Template · Management

Risk register with probability and impact scoring

Score each project risk by probability and impact, track its response and residual score, and see open risks on a heat map.

Create an account

Downloads are included in the $19.85 yearly membership. Sign in

XLSXCSVODSXMLNumbers
Risk register with probability and impact scoring
Example data — replace the blue input cells with your own.
OPEN RISKSHIGH OR CRITICAL (INHERENT)AVERAGE RESIDUAL SCORE (OPEN)REVIEWS OVERDUE
1384.81
Settings
As of date (for overdue reviews)Oct 9, 2026OK: probability and impact are between 1 and 5
Risk register (blue cells are inputs; scores and ratings are formulas)
IDRisk descriptionCategoryOwnerProbability (1-5)Impact (1-5)ScoreRatingResponseMitigation actionResidual probabilityResidual impact
R01Vendor API changes delay the integration buildVendorVendor manager4416CriticalMitigatePin the API version and agree 60 days' change notice in the contract23
R02Data migration finds more duplicate customer records than plannedTechnicalTech lead4312HighMitigateRun two profiling passes and agree a merge rule with Operations22
R03Key engineer leaves before go-livePeopleProject manager3412HighMitigateName a backup for each module and document the build23
R04Security review is not complete before the launch dateComplianceSecurity lead3515HighMitigateBook the penetration test for November and agree a fix window24
R05Go-live window clashes with the year-end billing runScheduleOps manager3412HighAvoidMove the cut-over to the first weekend after the billing run14

Showing the first 16 of 111 rows and 12 of 17 columns. Cells with formulas show the formula on hover.

What does this template do?

A risk register records what could go wrong in a project, who owns each risk, how likely it is, how much it would matter and what is being done about it. This template is for project managers, PMO staff and risk owners who review risks at a set cadence.

Each risk is scored as probability multiplied by impact, both on 1 to 5 scales, and the score falls in a rating band: Low, Medium, High or Critical. The register scores each risk again after the mitigation, so the inherent and residual ratings can be compared. A review flag compares each open risk's review date with an as-of date you set. The heat maps count open risks in a five-by-five grid, before and after mitigation.

The Scales tab holds the probability and impact definitions and the rating thresholds, all of which you can change. The example is a fictional software rollout with fifteen risks. Two are closed, to show how they leave the open counts.

What’s inside

  • Score equals probability times impact, rated Low, Medium, High or Critical from thresholds you set
  • Residual score and rating after the response, shown beside the inherent score
  • Review flag marks an open risk as Overdue when its review date is before the as-of date
  • Inherent and residual heat maps, with cell colors that follow the rating bands
  • Room for one hundred risks; spare rows stay blank

Which tabs does the workbook have?

TabWhat it holds
RegisterSettings, headline tiles and the risk table with scores, ratings, responses, residual scores and review flags.
Heat mapFive-by-five grids of open risks, inherent and residual, with the rating bands.
ScalesProbability and impact definitions, rating thresholds and risk categories.
NotesPurpose, steps, formulas used, assumptions and limits.

What formulas does this template use?

This template holds 585 formulas in 925 cells across 4 tabs, so 63% of its cells calculate. They use 5 distinct functions; the longest formula is 267 characters and 272 of them read from another tab.

FunctionUsesWhat it does
IF1,402one result when a test is true, another when false
OR200true when any test is true
COUNTIFS62counts cells meeting several conditions
COUNTIF8counts cells meeting one condition
SUMIFS1adds values meeting several conditions

Counted from the workbook itself. Only functions that Excel, LibreOffice Calc, Google Sheets and Apple Numbers evaluate the same way are used, so the formulas survive every download format.

How do you use it?

  1. On the Scales tab, check the probability and impact definitions and the rating thresholds.
  2. On the Register tab, set the as-of date.
  3. Enter each risk's description, category, owner, probability and impact.
  4. Choose a response and a mitigation action, then enter the residual scores and a review date.
  5. Read the tiles and the Heat map tab; set a risk's status to Closed when it is retired.

What is it good for?

  • Risk review at a steering committee meeting
  • Tracking vendor and compliance risks through a rollout
  • Showing the residual exposure left after agreed mitigations
  • Keeping a dated risk log for an audit trail

Questions about this sheet

Why multiply probability by impact?

Multiplying gives one number to rank risks. The scores are ordinal, so a score of 8 is not twice as serious as a score of 4 in any measured sense.

What counts as overdue?

An open risk whose review date is before the as-of date. Closed risks and risks with no review date are flagged differently.

Do the heat maps include closed risks?

No. Each grid counts only the risks with status Open.

How many risks can the register hold?

One hundred. Blank rows show no score or rating.