A risk register is useless when it is written once for approval and never enters the operational conversation. Its purpose is not to prove that risks were considered. Its purpose is to direct attention, money, evidence and decision authority toward uncertainty before that uncertainty becomes loss.
For a large event, one spreadsheet may contain strategic, commercial, technical, safety, protocol and live-operational risks. The register must therefore serve governance without overwhelming the people delivering the event.
The operating model
I use a six-step cycle: establish context, identify, analyse, treat, monitor and learn. The cycle repeats at every phase because the risk picture changes from design to procurement, build, rehearsal, public opening, egress and derig.
- Establish context: Define objectives, risk appetite, legal requirements, scoring criteria and escalation authority.
- Identify: Use workstream workshops, venue walks, supplier reviews, assumptions and lessons from comparable operations.
- Analyse: Assess likelihood, consequence, velocity, proximity and control effectiveness.
- Treat: Avoid, reduce, transfer or accept the risk with a funded and owned action plan.
- Monitor: Track measurable triggers, control evidence, action closure and changes in exposure.
- Learn: Capture incidents and near misses, correct the system and carry the lesson into the next phase.
Every risk has one accountable owner. Action owners may be different, but the risk owner remains responsible for understanding exposure and escalating when controls are not working. For critical safety or statutory matters, ownership and acceptance must align with competent authority; a project score never overrides law, engineering limits or an emergency plan.
Write risks that can be controlled
“Bad weather” is a topic, not a risk. Use cause, event and impact: If forecast wind exceeds the engineered operating limit for a temporary structure, the structure may become unsafe, causing programme suspension, asset damage or guest relocation. The sentence exposes what can be monitored and what must be protected.
A complete entry should contain:
- a unique identifier, category and phase;
- cause, uncertain event and operational consequence;
- inherent likelihood and impact before controls;
- existing preventive and responsive controls, with evidence;
- residual score after controls;
- trigger, trigger source and monitoring frequency;
- risk owner, action owner and action due date; and
- contingency, decision authority and communication route.
Keep assumptions linked. A generator-capacity assumption, for example, can create technical outage, commercial variation and schedule risk. If one assumption expires, every connected risk should be reviewed.
Score, treat and escalate
A probability-impact matrix helps sort attention, but the colour is not the control. Define scoring criteria before the workshop so “possible” and “major” mean the same thing across teams. Add velocity for risks that move quickly and proximity for risks whose decision window is closing.
For every material risk, ask four harder questions:
- What control prevents the event, and how do we know it exists?
- What measurable trigger tells us the risk is changing?
- What is the first safe action, and who can authorize it?
- What cost, time or stakeholder consequence follows the response?
Define escalation thresholds in advance. Examples include a risk score above the event’s tolerance, a failed critical control, an action past its latest useful date, or a trigger that enters amber. Some risks may be accepted, but acceptance must be explicit, recorded and made by a person with the authority to own the consequence.
Look for concentration risk: one supplier, route, power source, approval, data file or specialist may support several workstreams. The register can appear diversified while the operation depends on one hidden point of failure. Map those dependencies and decide whether redundancy, substitution or a protected recovery window is justified.
Move from register to live control
Strategic risks such as permits, budget gaps and supplier capacity need a weekly governance rhythm. Live risks such as crowd pressure, technical outage, medical response, severe weather or transport disruption need short operational monitoring. Do not ask the event-day team to navigate a 150-line project register.
Create a live risk board containing only current high-priority exposures, triggers, owners, first actions and escalation contacts. Review it at shift briefings and command updates. A risk can move into or out of the board as its phase and proximity change.
Triggers must be measurable. “Monitor weather” is weak. A useful instruction identifies the official information source, check times, engineering threshold, escalation point and decision owner. The actual threshold must come from competent specialists and approved plans, never a generic article.
Capture near misses without blame. A barrier almost moved, a radio call was missed or an unauthorized vehicle reached a controlled point: each is evidence that a control was weak. Record the condition, immediate correction and systemic action before the next operational period.
KPI dashboard
The following are recommended operating targets. Calibrate scoring bands and thresholds to event risk, applicable law, competent advice and organizational appetite.
| KPI | Formula | Cadence | Recommended target |
|---|---|---|---|
| Risk ownership | Open risks with owner ÷ open risks × 100 | Each review | 100% |
| Treatment closure | Actions closed on time ÷ actions due × 100 | Weekly; daily final phase | ≥90%; critical actions 100% |
| Control assurance | Critical controls evidenced ÷ critical controls due × 100 | Per phase gate | 100% |
| Overdue high risks | High-risk actions past due | Each governance meeting | 0 |
| Residual exposure | High/critical residual risks ÷ open risks × 100 | Weekly | Downward trend; all accepted |
| Trigger response time | Response initiated time − trigger detected time | Each activation | Within approved plan |
| Near-miss learning closure | Corrective actions closed ÷ near-miss actions due × 100 | Per shift and post-event | 100% critical; ≥90% overall |
Illustrative worked example
Illustrative scenario only; this is not an Ahmed or client outcome. An outdoor event has a temporary scenic element. The competent engineer defines operating limits in the approved design, and the weather provider forecasts conditions approaching the first action threshold.
The inherent risk is scored 4 likelihood × 5 impact = 20 on the project’s illustrative 5×5 matrix. Controls include engineered ballast, a documented inspection, official weather monitoring and a staged show-stop plan. With those controls evidenced, the residual score is assessed at 2 × 5 = 10. This does not make the impact smaller; it reduces the assessed likelihood.
At 14:00 the forecast crosses the agreed amber trigger. The operations manager logs the time, informs the event director and safety lead, and suspends installation of a vulnerable decorative component. Trigger response begins in six minutes, inside the project’s approved ten-minute target. The event director does not wait for a red score: the predefined trigger has already converted uncertainty into action.
Leading and lagging indicators
Leading indicators include overdue treatments, unverified critical controls, trigger trends, expiring assumptions, supplier concentration and risks above appetite. They show where exposure is building while there is still time to intervene.
Lagging indicators include incidents, losses, programme interruptions, claims, emergency activations and near misses. They show how the system performed. A low incident count is not proof of good risk management if control-assurance and near-miss reporting are weak; it may simply mean the team was fortunate or silent.
Evidence and standards
- ISO 31000:2018 sets out principles, a framework and a process for identifying, analysing, treating, monitoring and communicating risk.
- UK HSE: Getting started explains proportionate event planning, risk assessment, competent teams and contractor selection.
- UK HSE: Planning for incidents and emergencies covers clear responsibilities, emergency procedures, evacuation, show stop and testing.
- FEMA/USFA: National Incident Management System provides a shared framework for coordinated incident prevention, response and recovery.


