Construction Risk Management: Register to Site Reality
Almost every construction project has a risk register. Far fewer have risk management. The register is a document — a table of things that might go wrong, who owns them, and what will be done about them. Risk management is what happens when that document actually changes decisions on site: when a hazard is closed out, a new one is added the week it appears, and an owner is held to the mitigation they signed up to. The gap between the two is where projects quietly lose money and safety margin. This article is written for developers, principal contractors, and project managers who want a register that works as a live control on the programme rather than a file produced for an audit and never opened again.
Quick Summary
What a Risk Register Is Actually For
On the surface, a risk register is a list. It names the things that could threaten a project — a delayed planning decision, an unknown ground condition, a specialist subcontractor who might not be available when needed — and records how likely each is, how damaging it would be, and what will be done about it. Written well, it turns vague anxiety about a job into a set of specific, ownable problems that can be managed one by one.
The purpose, though, is not to have the list — it is to make better decisions because of it. A register earns its place when it changes how the programme is sequenced, where contingency is held, and what gets checked before work proceeds. That is the whole point of construction risk management: not to predict the future, but to make sure the risks a team already senses are named, owned, and actively reduced before they turn into cost, delay, or harm. A register that never influences a decision is not managing risk; it is describing it.
Why It Matters Beyond the Paperwork
Risk management matters because the alternative is expensive and, on a construction site, sometimes dangerous. Unmanaged risk does not disappear — it arrives later, usually at the worst moment and at a higher price. A ground condition that a modest survey fee could have investigated becomes a redesign and a delay once the foundations are being dug. The cost of managing a risk early is almost always a fraction of the cost of absorbing it late.
There is also a legal dimension developers and contractors cannot treat as optional. Under the Construction (Design and Management) Regulations 2015, duty holders must plan, manage and monitor work so that foreseeable risks to health and safety are eliminated or controlled — a discipline set out in the HSE summary of CDM duties and explained further in our guide to CDM 2015. Risk management is the mechanism through which those duties are discharged: get it right and the register evidences that the team took foreseeable risk seriously; get it wrong and its absence is the first thing an investigator notices.
The Anatomy of an Entry That Works
The difference between a live register and a dead one shows up entry by entry. A working entry is specific, owned by a named person, honestly scored, tied to a real mitigation, and reviewed on a set rhythm. A dead entry is generic, owned by "the team", scored to look comfortable, and never looked at again. The table below sets out what each column is really for, and how it tends to fail.
| Register element | What it is for | How it fails in practice |
|---|---|---|
| Risk description | A specific, testable statement of what could go wrong and its cause | Written so broadly ("delays", "weather") that no one can act on it |
| Owner | A single named person accountable for driving the mitigation | Assigned to a role, a company, or "everyone" — so effectively no one |
| Likelihood & impact | An honest score that ranks where attention should go | Scored optimistically to keep the register looking green |
| Mitigation | The concrete action that reduces likelihood or impact, with a date | A statement of intent ("monitor closely") with no action or deadline |
| Review & status | Evidence the risk is being tracked, updated, and closed when resolved | Frozen at the value it was given on day one and never revisited |
What Teams Overlook
The most common blind spot is ownership. A risk with no named owner has no one to drive it, so it stalls at whatever state it was in when it was written down. Assigning risks to a company or a job title feels tidy but dissolves accountability; the person who can actually influence the outcome needs to be the one whose name is against it. Where a risk sits with a specific duty holder — the client, the principal designer, or the principal contractor — that mapping should be explicit, because those roles carry defined legal responsibilities, as our explanation of the duty holder on a construction project sets out.
The second blind spot is that risk is dynamic. A register built at tender and left untouched describes a project that no longer exists: new risks appear as the design develops, ground is opened up, and subcontractors are appointed, while others recede or close. A register not refreshed on a regular cycle silently drifts out of date, and its scores stop meaning anything. The third overlooked point is closure — teams are diligent about adding risks and reluctant to close them, so the register bloats with resolved items until the genuinely live ones are buried in the noise.
The Register in the Drawer
The most dangerous risk register is the one that looks complete: written carefully at the start of the job, signed off, filed, and never opened again. It gives everyone the comfort of having "done" risk management while the real risks evolve unwatched. If your register has not changed since the project started, it is not protecting you — it is giving you false assurance, which is worse than none.
What Goes Wrong When It Is Treated as a Formality
When a register exists only to satisfy a checklist, the failure is not a paperwork failure — it is a management failure that paperwork was supposed to prevent, and it surfaces at exactly the wrong time. When a serious incident or dispute occurs, the register becomes disclosable evidence of what the team foresaw and how it responded, and one that identified a risk but shows no action taken is more damaging than one that never mentioned it, because it proves the risk was known and left unmanaged. Good project governance and documentation exists precisely so the record shows decisions being made and acted on, not merely logged.
Better Practice: Making the Register Live on Site
A register becomes a working control when it is treated with the same seriousness as the programme and the budget — reviewed on a fixed cadence, owned by named people, and used to drive action. That means a standing item in project meetings where the top risks are walked through, mitigations are chased, and closed risks are cleared out. It means scoring risks honestly even when the honest score is uncomfortable, because a register that never shows red is not being used. And it means writing mitigations as specific actions with owners and dates, so "reduce the risk" becomes "commission the intrusive survey by month-end, owned by the project manager".
Monitoring is where most of the value is won or lost. Identifying a risk is the easy part; verifying that the mitigation was carried out, and that it worked, is what separates management from documentation. That verification is the natural home of quality assurance and site oversight — checking on site that what the register promised has been done, rather than assuming it. A mitigation is not closed because someone said it was, but because it was seen to be complete.
Five Habits of a Register That Works
Give every risk a single named owner, not a role. Score honestly, even when the honest score is red. Write mitigations as dated, checkable actions. Review the register on a fixed rhythm and close what is genuinely resolved. And keep a short record of what changed at each review, so the register shows a history of decisions rather than a static snapshot.
The Link to CDM 2015 and the Building Safety Act
Risk management does not sit apart from the regulatory framework — it is how much of that framework is satisfied in practice. CDM 2015 places duties on clients, designers and contractors to plan, manage and monitor foreseeable risk from the earliest design stages, which is exactly what a well-run register operationalises: it is where the abstract duty to "manage risk" becomes a concrete, auditable set of actions with owners and dates.
The Building Safety Act raises the stakes further, particularly for higher-risk buildings, by demanding that safety-critical decisions be evidenced across the life of a project — a shift reinforced by the Building Safety Regulator becoming a standalone body in January 2026, having previously sat within the Health and Safety Executive. Under this regime, being able to show how a risk was identified, owned, controlled and verified is part of demonstrating compliance, as the government's Building Safety Act guidance makes clear. A living risk register, tied to the wider project record, is one of the more practical ways a team builds that evidence as it goes rather than reconstructing it under pressure at the end.
What to Consider Before You Start
The most useful decision is made early: who owns the risk process, and how often it is reviewed. A register without a designated driver and a fixed review rhythm will decay however well it is written at the outset. Decide, at the point the project is set up, who chairs the risk review, who holds the register, and how new risks are captured between reviews so the document keeps pace with the job.
It is also worth testing the register independently rather than marking your own homework. A fresh reading by someone outside the immediate team tends to surface the risks that familiarity has made invisible and to challenge the optimistic scores that creep in when people assess their own work. That is the thinking behind a compliance and building safety audit, and the same discipline our post on building safety audits describes — compliance proven by evidence, not assumed. Above all, keep the register proportionate: a short, honest, actively managed list of real risks protects a project far better than a long one no one reads.
A risk register does not reduce risk. People reduce risk, using the register as the instrument that tells them where to look and holds them to what they said they would do. The projects that stay in control are the ones where it is reviewed like the schedule, owned like the budget, and trusted because it reflects what is actually happening on site.
At Tarj Construction, we treat risk as something managed continuously through a project rather than documented at the start of it. If you want an independent view of whether your risk register is genuinely controlling your project — or help building one that will — that is the kind of consultancy support for developers and contractors worth bringing in early, while it can still change the outcome.
Frequently Asked Questions
What is the difference between a risk register and risk management?
A risk register is the document that records identified risks, their scores, owners and mitigations. Risk management is the ongoing activity of using that document to make decisions — reviewing it, chasing mitigations, adding new risks, closing resolved ones, and verifying the actions were carried out. The register is a tool; risk management is the work. A project can have a detailed register and no real risk management if the document is never acted upon, which is one of the most common weaknesses on otherwise well-run jobs.
How often should a construction risk register be reviewed?
There is no single legally fixed interval, but the sensible principle is to review the register on a regular, defined rhythm — commonly as a standing item in project or site meetings — and whenever something material changes, such as a design revision, a new subcontractor appointment, or a change in ground conditions. A fast-moving or higher-risk scheme needs more frequent review than a slow, low-risk one. What matters is that the interval is deliberate and adhered to, rather than the register sitting untouched between the start of the job and the first problem.
Is a risk register a legal requirement on a construction project?
CDM 2015 does not mandate a "risk register" by name, but it does require duty holders to plan, manage and monitor foreseeable health and safety risks, and a register is the standard, practical way of demonstrating that this is being done. For higher-risk buildings, the Building Safety Act's emphasis on evidencing how safety risks are controlled makes a documented, actively managed approach effectively unavoidable. Treat structured risk management as an expectation you must be able to evidence, and confirm the specific requirements for your project with the relevant regulator and a qualified adviser.
This article is general guidance only and does not constitute legal, health and safety, or building safety advice. The right approach to risk management depends on your specific project, its scale, and its risk profile. Always confirm current duties with the HSE, the Building Safety Regulator where relevant, and qualified professional advisers before acting.