Project Management: Foundations to Practice · Risk Management
Monitoring Risks Throughout the Project
A risk register that is thorough at kickoff but frozen thereafter provides false comfort. This chapter covers what genuine, continuous risk monitoring actually looks like.
Risk management does not end once response strategies are assigned. ISO 31000 emphasizes that monitoring and review must run continuously throughout an activity's life, since risk conditions change as new information emerges and previously unlikely risks can become imminent, sometimes rapidly and with little warning if nobody is actively watching for the relevant signals [23].
Key Takeaways
- ISO 31000 requires continuous monitoring and review, since risk conditions change and previously unlikely risks can become imminent.
- Risk registers should be revisited at regular intervals (weekly or monthly), not treated as a static, one-time planning artifact.
- Risk triggers convert a vague ongoing worry into a specific, observable condition, making monitoring efficient rather than exhausting.
- A stale risk register creates false security, since it stops reflecting the project's actual current risk exposure almost immediately.