that follow the rating bands
- Room for one hundred risks; spare rows stay blank
Which tabs does the workbook have?
| Tab | What it holds |
|---|---|
| Register | Settings, headline tiles and the risk table with scores, ratings, responses, residual scores and review flags. |
| Heat map | Five-by-five grids of open risks, inherent and residual, with the rating bands. |
| Scales | Probability and impact definitions, rating thresholds and risk categories. |
| Notes | Purpose, steps, formulas used, assumptions and limits. |
What formulas does this template use?
This template holds 585 formulas in 925 cells across 4 tabs, so 63% of its cells calculate. They use 5 distinct functions; the longest formula is 267 characters and 272 of them read from another tab.
| Function | Uses | What it does |
|---|---|---|
IF | 1,402 | one result when a test is true, another when false |
OR | 200 | true when any test is true |
COUNTIFS | 62 | counts cells meeting several conditions |
COUNTIF | 8 | counts cells meeting one condition |
SUMIFS | 1 | adds values meeting several conditions |
Counted from the workbook itself. Only functions that Excel, LibreOffice Calc, Google Sheets and Apple Numbers evaluate the same way are used, so the formulas survive every download format.
How do you use it?
- On the Scales tab, check the probability and impact definitions and the rating thresholds.
- On the Register tab, set the as-of date.
- Enter each risk's description, category, owner, probability and impact.
- Choose a response and a mitigation action, then enter the residual scores and a review date.
- Read the tiles and the Heat map tab; set a risk's status to Closed when it is retired.
What is it good for?
- Risk review at a steering committee meeting
- Tracking vendor and compliance risks through a rollout
- Showing the residual exposure left after agreed mitigations
- Keeping a dated risk log for an audit trail
Questions about this sheet
Why multiply probability by impact?
Multiplying gives one number to rank risks. The scores are ordinal, so a score of 8 is not twice as serious as a score of 4 in any measured sense.
What counts as overdue?
An open risk whose review date is before the as-of date. Closed risks and risks with no review date are flagged differently.
Do the heat maps include closed risks?
No. Each grid counts only the risks with status Open.
How many risks can the register hold?
One hundred. Blank rows show no score or rating.