This guide defines the risk audit, compares it with the risk review, and covers who audits, what the audit examines, how to run one, and how it appears on the PMP exam.
What Is a Risk Audit in Project Management?
A risk audit is a systematic examination of the effectiveness of the risk management process and its responses. The PMBOK Guide lists audits as a technique in Monitor Risks. The project manager ensures audits run at the frequency set in the risk management plan.
The risk management plan defines the audit’s format and objectives before it starts. The audit produces documented findings and recommendations. Results flow into the risk report, the risk management plan, and the lessons learned register.
An audit checks evidence, not opinions. It asks whether the register, the response actions, and the reserve records match what the plan promised.
PMTI’s guide Project Risk Management Process, Tools & Templates walks through the risk processes, including Monitor Risks, where the audit sits.
Why Do Projects Run Risk Audits?

Projects run risk audits for 5 reasons: to verify that responses reduced exposure, to confirm that the team followed the plan, to test whether risk identification was complete, to check reserve use, and to capture lessons for later projects.
| Purpose | Question the audit answers | Example finding |
| Response effectiveness | Did the response lower the risk score as planned? | Mitigation for R7 cut probability from 40% to 15% |
| Process compliance | Did the team follow the risk management plan? | 5 of 21 open risks have no owner |
| Identification completeness | Did the team find the risks that occurred? | 3 of 9 issues were never in the register |
| Reserve control | Was the reserve drawn against registered risks? | 30% of the contingency reserve is spent, and 2 draws have no risk ID |
| Learning | What does the next project change? | Add a supplier-failure prompt to the risk checklist |
What Is the Difference Between a Risk Audit and a Risk Review?
A risk audit looks backward and tests the effectiveness of the risk management process and its responses. A risk review looks forward and updates the register, ratings, and plan. Audits run less often. Reviews run at every status cycle.
| Attribute | Risk audit | Risk review |
| Direction | Backward: what happened and whether it worked | Forward: what happens next |
| Focus | Process and response effectiveness | Individual risks and their ratings |
| Frequency | At milestones, gates, or set intervals | Weekly, or at each status meeting |
| Output | Findings, recommendations, corrective actions | Updated register, new risks, revised ratings |
| Independence | Often independent of the day-to-day team | Run by the project team |
| Analogy | Quality assurance of the risk process | Quality control of the risk results |
PMI guidance suggests holding audit meetings separately from review meetings, so that the check on the process stays apart from the check on the results. Use both. A team that reviews without auditing never learns why its responses fail.
What Does a Risk Audit Examine?
A risk audit examines 8 areas: plan compliance, risk identification, analysis quality, response effectiveness, ownership and triggers, reserve use, reporting, and lessons learned. Each area has a test question and a body of evidence to review.
PMTI’s guide What is a Risk Register in Project Management? covers the register that most of this evidence comes from.
| Area | Test question | Evidence |
| Plan compliance | Did the team use the agreed methods, scales, and cadence? | Risk management plan, meeting minutes |
| Identification | Were the risks that occurred already registered? | Register versus issue log |
| Analysis quality | Were probability and impact scored on the defined scales? | Register scores, scale definitions |
| Response effectiveness | Did residual scores fall as planned? | Register history, response actions |
| Ownership and triggers | Does every risk have an owner and a trigger? | Register fields |
| Reserve use | Do draws tie to registered risks and approvals? | Cost records, change log |
| Reporting | Did sponsors receive the risk report on schedule? | Risk reports, distribution records |
| Lessons learned | Did the team record and apply lessons? | Lessons learned register |
A large organization’s audit can also test the link between project risks and organizational risks. One PMI conference paper on a telecom equipment supplier describes an independent expert audit that checks how good the team is at identifying risks, how granular the register is, and whether mitigation and contingency plans worked. It calls this an aid to improve risk quality, not a process-adherence audit.
Who Conducts a Risk Audit?

A risk audit can be run by the project manager, the PMO or quality function, independent experts, or an external auditor. The PMBOK Guide makes the project manager responsible for ensuring audits happen, not for performing them. Independence strengthens assurance.
| Auditor | Independence | Best fit |
| Project manager and team (self-audit) | Low | Small projects, interim checks |
| Peer project manager | Medium | Programs with several projects |
| PMO or quality function | Medium to high | Organizations with standard risk methods |
| Independent domain experts | High | Large, complex, or high-risk projects |
| External auditor | Highest | Regulated or contractual assurance |
Choose independence in proportion to exposure. A self-audit is quick and biased. An independent audit costs more and finds more.
How Do You Run a Risk Audit Step by Step?
Run a risk audit in 8 steps: set objectives and scope, choose the auditor and dates, collect evidence, test a sample of risks, interview owners, assess against criteria, report findings, and agree corrective actions. Record the audit and its conclusions.
- Set the objectives, scope, and criteria in the risk management plan before the audit starts.
- Choose the auditor and schedule the audit around a milestone or phase gate.
- Collect the evidence: register, risk reports, minutes, response records, and reserve logs.
- Test a sample, such as the 10 highest-scoring risks plus every risk that occurred.
- Interview risk owners on triggers, actions, and results.
- Rate each area against the criteria.
- Write the findings, each with evidence, a rating, and a recommendation.
- Agree corrective actions with owners and dates, update the risk management plan, and log the lessons.
Sampling keeps the audit affordable. Test the highest-priority risks and every risk that already occurred, because those show whether the process works.
How Do You Score and Report Audit Findings?
Rate each area as compliant, partially compliant, or a gap, and attach a severity to every finding. Report each finding with its evidence, its cause, a recommendation, an owner, and a due date. Track corrective actions to closure.
Example findings from one audit:
| Finding | Evidence | Rating | Recommendation | Owner | Due |
| 5 of 21 open risks have no owner | Register review | Gap, high | Assign owners at the next risk review | Project manager | Next status meeting |
| 3 of 9 issues were never registered as risks | Issue log versus register | Partial, medium | Add a supplier-failure prompt to the identification checklist | Risk lead | 2 weeks |
| Reserve draws lack risk IDs | Cost records | Gap, high | Require a risk ID on every draw request | Cost controller | 2 weeks |
| Probability scored on 2 different scales | Register history | Partial, medium | Reissue the agreed scale, and re-score affected risks | Risk lead | 1 month |
| Risk report reached the sponsor on time | Distribution records | Compliant | None |
Every gap needs an owner and a date. A finding without both reads as an opinion and gets ignored.
How Often Should You Audit Project Risk?
Set the audit frequency in the risk management plan. A small project needs one audit near the end of the main work. A large or long project needs a series at milestones or phase gates. Trigger an unscheduled audit when warning signs appear.
| Project profile | Typical audit rhythm |
| Small, short | One audit before closure |
| Medium | At each major milestone |
| Large, complex, or long | At each phase gate, plus an annual independent audit |
| Any project | Unscheduled, when a trigger below fires |
Call an unscheduled audit when any of these conditions appears:
- Risks that the register rated low occur more than once.
- The contingency reserve is drawn heavily early in the project.
- Several issues surface that were never registered.
- A phase gate fails for risk-related reasons.
- A major scope or contract change lands.
How Do You Audit Risk Metrics?
Audit risk metrics by comparing what the team predicted with what happened. Track the share of identified risks that occurred, the share of issues that were never registered, the reserve drawn against registered risks, and the change in residual scores after responses.
The first 2 metrics appear in a PMI conference paper on a telecom supplier’s risk framework. Example, on a project with 40 identified risks and 9 issues:
| Metric | Calculation | Example result | Reading |
| Occurrence rate | Risks that occurred ÷ risks identified | 6 ÷ 40 = 15% | Compare with the average probability the team assigned |
| Unregistered issue rate | Issues never in the register ÷ all issues | 3 ÷ 9 = 33% | Identification missed a third of what happened |
| Reserve traceability | Draws with a risk ID ÷ all draws | 8 ÷ 10 = 80% | 2 draws lack support |
| Response effect | Average score before minus after responses | 14 to 8 | Responses cut exposure by 43% |
A high unregistered issue rate points to weak identification. A low occurrence rate with heavy response spend points to over-response. Report both.
Is a Project Risk Audit the Same as Audit Risk in Financial Auditing?
No. A project risk audit examines how a project manages risk. Audit risk, in financial auditing, is the chance that an auditor issues an unqualified opinion on financial statements that contain a material misstatement. The 2 terms share words and nothing else.
| Term | Field | Meaning |
| Project risk audit | Project management | Examines the effectiveness of the risk management process |
| Audit risk | Financial auditing | Risk of a wrong opinion: inherent risk × control risk × detection risk |
| Risk assessment procedures | Financial auditing (ISA 315) | Inquiry, observation, inspection, and analytical procedures to assess risks of misstatement |
Audit risk mitigation in the financial sense means adjusting the amount of testing. When inherent and control risk are high, the auditor lowers detection risk by testing more. Project teams do not use this model. They use the risk register, the risk report, and the audit steps above.
How Does a Risk Audit Differ From a Project Audit?
A project audit examines project management practice across scope, schedule, cost, quality, and governance. A risk audit is the part that examines risk management. The PMBOK Guide names 3 related audits: risk audits, quality audits, and procurement audits.
| Audit | Examines | PMBOK process |
| Risk audit | Effectiveness of the risk management process and responses | Monitor Risks |
| Quality audit | Whether quality processes and standards are followed | Manage Quality |
| Procurement audit | Whether the procurement process and contracts are followed | Control Procurements |
| Project audit (health check) | Overall project performance, methods, and governance | Organization-defined |
Organizations often combine them in one project health check. A combined audit uses the same steps as the risk audit above, with a wider scope and criteria for each area.
How Do Risk Audits Work in Agile and Hybrid Projects?
Agile and hybrid teams run lightweight risk audits at release boundaries or quarterly. The audit checks the risk items in the backlog, the response results, and the retrospective actions. The findings feed the next release plan.
- Audit at release boundaries, or every 3 months on long-running products.
- Sample the top-ranked risk items and every risk that occurred.
- Compare retrospective actions with results.
- Feed findings into release planning and the team’s working agreements.
Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.
How Are Risk Audits Tested on the PMP Exam?
PMP questions test the audit’s process home, purpose, and difference from a risk review. A risk audit sits in Monitor Risks, evaluates the effectiveness of the risk management process, and looks backward. A risk review looks forward and updates the register.
| Scenario cue | Answer |
| The team examines whether its risk responses and process worked | Risk audit |
| The team reassesses risks and updates ratings for the next phase | Risk review |
| Which process includes audits | Monitor Risks |
| Where the audit’s format and frequency are defined | Risk management plan |
| Who ensures audits are performed | Project manager |
| An audit finds gaps in the plan | Change request and risk management plan update |
| Audit results appear in | Risk report and lessons learned register |
Read the direction of the question. Backward-looking and process-focused points to the audit.
PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.