Risk Management in Projects – Hillson's Active Risk Cycle
Many projects have a risk register that was created at kickoff, got ten rows — and was never opened again. David Hillson, one of the world's best-known risk researchers and consultants in project risk management, has spent his career explaining why that isn't enough. In his book Managing Risk in Projects, he sums up what risk management really is: not a list, but an active cycle.
Hillson's approach has shaped international standards in the field, and it is surprisingly practical. It is about making uncertainty manageable — before it has time to become a problem. For a project manager, that is good news: risk management requires no advanced mathematics, just a structured way of working that is actually carried out and kept alive throughout the project.
What does the research say?
Hillson's definition of risk is pithy: risk is uncertainty that matters. Everything in a project is uncertain, but only the uncertainty that can affect the project's objectives deserves your attention. The definition also covers two kinds of risk: threats, which can harm the objectives, and opportunities, which can benefit them. Chasing only threats is, according to Hillson, doing half the job.
He describes the management itself as a recurring cycle. First the risks are identified — what could happen that affects the objectives? Then each one is assessed for probability and impact, so the most important ones rise to the top. After that, a deliberate response is chosen for every significant risk: avoid it, reduce it, transfer it to another party, or accept it with eyes open. Opportunities have mirror-image responses, such as enhancing or exploiting them.
The decisive final step is follow-up. Every response should have an owner and a deadline, and the cycle should turn again at regular intervals, because old risks die and new ones are born as the project moves along. A risk assessment without owners, dates and follow-up is, according to Hillson, just documentation — not risk management. The difference between the two is rarely visible in the documents, but always in how the project copes when something unexpected happens.
What does this mean for you as a project manager?
Give every risk an owner and a date. When the risk workshop ends, no action should be left floating. 'We should keep an eye on the supplier' is not an action — 'Anna checks the delivery plan with the supplier by Friday' is.
Prioritise by probability and impact — and dare to cut. A list of thirty unassessed risks protects no one. Assess, sort, and put your energy into the handful of risks that could actually sink the project. Watch the rest with a light touch — and strike them off with a clear conscience when they are no longer relevant.
Put risks on the agenda, every time. A standing item at the project meeting — which risks have changed, which are new, which can we close? — costs ten minutes and is the difference between a living cycle and a dead list. Don't forget to ask about opportunities too.
How to practise this
Risk management largely happens in conversations: leading a risk workshop where everyone dares to contribute, getting a reluctant line manager to take ownership of an action, or telling the steering group about a risk that has grown — without sugar-coating or scaremongering. In Project-simulator you practise those conversations against AI counterparts in a safe simulator environment, with evidence-based feedback that points to your own wording. You can try it free for a week.
In Project-simulator you practice these conversations against an AI counterpart and get feedback grounded in research like this.
Try free for 7 days