This guide compares the two side by side, gives a review agenda, a decision table for choosing between them, a calendar, and the PMP exam cues.
What Is the Difference Between a Risk Audit and a Risk Review?
A risk audit looks backward and tests whether the risk management process and its responses worked. A risk review looks forward and reassesses risks, finds new ones, and closes old ones. Audits run at set intervals. Reviews run every reporting cycle.
| Attribute | Risk review | Risk audit |
| Direction | Forward: what happens next | Backward: what happened and whether it worked |
| Core question | Are the risks and ratings current? | Is the risk process working, and did responses deliver? |
| Subject | Individual risks and overall project risk | The risk management process and response results |
| PMBOK Sixth Edition location | Monitor Risks, meetings | Monitor Risks, audits |
| Frequency | Every status cycle or on a set schedule | At milestones, gates, or set intervals |
| Led by | Project manager | Project manager ensures it happens; the auditor is often independent |
| Participants | Team, risk owners, experts | Auditor, project manager, risk owners interviewed |
| Evidence | Current register, triggers, status | Register history, minutes, cost records, reports |
| Outputs | Updated register and report, new and closed risks, lessons | Findings, recommendations, corrective actions |
| Quality analogy | Quality control: check the results | Quality assurance: check the process |
| Format defined in | Risk management plan (meetings) | Risk management plan (audit format and frequency) |
| Effort | Short and routine | Longer and formal |
What Is a Risk Review?
A risk review is a scheduled meeting where the team documents the effectiveness of responses, identifies new risks, reassesses current ones, closes outdated ones, examines issues from risks that occurred, and records lessons. The PMBOK Guide requires periodic risk reviews.
The PMBOK Guide Sixth Edition lists risk review meetings as a Monitor Risks technique. PMI prefers separate risk review meetings, and it allows a combined status and risk meeting when the risk management plan says so. Either way, the project must review risk periodically.
A review covers 6 topics:
- Effectiveness of responses against overall project risk and individual risks.
- New risks, including secondary risks that responses create.
- Reassessment of current risks, such as watch-list items that now merit a response.
- Closure of outdated risks and release of their reserves to the contingency pool.
- Issues that came from risks that occurred.
- Lessons for the remaining phases.
What Is a Risk Audit?
A risk audit is a formal examination of how well the project manages risk. It tests plan compliance, identification completeness, response effectiveness, and reserve use, then reports findings. The project manager ensures audits run at the frequency in the risk management plan.
PMTI’s guide Project Risk Management Process, Tools & Templates walks through the risk processes, including Monitor Risks, where both the audit and the review sit.
An audit samples evidence. It asks whether the register, the response records, and the reserve log match what the plan promised. A review asks what the register must say today. An audit asks whether the process that fills the register is sound.
How Do Audits and Reviews Work as Quality Assurance and Quality Control?
The review is the quality control of risk management: it checks results such as ratings and response outcomes. The audit is the quality assurance: it checks the process that produces them. PMI suggests holding the two meetings separately.
| Check | Type | Example finding |
| Review | Quality control | Mitigation for R7 cut probability from 40% to 15%, so the risk moves to the watch list |
| Review | Quality control | A new supplier risk appears and enters the register |
| Audit | Quality assurance | 5 of 21 open risks have no owner, which shows the assignment step fails |
| Audit | Quality assurance | 3 of 9 issues were never registered, which shows identification misses risks |
Reviews find a risk problem. Audits find the process problem behind it. A team that only reviews keeps fixing symptoms.
What Does a Risk Review Meeting Agenda Look Like?
A 60-minute risk review covers 7 items: a recap, the top risks, triggers, new risks, closures, issues from occurred risks, and lessons with actions. The chair records every decision and updates the register before the meeting ends.
PMTI’s guide What is a Risk Register in Project Management? covers the register that the meeting updates.
| Item | Minutes | Input | Output |
| Recap of the last review’s actions | 5 | Action log | Actions closed or carried forward |
| Top risks and response status | 15 | Register, top 10 by score | Confirmed or changed responses |
| Trigger watch | 10 | Trigger list | Risks moved to a stronger response |
| New risks | 10 | Team input, change requests | New register entries with owners |
| Closures | 10 | Expired exposure windows | Closed risks, reserve released |
| Issues from occurred risks | 5 | Issue log | Issues linked to risk IDs |
| Lessons and actions | 5 | Notes | Lessons logged, new actions assigned |
Send the top-10 list ahead of time. A review that spends 20 minutes reading the register aloud has no time left to decide.
When Do You Use an Audit and When Do You Use a Review?
Use a review when the question is about a risk: is the rating right, is the trigger close, is the response working. Use an audit when the question is about the process: is the method followed, can the sponsor trust the register.
| Situation | Use | Why |
| A new phase is starting | Review | Reassess ratings for the coming work |
| A team member reports a new risk | Review | Add and rate it |
| A risk the register rated low occurs twice | Audit | Repeat surprises point at the process |
| The sponsor asks whether risk management works | Audit | The question is about the process |
| A watch-list risk rises in probability | Review | Decide on a response |
| The contract requires assurance on risk control | Audit | Independent evidence is needed |
| The contingency reserve drains faster than planned | Review, then audit | Review the risks that drew on it, then test the process |
| Several issues were never registered | Audit | Identification is failing |
How Often Do You Run Each?
Run reviews at every reporting cycle, often every 2 weeks or monthly. Run audits less often: once on a small project, at each milestone or phase gate on a large one. Set both frequencies in the risk management plan.
| Project profile | Risk review | Risk audit |
| Small, short | At each status meeting | Once, before closure |
| Medium | Every 2 weeks or monthly | At each major milestone |
| Large, complex, or long | Every 2 weeks, plus at each gate | At each phase gate, plus an independent audit each year |
Example calendar for a 12-month project: review every 2 weeks, an audit at month 6 (after the design gate), and an audit at month 11 (before closure). The month 6 findings change the risk management plan for the second half.
How Do Audit Findings and Review Outputs Feed Each Other?
Review outputs become audit evidence, and audit findings change the review. The register history, closed risks, and lessons from reviews show the auditor what happened. Findings add agenda items, owners, or training, which the next review carries out.
| Output | Feeds | Effect |
| Review: updated register and closed risks | Audit evidence | The auditor tests them against the plan |
| Review: lessons learned | Audit and the lessons register | Repeated lessons show a process gap |
| Audit: finding on missing owners | Next review agenda | The team assigns owners in the meeting |
| Audit: finding on scale inconsistency | Risk management plan | The plan reissues the scales, and the review re-rates risks |
| Audit: finding on weak identification | Identification checklist | The next review adds the missing prompts |
The cycle closes when a finding becomes a review action and the next audit confirms the fix.
Who Runs and Who Attends Each One?
The project manager chairs the risk review with the team, risk owners, and experts. The audit needs an auditor, the project manager, and the risk owners it interviews. The sponsor receives the audit report and attends reviews only for escalations.
| Role | Risk review | Risk audit |
| Project manager | Chairs | Ensures it happens, supplies evidence |
| Risk owners | Report status on their risks | Interviewed on triggers and results |
| Team and experts | Contribute new risks and ratings | Provide records |
| Auditor | Not present | Plans, tests, and reports |
| Sponsor | Joins for escalations | Receives the report and agrees corrective actions |
The auditor can be the PMO, the quality function, a peer project manager, independent experts, or an external party. The PMBOK Guide does not fix who audits. Independence raises assurance and cost.
What Is a Risk Portfolio Audit?
A risk portfolio audit examines risk management across a group of projects or programs. It samples projects, compares their practices, checks that exposure rolls up consistently, and reports common gaps and the top risks for executive attention.
One PMI conference paper on a telecom supplier describes an audit that benchmarks projects against each other and lists the top 10 risks in the organization from key projects. Use the same approach at portfolio level:
| Level | Audit focus | Typical finding |
| Project | Plan compliance, response effectiveness | Owners missing on 5 of 21 risks |
| Program | Cross-project dependency risks | Shared supplier risk recorded in 3 projects with 3 different ratings |
| Portfolio | Consistent scales, roll-up, exposure against appetite | Two business units score probability on different scales |
The PMO or enterprise PMO usually commissions the portfolio audit, and its findings feed the enterprise risk report.
What Does “Risk” Mean in Auditing?
In financial auditing, audit risk is the chance that an auditor issues a clean opinion on statements containing a material misstatement. It equals inherent risk times control risk times detection risk. A project risk audit examines project risk management instead.
| Term | Field | Meaning |
| Project risk audit | Project management | Tests how well the project manages risk |
| Audit risk | Financial auditing | Risk of a wrong opinion: inherent × control × detection |
| Risk assessment procedures | Financial auditing (ISA 315) | Inquiry, observation, inspection, and analytical procedures |
The words overlap and the disciplines do not. Project teams audit their risk process. Financial auditors audit the risk of misstatement.
How Do Audits and Reviews Work in Agile and Hybrid Projects?
Agile and hybrid teams run the review as a short recurring session, often inside sprint planning or the retrospective, and the audit at release boundaries or quarterly. The review updates backlog risks. The audit checks the practice.
- Fold a 10-minute risk review into sprint planning, or run it in the retrospective.
- Update risk items in the backlog at every review.
- Audit at each release boundary, or every 3 months on long-running products.
- Sample the top risk items and every risk that occurred.
Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.
How Are the Risk Audit and the Risk Review Tested on the PMP Exam?
PMP questions test the direction and the subject. A backward look at whether the risk process and responses worked is an audit. A forward look that reassesses risks and updates the register is a review. Both sit in Monitor Risks.
| Scenario cue | Answer |
| The team examines whether the risk management process worked | Risk audit |
| The team reassesses current risks and closes outdated ones | Risk review |
| The team identifies new risks at a scheduled meeting | Risk review |
| Which is the quality assurance of risk management | Risk audit |
| Which is the quality control of risk management | Risk review |
| Where the audit format is defined | Risk management plan |
| Who ensures audits are performed | Project manager |
| PMI’s preference for meeting format | Separate audit and review meetings |
Ask 1 question: does the scenario test the process or the risks?
PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.