Skip to main content

Applications for the autumn mentorship cohort are open until 30 September. Apply now

Worksheet

Delivery-Risk Register

A structured register of the risks that could prevent a funded proposal from delivering what it promised, scored on probability and impact.

Type
Worksheet
Difficulty
Intermediate
Time
60 min
Version
v1.0.0
Updated
8/9/2026
deliveryriskprocess

What this helps you do

Delivery risk is rarely hidden. It is usually visible in a plan that depends on one person, a dependency nobody controls, or a timeline with no slack. What is missing is a place to write it down consistently.

This register records each risk with evidence, a probability and impact score, a mitigation and its owner, the residual risk after mitigation, and the indicator you would monitor after enactment. The matrix at the end shows where the register is concentrated.

When to use this

  • A proposal promises outcomes over a period long enough for conditions to change.
  • Delivery depends on parties or systems the proposer does not control.
  • You want to define what you will monitor after enactment, before you vote.

When NOT to use this

  • The action has no delivery component, such as an informational action.
  • You are assessing financial assumptions; use the reconstruction workbook or the calculator.
  • You intend the register as an argument against the proposal rather than as an assessment.

What you'll need

  • The delivery plan, milestone schedule and dependency list
  • The team composition and stated capacity
  • Any prior delivery record for the same team
  • Your intake brief and claim-evidence map

Estimated completion time

60 minutes

Working time for one governance action, assuming the inputs listed here are already to hand.

How to use it

  1. 1Write one risk per row, phrased as an event with a consequence rather than as a worry.
  2. 2Categorise it: technical, financial, team, dependency, governance, legal, or market.
  3. 3Score probability from one to five, and impact from one to five, on the delivery of the stated outcome.
  4. 4Let severity fall out of probability times impact rather than setting it by feel.
  5. 5Record the evidence for the score. A score with no evidence is an opinion in a numeric costume.
  6. 6State the mitigation the proposal already offers, and name its owner.
  7. 7Re-score residual risk after that mitigation, honestly.
  8. 8Define one monitoring indicator per material risk, measurable by someone outside the team.
  9. 9Read the matrix for concentration, then carry the top residual risks into your decision record.

The tool

Full worksheet - v1.0.0

Risk row fields

  • Risk, as an event with a consequence
  • Category
  • Probability, one to five
  • Impact, one to five
  • Severity, probability times impact
  • Evidence for the scoring
  • Mitigation offered or available
  • Mitigation owner
  • Residual risk after mitigation
  • Monitoring indicator and its measurement interval

Probability and impact matrix

  • Score probability one to five where five is near certain
  • Score impact one to five where five prevents the stated outcome
  • Severity of 15 or more is treated as material for this register
  • Plot each risk to see whether the register is concentrated in one category
  • Concentration in a single category is itself a finding

Scoring discipline

  • Score the delivery risk, not your view of the proposers
  • A risk with no evidence is recorded with the evidence field left explicitly empty
  • Mitigations that exist only as intentions do not reduce residual risk
  • Every material residual risk needs a monitoring indicator or it cannot be tracked
Fictional Example

Invented for illustration. It does not describe a real governance action, proposal, or organisation.

Fictional risk row

  • Risk: the single named technical lead leaves and the hub build stalls for a quarter
  • Category: team
  • Probability: 3
  • Impact: 4
  • Severity: 12
  • Evidence: no deputy named; the same individual appears in all three site plans
  • Mitigation: proposal states a contractor could be engaged, with no contract in place
  • Mitigation owner: proposer, unnamed
  • Residual risk: 12, unchanged, because the mitigation is an intention
  • Monitoring indicator: named technical lead listed in each quarterly report

How to interpret the result

  • Read severity as a triage aid, not a measurement. It tells you what to examine next.
  • The gap between raw and residual severity measures how much real mitigation exists. A zero gap means the mitigations are words.
  • A register concentrated in one category tells you where to seek expert input.
  • Material risks with no monitoring indicator mean you would not know if the risk landed.

Limitations

  • Scores are subjective and are not comparable across reviewers without a shared calibration.
  • The register captures foreseeable risks only, and delivery often fails on unforeseen ones.
  • A high-risk register does not mean a proposal should not proceed; it means the risks should be visible and monitored.

Sources and methodology

  • ISO 31000 risk management principles and guidelines

    International Organization for Standardization

    Underlying structure for the probability and impact register.

  • Cardano project delivery reporting

    Placeholder entry. A canonical delivery reporting source is not yet established.

    Canonical link not yet verified. Treat this entry as incomplete.

Learn this method

This tool records the work. The Training Lab teaches how to do it.

  • risk-security-legal · Evaluating Team and Delivery Risk

    Evaluating Team and Delivery Risk

    Builds a risk register and proportionate mitigations.

    Open lesson
  • Lab lesson planned

    A dedicated lesson on monitoring indicators is planned.

Downloads

  • Markdown export: the complete tool, including metadata, instructions, the template, limitations, sources and version history.

No other file formats are published for this resource. We list a format only when the file exists.

Version and governance

Current version
v1.0.0
Published
8/9/2026
Last updated
8/9/2026
Next scheduled review
2/9/2027
Licence
CC BY 4.0
Editorial status
Not yet externally reviewed

No named reviewer is shown because no external review has been completed. Attribution appears only once a verified reviewer has signed off.

Changelog

  • v1.0.0 (2026-08-09) - First published edition.
Next in the workflow

Use these alongside it

The tools that usually come before or after this one.