An NGO risk register is a living management tool that records threats and opportunities, assesses their significance, assigns ownership and tracks action. It helps project teams make risks visible before they become incidents or delivery failures.

Copyable NGO risk-register structure

ID Risk statement Category Likelihood Impact Rating Controls and actions Owner Review date
R01 If [cause] occurs, then [event] may happen, resulting in [effect] Programme/finance/security/compliance 1–5 1–5 L × I Existing controls and additional actions Named role Date

Write risks clearly

Use a cause–event–effect format. “Political instability” is a context description, not a complete risk. A stronger statement explains how instability could restrict field access and delay services for targeted communities.

Score likelihood and impact consistently

Define every score. Impact criteria should consider people, programme delivery, finance, safeguarding, reputation and compliance. Agree escalation thresholds so high and critical risks receive management attention.

Distinguish controls from actions

Controls already reduce risk, while actions are additional measures with deadlines. Record the residual rating expected after controls. Avoid vague responses such as “monitor closely” without an owner, frequency or decision threshold.

Cover the full NGO risk landscape

  • Context and conflict risks
  • Programme quality and delivery risks
  • Safeguarding and protection risks
  • Fraud, corruption and financial risks
  • Procurement and partner risks
  • Safety, security and duty-of-care risks
  • Data protection and information-security risks
  • Donor compliance and reputational risks

Review the register throughout the project cycle

Review risks during design, inception, partner assessment, procurement, programme reviews and close-out. Update the register after incidents, major context changes, or significant budget and scope revisions. Risk information should inform decisions rather than sit in a compliance file.

ATI’s Risk Management in Donor-Funded Projects Course covers assessment, mitigation planning, compliance, monitoring and contingency planning.

Sources: UNDP Portfolio and Project Risk Register Template and GISF Blank Risk Register Template.