# Risks & updates

> The project risk register and the period-based status narrative - the two records that make governance meetings short.

Source: https://app.assetlab.ca/docs/projects/risks-and-updates

Schedule and budget say how the project *is*; risks and updates say how it's *going* - and going to go. These two lightweight records replace the status PowerPoint nobody can find later.

## The risk register

Each project carries its own **risk register**. A risk entry has:

- **Description** - what could happen ("winter arrives before roof membrane complete")
- **Category** - technical, financial, schedule, resource, or external
- **Probability and impact** - scored, combining into a severity band
- **Mitigation and contingency** - what you're doing to prevent it, and the plan if it lands anyway
- **Owner, due date, and status** - who's watching it and by when; status moves through identified → analyzing → mitigating → resolved (or accepted)

Risks also plot on a **probability × impact matrix**, so the meeting can look at one grid instead of reading twenty rows.

This is the project-delivery cousin of [asset risk](/docs/asset-management/risk-and-fci) - same discipline, different subject. The register is a living list: review it at each project meeting, resolve what's passed, add what's emerged.

> [!tip] Write risks as events, not worries. "Supplier lead time exceeds 12 weeks" can be watched and mitigated; "supply chain issues" cannot.

## Project updates

An **update** is a status entry posted against a reporting **period**: pick the cadence (bi-weekly, monthly, quarterly, bi-annual, or annual), the year, and the period, then write the narrative - progress, decisions, what's next. The timeframe and period lock once the update is created, which is the point: updates form a regular series, not a loose pile of notes.

Updates are the project's memory:

- The board summary drafts itself from the last few periods.
- A new PM inheriting the project reads the updates in order and knows the story.
- Disputes about "when did we know X" resolve by period.

Post on the cadence you chose, and mention every milestone hit and every approved [change order](/docs/projects/budgets-and-financials) in the period it happened.

## Comments vs. updates

**Comments** (the project's Activity tab) are conversation - questions, quick answers. **Updates** are record - deliberate period entries. Keep the distinction and both stay useful; blur it and updates drown in chatter.

## The governance loop

1. Before the meeting: skim open risks, the latest update, and the [financials](/docs/projects/budgets-and-financials) view.
2. In the meeting: decisions, not archaeology.
3. After the meeting: capture decisions in the current period's update; adjust risks accordingly.

An AI assistant connected via [MCP](/docs/ai) can assemble step 1 into a briefing across *all* active projects - see [example workflows](/docs/ai/example-workflows).
