The Risk Report in Project Management: Contents, Format, and How to Write One

risk report in project management
Table of Contents
A risk report tells decision makers how risky the project is and what action the project needs from them. It summarizes overall project risk, ranks the top risks, shows the trend, and lists decisions requested. A good risk report fits on one page and ends with a request.

This guide covers what a risk report contains, how to write one step by step, which visuals to use, who reads it, when to issue it, and how it appears on the PMP exam.

What Is a Risk Report in Project Management?

what is risk report

A risk report is a project document that presents the sources of overall project risk, the current level of overall risk, and summary information on individual risks. It communicates risk status to stakeholders at a point in time and supports their decisions.

The PMBOK Guide Sixth Edition creates the risk report in Identify Risks and updates it in every later risk process. It draws on the risk register. The register lists every risk in detail for the team. The report turns that detail into a summary for readers who need a decision, not a data set.

Risk report, risk management report, and risk status report describe the same document. A risk analysis report is a related output: the numeric results of quantitative analysis. A later section covers it.

What Does a Risk Report Contain?

A risk report contains 9 sections: overall status, top risk drivers, top risks, trend, category distribution, response progress, occurred risks, reserve status, and decisions requested. Each section answers a question the reader would otherwise ask.

Section Content Question it answers
Overall status Red, amber, or green rating with a one-line reason How risky is the project now?
Top risk drivers The sources that contribute most to overall exposure What drives the risk?
Top risks The 5 to 10 highest-scoring risks with owner and response Which risks matter most?
Trend Change in open risks and total exposure since the last report Is risk rising or falling?
Category distribution Risks and exposure by category, such as technical or commercial Where does risk concentrate?
Response progress Status of planned actions, and overdue actions Are the responses working?
Occurred risks Risks that became issues, with cost and schedule impact What already happened?
Reserve status Contingency reserve approved, used, and remaining Is there enough protection?
Decisions requested Approvals, funding, or escalations needed What do you need from us?

Add an outlook line: the expected level of overall risk at the next reporting date.

How Do You Write a Risk Report Step by Step?

Write the report in 7 steps: define the reader and question, pull the data from the register, rank and summarize, add the overall view, state the decisions needed, apply the format, and check the numbers. Lead with the answer.

  1. Name the reader and the decision the report must support.
  2. Pull the current data from the risk register, not from memory.
  3. Rank the risks by score, and keep the top 5 to 10.
  4. Add the overall view: the status rating, the trend, and the reserve balance.
  5. Write the decisions and support requested, each with a date.
  6. Apply the project’s standard format, so every report looks the same.
  7. Check that every number matches the register and that the date is on the page.

Follow 5 writing standards:

  • Lead with the overall status and its one-line reason.
  • Define each color rating once, in a legend the reader sees.
  • Name an owner beside every risk and every action.
  • State units and the period covered on every number.
  • Cut any section that does not change a decision.

Which Formats and Visuals Work Best in a Risk Report?

Use a status rating, a top-risks table, a heat map, and a trend chart. Each visual answers one question. Add a reserve gauge and a category chart when the reader needs them. Cut any visual that does not change a decision.

Visual Shows Use when
Red, amber, green rating Overall risk level Always, at the top
Top-risks table Ranked risks with owner and response Always
Heat map Count of risks in each probability and impact cell The reader wants the shape of the exposure
Trend chart Total exposure or open risks over reporting periods Reports repeat over time
Category bar chart Exposure by risk category Risk concentrates in a few areas
Reserve gauge Contingency reserve used against approved Reserve is a decision topic
S-curve Probability of reaching a cost or schedule target Quantitative analysis exists

Consistency beats novelty. Readers learn where to look, and a change in the pattern stands out.

Who Reads the Risk Report and What Do They Need?

The sponsor needs decisions, the steering committee needs escalations and trends, the PMO needs comparable data, and the team needs context. Match the length and detail to the reader, and follow the communications management plan for distribution.

Reader Needs Length Typical cadence
Sponsor Overall status, decisions, reserve 1 page Each reporting cycle
Steering committee Trends, escalations, top risks 1 to 2 pages Monthly or at gates
PMO Comparable status across projects Standard template Monthly
Project team Context for their own risks Register plus a summary Weekly
Customer Risks named in the contract As the contract requires As agreed

PMTI’s guide What is a Risk Register in Project Management? covers the register that feeds the report.

How Often Do You Issue a Risk Report?

Issue the risk report at each reporting interval, at each phase gate, and whenever a critical event occurs. The PMBOK Guide updates it in every risk process. Consistency matters more than the exact interval, so match the cadence to the sponsor’s decision cycle.

Report type Trigger Content
Routine Each reporting interval, often monthly Full one-page report
Gate Each phase gate Full report plus the response results for the phase
Exception A critical risk occurs, or a threshold is crossed Short alert with impact and the decision needed

Set the cadence in the risk management plan. PMTI’s guide Project Risk Management Process, Tools & Templates walks through the plan and the risk processes that update the report.

What Is a Risk Analysis Report?

A risk analysis report presents the numeric results of quantitative risk analysis: the probability of meeting cost and schedule targets, confidence-level figures from a simulation, and sensitivity to each risk. Its results feed the overall status in the risk report.

Element What it shows Example (illustrative)
Probability of meeting the target Chance of finishing at or below the budget About 55% chance of finishing within $1,000,000
Confidence-level costs Cost at each confidence level 50%: $985,000. 80%: $1,060,000. 90%: $1,110,000
Sensitivity (tornado chart) Which inputs move the result most Supplier price 32%, scope change 24%, labor productivity 18%, currency 12%, other 14%
Contingency implied Gap between a chosen confidence level and the base estimate 80% level less $1,000,000 base = $60,000

The risk report carries the headline. It states the probability of meeting the target and the top drivers. The risk analysis report holds the method and the full output for readers who test it.

Which Incidents Go to the Risk Manager?

Report an incident to the risk manager when it crosses a defined threshold: exposure above the risk threshold, a high-priority trigger firing, an impact above tolerance, a legal, safety, or regulatory event, or a matter outside the project manager’s authority.

Escalation criterion Example Route
Exposure above the risk threshold A risk score rises above the agreed limit Sponsor and risk manager
High-priority trigger fires A supplier misses a critical milestone by 5 days Sponsor
Impact above tolerance An occurred risk pushes cost past the approved variance Sponsor and steering committee
Legal, safety, or regulatory event A data breach or a site injury Risk manager, legal, and sponsor at once
Outside project manager authority A response needs funding the project cannot approve Sponsor
Near miss with high potential A control failed but no loss followed Risk manager

Define the criteria and the reporting time in the risk management plan. One university risk management policy sets a 24 to 48 hour window for high-risk incidents. Hospital risk managers apply the same principle: adverse events such as wrong-site surgery go to the risk manager under a defined policy.

How Do Risk Reports Roll Up to Program and Portfolio Levels?

Project risk reports roll up into program and portfolio risk reports. The program report adds dependencies between projects. The portfolio or enterprise report compares total exposure with risk appetite and shows concentration by category. Each level uses the same definitions.

Level Focus Key content Reader
Project Individual risks and overall project risk Top risks, trend, reserve, decisions Sponsor
Program Cross-project dependencies and shared risks Risks that span projects, benefit risks Program board
Portfolio or EPMO Exposure against appetite Total exposure, concentration by category, top risks across projects Executive committee

Shared definitions make the roll-up work. If each project scores probability on a different scale, the portfolio report adds up disagreements.

What Mistakes Weaken a Risk Report?

6 mistakes weaken a risk report: dumping the whole register, omitting decisions, changing formats each period, using colors without definitions, hiding bad news behind a green rating, and reporting stale data. Each one costs the reader’s trust or time.

Mistake Effect Fix
Dumping the whole register The top risks are buried Cut to the top 5 to 10
No decisions requested The report informs and moves nothing End with a decision list
A new format each period Readers cannot compare Fix the template for the project
Colors with no definitions Ratings mean different things to different readers Add a legend
Green on top, red underneath Bad news stays hidden until it is too late Rate overall status from the worst top risk
Stale data Readers act on old exposure Date the report and refresh it from the register

How Do Risk Reports Work in Agile and Hybrid Projects?

How Do Risk Reports Work in Agile and Hybrid Projects?

Agile and hybrid teams report risk in short, frequent forms: a risk section in the sprint review, a risk view in release readiness reviews, and a risk board at planning. The report keeps the same core: status, top risks, and decisions needed.

  • Show the top risks and their trend in each sprint review.
  • Include a risk view in every release readiness review.
  • Use a risk board at program increment planning, with each risk marked resolved, owned, accepted, or mitigated.
  • Escalate any risk that crosses the team’s threshold to the product owner or sponsor.

Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.

How Is the Risk Report Tested on the PMP Exam?

PMP questions test what the risk report contains, when it is created, and who reads it. The report presents overall project risk and summary information on individual risks. Identify Risks creates it, and every later risk process updates it.

Scenario cue Answer
A sponsor asks how risky the project is Risk report
Which process creates the risk report Identify Risks
Which processes update it Qualitative, quantitative, plan responses, implement responses, monitor risks
A document lists sources of overall project risk Risk report
The report lists each risk’s trigger and fallback plan Risk register, not the report
The manager must tell stakeholders the status of risk Risk report, distributed per the communications plan
An audit finds gaps Findings appear in the risk report

Read for the audience. Executive and overall points to the report. Detail and ownership points to the register.

PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.

 

Picture of Yad Senapathy

Yad Senapathy

Founder & CEO of PMTI with 20+ years in project management. He has contributed to the PMBOK® Guide & developed multiple certification programs including PMP and CAPM.
Yad Senapathy
Yad Senapathy

Your project managers will be trained on the PMI PMBOK Guide's best practices and ethics. They'll understand the framework of a successful project from initiating to close.

Share this article
Twitter
Facebook
Linkedln
whatsapp
telegram
pinterest
Get in Touch With Us