Risk Owners vs Action Owners


Risk Owners vs Action Owners

A risk register in which the project manager's name appears in the owner column of every row is not a record of ownership. Neither is one where the owner is a team, a supplier or a department, because none of those will notice anything, judge anything or make a decision. The name is there because the column demanded a name.

The distinction worth holding onto is simple to state and surprisingly easy to lose. The risk owner is accountable for the risk itself: for watching it, for judging whether the exposure is growing or shrinking, for deciding whether the current response is working, and for saying when it has become an issue or is no longer worth managing. The action owner is accountable for delivering one specific response by an agreed date. Sometimes the same person holds both. Often they should not.

The two questions behind every row

Every managed risk is really asking two separate questions, and a register that only answers one of them will drift.

The first question is who is watching. Risks change without anyone deciding they should. A supplier's delivery confidence erodes over six weeks, a regulatory consultation closes earlier than expected, a key integration turns out to depend on a version that is being withdrawn. Somebody needs to be close enough to notice the change, and to have the standing to say so before it becomes a matter of fact rather than probability. That is the risk owner's work, and it continues whether or not any response action is currently open.

The second question is who is doing something. A response action is ordinary project work: it has a scope, an owner, a date and a definition of done. A single risk can carry three or four actions with different owners in different teams, and one of them may sit with a supplier or with the client. None of those people is thereby the risk owner. They have each agreed to complete a piece of work, which is a narrower and much more finite commitment.

The Risk Performance Domain in Section 2.7 of the PMBOK® Guide treats responses as work that must be actionable and owned rather than simply recorded, and the same logic applies one level up. A risk that is documented but not held by anyone with the attention and authority to manage it has been described, not managed.

Choosing an owner who can actually see the risk

Most bad ownership decisions come from assigning the risk to whoever raised it, or to whoever is senior enough to sound like a safe answer. Three questions produce better allocations.

Who will notice first if this changes? Proximity beats seniority here. If the risk concerns test environment stability, the person who will see the pattern shift is not the programme director. Ownership placed too far from the work turns into a monthly request for an update.

Who can influence it, or authorise someone who can? An owner with no route to action can only report deterioration. That is not useless, but it is not ownership either, and it should be a signal that the risk may belong somewhere else.

Who will be believed? Unwelcome risk information travels badly. If the owner has no credibility with the people who would need to fund a response or change a commitment, the risk will be visible in the register and invisible in decisions.

Where a risk fails all three tests at project level, it usually belongs above the project. Dependency on another programme's delivery date, a shortage of a scarce specialist skill across the organisation, an unresolved commercial position with a supplier: these are frequently owned by a sponsor, a portfolio lead or a functional head, with the project manager holding the actions and the reporting. Pushing an organisational risk down to a delivery team is one of the quieter ways of losing it.

Finished actions and unfinished risks

The failure mode that matters most is the one that looks like success. Every response action against a risk is complete, every date has been met, and the exposure has not moved.

Consider a payroll system implementation for a housing association. The registered risk is that poor data quality in the legacy records will delay migration and force a phased cutover. Three actions are agreed: the data lead runs a profiling report, the business analyst agrees cleansing rules with the client, and the client's HR manager cleanses the affected records. All three are delivered, on time, and the actions are closed.

What nobody tracked is the cleansing rate. The rules were agreed for around 9,000 records on the assumption that the client could work through roughly 800 a week. Six weeks in, the actual rate is closer to 250, because the HR manager is doing it alongside a full job. Every action owner has fulfilled their commitment. The risk is materially worse than when it was raised, and it now has no open actions against it, which in many registers is indistinguishable from being under control.

A risk owner who was watching the exposure rather than the action list would have seen this in week two. That is the whole practical value of separating the two roles: action owners report completion, and only the risk owner is positioned to report that completion did not achieve anything. Where a response introduces new exposure, as a phased cutover would here, the same person is the one who has to raise the secondary risk rather than quietly absorbing it.

Two habits make this concrete. First, give each significant risk a review rhythm and, where possible, an observable trigger, so that monitoring is a scheduled act rather than a good intention. Second, close risks deliberately, on the owner's judgement that exposure has fallen, and never automatically because the last action has been ticked.

Ownership when there is no register

None of this depends on a formal register. In adaptive and hybrid delivery the mechanics change and the accountabilities do not.

Response work usually sits in the backlog, sized and pulled like anything else, which makes action ownership straightforward: whoever takes the item owns it for that iteration. Risk ownership is where adaptive teams sometimes get into difficulty, because collective responsibility is genuinely a strength of a well-formed team and it is a poor substitute for a named person on a specific exposure. "The team owns it" is fine when the team meets daily and the risk is inside its work. It is a way of nobody owning it when the risk concerns a supplier, another programme, or a decision the team cannot make.

A workable pattern in hybrid delivery is to let the team hold and work the risks inside its own delivery, with a named person for each of the few that cross a boundary, and to review those at whatever cadence the wider governance already runs at. The formality should follow the risk, not the methodology label attached to the project.

For a PMP candidate, this is one of those distinctions that is easy to recognise in a definition and easy to miss in a scenario. Questions that describe a completed mitigation with an unchanged situation are asking whether you understand that the two are separate. The current Examination Content Outline places risk work in the Business Environment domain, which accounts for 26% of exam items, and includes maintaining a risk register, communicating risk impact status and recognising when a risk has become an issue among its enablers. That last one is a risk owner's judgement, not an action owner's. Practising that separation across unfamiliar scenarios, rather than on the projects you already understand, is much of what structured PMP® exam preparation is for.

On a live project, the useful exercise takes about half an hour. Open the register, ignore the descriptions, and read only the owner column. For each name, ask whether that person would notice a change without being asked, whether they can influence the risk or reach someone who can, and whether anyone would act on their warning. Then look for rows where every action is closed and nothing about the situation has actually improved. Those two passes will tell you more about how risk is really being managed than any amount of rescoring probability and impact.

Andre Malowney

Interested in going further?

Deciding who should hold a risk, and keeping that separate from who delivers the response, is the kind of judgement that gets tested in unfamiliar situations rather than familiar ones. Omega's PMP® Exam Preparation works through risk accountability in predictive, adaptive and hybrid settings, so the reasoning still holds when the next project looks nothing like the last one.

The Risk Performance Domain in the PMBOK® Guide Eighth Edition sets out how response ownership sits alongside monitoring and reporting, for readers who want the fuller treatment.

Ad · Amazon affiliate link.

References

A152: The PMBOK 8 Risk Performance Domain: What It Really Covers
A154: When Does a Risk Become an Issue?
A157: Do Agile and Hybrid Projects Still Use Risk Registers?
A165: Tailoring Risk Management to the Project
A160: Qualitative vs Quantitative Risk Analysis

PMP and PMBOK are registered marks of the Project Management Institute, Inc.