RR
Risk Register
🔵 Stable🕐 updated 2026-06-08
🔷 SkillSpec L3
pm-operations
Build and maintain a project or product risk register. Use when asked to create a risk register, identify project risks, build a risk matrix, or document risks and mitigations for a programme. Produces a complete risk register with likelihood/impact scoring, RAG status, ownership, and prioritised mitigations.
📚 Based on Risk management — PMI / PMBOK
🗣 Say this to your agent
“Build a risk register for our product launch”“Create a risk matrix for [project name]”“What risks should I document for a data migration project?”“Generate a risk register for our steering committee”“Help me identify and score risks for our Q3 delivery plan”
What to give it
▸Project or product name
▸Project stage — discovery / delivery / launch / live / programme-level
▸Key objectives — what is the project trying to achieve?
▸Known risks — anything already on the team's radar (even informal concerns count)
▸Key dependencies — external vendors, teams, systems, or regulatory approvals
▸Deadline or milestone sensitivity — are there hard dates that cannot move?
▸Audience — who will read this? (internal team / executive steering / external board / regulator)
✅ The bar it holds itself to
Every skill in this library self-verifies — these are this skill's own quality checks, straight from its definition.
✓Every risk has a specific owner — not "the team" or "TBD"
✓Mitigations describe what is actively being done — not "monitor and review"
✓Contingency plans exist for all Critical and High risks
✓Risk descriptions are specific — "vendor may be late" is not specific enough; name the vendor and the dependency
✓Register has been reviewed in the last [X] days
✓Closed risks are archived, not deleted — they provide audit trail
✓Risks are distinguished from issues — a risk is something that might happen; an issue is something that has happened
⚠️ What it refuses to do
Do not assign risks to "the team" or "TBD" — every risk must have a named individual owner
Do not write mitigations as "monitor and review" — mitigations must describe what is actively being done to reduce likelihood or impact
Do not delete closed risks — they provide an audit trail; archive them instead
Do not confuse risks with issues — a risk is something that might happen; an issue is something that has already happened
Do not leave Critical or High risks without a contingency plan — what happens if the mitigation fails must be documented
Install
npx pm-claude-skills add --agent claude # or codex · cursor · gemini · hermes
# or one-line MCP (every skill, any client):
claude mcp add pm-skills -- npx -y pm-claude-skills-mcp
Start with
Related skills
🔌 Embed this skill
Drop this on your blog, docs, or site — it renders a "Run this skill" card:
<div data-pm-skill="risk-register"></div>
<script src="https://mohitagw15856.github.io/pm-claude-skills/embed.js" async></script>
💬 Discussion
Risk Register is one of 1174 open-source professional AI agent skills — all SkillSpec L3.
Try them all in the browser · ⭐ Star on GitHub · Browse the full catalog