Action is the key to success

Loading...

Doitify
Pricing Enterprise Contact Us
Doitify Project Planning & Execution

Project Risk Assessment Template (Free, Fillable + Example)

Updated on August 21, 2026 https://doitify.com/planning/project-risk-assessment-template/
Share Link copied!
Summary

Free fillable project risk assessment template with a 5×5 risk matrix, a worked example, and response-planning tips.

A project risk assessment is the structured process of identifying, analyzing, and planning responses to uncertain events before they happen — following the classic project management sequence of identify → analyze → respond → monitor. The core template has 10 columns: ID, risk description, category, likelihood, impact, risk score, priority, owner, response strategy, and action plan.

Every project has risks, and most teams discover them the hard way — the vendor delivers two weeks late, the key developer leaves mid-build, or the new regulation lands a month before launch. A project risk assessment is the disciplined process of writing those risks down before they happen, scoring them, and assigning a response. The tool that makes that possible is a simple template: one row per risk, with likelihood, impact, a score, an owner, and an action. Teams that fill it out at kickoff survive surprises; teams that don’t spend their contingency reacting to them.

This article gives you a copy-paste-ready project risk assessment template, a worked example with real numbers and a 5×5 risk matrix, the difference between a risk assessment and a risk register, where to find free templates, and the mistakes that make risk assessments useless.

Quick Answer: What Should a Project Risk Assessment Template Include?

A project risk assessment template should include, per risk: an ID, a description of the risk, its category, likelihood (1–5), impact (1–5), the risk score (likelihood × impact), priority, an owner, a response strategy (avoid, mitigate, transfer, or accept), and an action plan with dates. The assessment answers three questions per risk: How likely is it? How bad would it be? What are we going to do about it? Per standard project management practice, this is the identify-and-analyze stage of risk management, and the output feeds a risk register that the team reviews at regular intervals for the rest of the project.

What Is a Project Risk Assessment, Really?

A project risk assessment is the process of finding out what could go wrong with a project, how likely each event is, how much damage it would cause, and what the team will do about it. It is one stage of project risk management — followed by planning responses and then monitoring risks through the project’s life.

The key distinction to keep straight:

  • A risk is a future, uncertain event — it hasn’t happened yet. (“The vendor may deliver late.”)
  • An issue is happening right now. (“The vendor missed the deadline; we are 5 days behind.”)

A risk assessment works with the first category. If a risk becomes certain, it stops being a risk and becomes an issue — and it moves from the risk assessment into the issue log. This is why the template has a “status” field: risks are born, get tracked, sometimes get closed because they came true (and became issues) or because they became impossible.

Join Doitify Today

Move projects forward without the chaos: all your tasks, progress, and team reports in one unified workspace. Built for companies, startups, and remote teams — with a quick setup and a free trial.

The Free Project Risk Assessment Template (Copy-Paste Ready)

Copy the structure below into Excel, Google Sheets, a board, or your project tool. One row per risk, sorted by score from highest to lowest.

Risk Assessment Table (one row per risk)

ID Risk description Category Likelihood (1–5) Impact (1–5) Risk score (L×I) Priority Owner Response strategy Action plan Status
R-01 ____ ____ __ __ __ __ ____ ____ ____ Open / Mitigating / Closed

Scoring scale (1–5)

  • Likelihood: 1 = rare, 2 = unlikely, 3 = possible, 4 = likely, 5 = almost certain.
  • Impact: 1 = negligible, 2 = minor, 3 = moderate, 4 = major, 5 = severe (threatens the project).
  • Priority by score: 1–4 low (accept/monitor), 5–9 medium (assign owner + response), 10–15 high (active mitigation, escalate), 16–25 critical (immediate action, likely needs sponsor).

Response strategies

  • Avoid: remove the risk by changing the plan (e.g., drop a risky third-party dependency).
  • Mitigate: reduce likelihood or impact (e.g., add a second supplier, extra QA).
  • Transfer: shift the risk to someone else (e.g., insurance, fixed-price contract).
  • Accept: take the risk knowingly, often with a contingency reserve for the impact.

Header Info

  • Project: ____ | Assessor / team: ____
  • Date of assessment: ____ | Next review date: ____
  • Approved by (sponsor): ____

Filled-In Example: A Risk Assessment With Real Numbers

Here is a condensed filled example: a SaaS platform launch, 12 risks assessed at kickoff, scored on the 5×5 matrix.

  • Risk R-01: Key developer leaves mid-project. Likelihood 3, Impact 5 → score 15 → High. Mitigation: document all critical modules, cross-train a second developer, budget a recruiting buffer. Owner: Engineering lead.
  • Risk R-02: Vendor API does not meet the performance contract. Likelihood 4, Impact 4 → score 16 → Critical. Mitigation: load-test by week 3, run a parallel vendor proof-of-concept, include an exit clause. Owner: Tech lead.
  • Risk R-03: Data migration corrupts customer records. Likelihood 3, Impact 4 → score 12 → High. Mitigation: dry-run migration on staging, automated record-count validation, rollback plan. Owner: Data engineer.
  • Risk R-04: Compliance review (new data regulation) delays launch. Likelihood 4, Impact 3 → score 12 → High. Mitigation: pre-schedule the compliance review in week 6, prepare documentation in advance. Owner: Product manager.
  • Risk R-05: A competitor launches a similar feature first. Likelihood 3, Impact 2 → score 6 → Medium. Response: accept, monitor monthly; reorder roadmap if needed. Owner: Product manager.

Of the 12 risks, three were High/Critical (scores 15, 16, 12) and immediately got owners and mitigation actions; the rest were medium or low and tracked in the register. The team budgeted $9,000 of mitigation activity against a $120,000 contingency. Three weeks later, the vendor proof-of-concept failed its load test — but because R-02 was already in motion with an exit clause, the team switched vendors with 2 weeks of buffer left instead of discovering the problem at launch.

That is the whole argument for a risk assessment: the surprises you find early are the ones you can still do something about.

What Is a Risk Matrix and How Do You Use It?

A risk matrix (or probability–impact matrix) is a 5×5 grid with likelihood on one axis and impact on the other. Each risk is placed in a cell, and the cell’s color/zone determines priority:

  • Green zone (score 1–4): low risk — accept and monitor.
  • Yellow zone (score 5–9): medium — assign an owner and a response.
  • Orange zone (score 10–15): high — active mitigation, escalate to the sponsor.
  • Red zone (score 16–25): critical — immediate action required.

The matrix does the prioritization for you: instead of arguing over which risk is “bigger,” the team plots each one and the scoring does the ranking. Two practical rules: never score a risk 5×5 without a serious reason (it usually means you don’t understand it yet), and update the scores at every review — a risk that was 2×3 in week 1 can be 4×4 by week 4 as new information arrives.

Risk Assessment vs Risk Register: What’s the Difference?

The two terms are often used interchangeably, but they describe different things:

  • A risk assessment is the analysis activity (and the moment-in-time output): identifying risks, scoring likelihood and impact, and deciding responses.
  • A risk register is the living document that holds all assessed risks and tracks them through the project — with owners, status, review dates, and updates.

You run an assessment (often in a workshop) and the result populates the register, which you then update weekly or monthly. The template in this article works for both: use the full table during the assessment, then keep maintaining the same table as the register for the project’s duration.

Where Can You Find Free Project Risk Assessment Templates?

Real, reputable sources include:

  • Atlassian Confluence — a free risk assessment matrix template (Background, Risk rating, Risks table, Action items) that works inside the Atlassian ecosystem. Trade-off: best for teams already in Confluence; the template is a page, so you must connect actions to real task tracking.
  • Microsoft Excel / Google Sheets — standard 5×5 risk matrix and risk register templates; universally usable and free. Trade-off: static — scores, owners, and actions are only as current as the last manual update.
  • Trello — free risk register board templates using lists by risk score. Trade-off: visual and simple, but no built-in scoring math or audit history.
  • Asana — free risk register templates with custom fields for likelihood, impact, and owner, plus task-based action items. Trade-off: good for the action half, weaker for the analysis workshop half.
  • Smartsheet — project and risk templates with matrix views and more structured scoring. Trade-off: free for some templates, but the full gallery is designed around a paid product.

The pattern: spreadsheet and document templates are free and universal but go stale fast; board- and tool-native templates keep risks next to the work but lock you into the tool. Whatever you choose, the fields that must survive are owner, score, status, and next review date — those are what make the register alive.

How Do You Run a Risk Assessment and Keep It Updated?

  1. Run a kickoff workshop. Get the core team plus one or two stakeholders into a room (or a shared board) for 60–90 minutes. Brainstorm risks freely, then cluster them and remove duplicates.
  2. Score and rank. Apply likelihood and impact per risk, compute scores, and sort the list. Discuss only the top 10–15 — the long tail of low risks gets accepted and monitored.
  3. Assign owners and responses. Every risk above the low threshold gets one owner and one response strategy. Write the action plan with dates while the team is in the room.
  4. Review on a fixed cadence. Add risk review to the weekly status meeting or a monthly risk review: re-score each open risk, close the ones that materialized (move to the issue log) or became irrelevant, and add new ones.
  5. Escalate early. A risk at score 15+ goes to the sponsor the week it is identified, not at the next review.

Scenario 1: A SaaS launch with 12 assessed risks (numbers from the example)

The assessment found 12 risks; three scored 12–16 (High/Critical) and received mitigation within 48 hours. The vendor risk (16) materialized at week 3 — but the exit clause and parallel PoC meant a vendor switch cost 2 weeks of buffer rather than a 4-week launch slip. Total mitigation spend: $9,000 against a $120,000 contingency, which protected roughly $60,000 in launch-week revenue.

Scenario 2: A construction fit-out with a fixed completion date

A 10-week office fit-out assessed 9 risks. The top risk (14): the landlord’s approval for structural changes arrives late. Mitigation: submit drawings in week 1, pre-book the inspection, and sequence interior works so the critical path waits on nothing. Approval came 3 days late but the team absorbed it with a 2-day float — the project finished on the contracted date and avoided a $4,000/day penalty.

Scenario 3: A 5-person agency project with a tight margin

A small agency does a 45-minute risk assessment on a fixed-fee website project. They find a 12-score risk: the client’s content will arrive late and push the timeline. Mitigation: the contract already holds a client-supplied-content clause and a weekly content checkpoint. Content arrives 1 week late; the checkpoint catches it, the client is invoiced for the extension per the clause, and the team’s margin holds instead of being eaten by unplanned hours.

Common Mistakes

Mistake 1: Assessing risks only at kickoff and never again. A risk assessment is a snapshot; without regular review, the register becomes a museum piece while the project changes around it.

Mistake 2: Confusing risks with issues. Putting problems that are already happening into the risk register makes the list feel safer than it is. Issues go to the issue log and get resolved now; risks get assessed and watched.

Mistake 3: No owner on a risk. A risk without a named owner is a risk nobody is responsible for tracking or resolving.

Mistake 4: Vague scores. “Possible” and “big impact” mean different things to different people. Use the 1–5 scale with written definitions so the matrix is consistent across the team.

Mistake 5: Ignoring the low-scoring tail. Risks scoring 1–4 are still real; accept them deliberately and re-check them at reviews, because a 2×2 in January can become a 4×3 by March.

Mistake 6: No connection to the contingency budget. An assessment that scores risks but never budgets for responses leaves the team helpless when a top risk lands. Tie mitigation actions to money and owner time.

Know This Before You Choose

  • The template is analysis plus tracking, not just a form. Judge it by whether it survives the project: updated scores, closed risks, and next review dates.
  • Score definition matters more than the matrix shape. A 5×5 matrix without a written 1–5 scale produces random scores. Define the scale first.
  • Owners and due dates are the deliverable. The assessment’s real output is a short list of owned, dated mitigation actions — not the list of risks itself.
  • Review cadence is non-negotiable. Weekly re-scoring of open risks (even for 5 minutes) beats a perfect workshop that is never revisited.
  • Low risks should be accepted, not filed forever. If a risk has sat at score 3 for three months with no action, close it or re-score it honestly.

How Can You Run This Template in Doitify?

The point where risk assessments usually fail is the handoff from a workshop list to weekly tracking with owners and dates. To be transparent: Doitify is our product, which is why we know its capabilities from the inside. In Doitify you can record each assessed risk as a tracked item with an owner, due date, and status, attach the risk and constraint documentation and the project documents to the project, and keep mitigation actions as tasks and sub-tasks with checklists and reminders so they are actually executed. Risks are visible next to the plan on boards, Gantt, and roadmaps, and work/performance reports give the monthly risk review real numbers. If your assessments are thorough but the follow-up keeps slipping, closing that loop is exactly what this platform is built for. Explore project management templates to see the full risk-to-delivery workflow in one workspace.

FAQ

A structured table that captures every risk in a project with the same fields — ID, description, category, likelihood, impact, score, priority, owner, response strategy, and action plan — so the team can rank and respond to risks consistently.

The risk assessment is the analysis activity (and its one-time output); the risk register is the living document that tracks all assessed risks through the project with owners, status, and review dates. Assessment populates the register.

Multiply likelihood (1–5) by impact (1–5). Scores of 1–4 are low, 5–9 medium, 10–15 high, and 16–25 critical on the standard 5×5 matrix.

Avoid (change the plan to remove the risk), mitigate (reduce likelihood or impact), transfer (shift the risk to a third party, e.g., insurance), and accept (take the risk knowingly, usually with a contingency reserve).

A risk is a future, uncertain event that may or may not happen. An issue is a problem happening now. When a risk materializes, it becomes an issue and moves to the issue log.

At least monthly for most projects, and weekly re-scoring of open risks during active phases. New risks should be added whenever the plan changes, and materialized or obsolete risks closed out.

The project manager usually facilitates and owns the process, but the core team and sponsors contribute risks and responses. Every risk above the low threshold needs one named owner.

A lighter version, yes. For a 5-task project, a one-page list of 4–6 risks with owners is enough; skip the full matrix machinery but keep the ownership and review discipline.

Conclusion

A project risk assessment template is the cheapest insurance a project can buy: an hour at kickoff that turns vague worry into a scored, owned, dated plan. Copy the template in this article, run a 60–90 minute workshop, score every risk on the 5×5 matrix, assign an owner and response to anything scoring 5 or above, and review the register at a fixed cadence for the project’s whole life. The team that finds its vendor risk at week 3 instead of at launch is the team that finishes on the contracted date — and that is exactly what the template is for.

Join Doitify Today

Move projects forward without the chaos: all your tasks, progress, and team reports in one unified workspace. Built for companies, startups, and remote teams — with a quick setup and a free trial.

0 0 votes
Article Rating
Share
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Table of Contents

Ready to do more with Doitify?

Bring your projects, team, and goals together in one AI-powered workspace.

Get Started
Table of Contents