An NGO risk register is a living management tool that records threats and opportunities, assesses their significance, assigns ownership and tracks action. It helps project teams make risks visible before they become incidents or delivery failures.
Copyable NGO risk-register structure
| ID | Risk statement | Category | Likelihood | Impact | Rating | Controls and actions | Owner | Review date |
|---|---|---|---|---|---|---|---|---|
| R01 | If [cause] occurs, then [event] may happen, resulting in [effect] | Programme/finance/security/compliance | 1–5 | 1–5 | L × I | Existing controls and additional actions | Named role | Date |
Write risks clearly
Use a cause–event–effect format. “Political instability” is a context description, not a complete risk. A stronger statement explains how instability could restrict field access and delay services for targeted communities.
Score likelihood and impact consistently
Define every score. Impact criteria should consider people, programme delivery, finance, safeguarding, reputation and compliance. Agree escalation thresholds so high and critical risks receive management attention.
Distinguish controls from actions
Controls already reduce risk, while actions are additional measures with deadlines. Record the residual rating expected after controls. Avoid vague responses such as “monitor closely” without an owner, frequency or decision threshold.
Cover the full NGO risk landscape
- Context and conflict risks
- Programme quality and delivery risks
- Safeguarding and protection risks
- Fraud, corruption and financial risks
- Procurement and partner risks
- Safety, security and duty-of-care risks
- Data protection and information-security risks
- Donor compliance and reputational risks
Review the register throughout the project cycle
Review risks during design, inception, partner assessment, procurement, programme reviews and close-out. Update the register after incidents, major context changes, or significant budget and scope revisions. Risk information should inform decisions rather than sit in a compliance file.
ATI’s Risk Management in Donor-Funded Projects Course covers assessment, mitigation planning, compliance, monitoring and contingency planning.
Sources: UNDP Portfolio and Project Risk Register Template and GISF Blank Risk Register Template.