Procurement Risk Register Example
A full worked example for procurement teams. Replace the sample numbers with your own project, supplier, contract, or approval data before using the wording in a live file.
Visual example: file-note structure
A risk register is only useful when it drives follow-up action.
Situation
A project has several active procurement packages. One imported equipment package is technically approved, but supplier documents for shipment are late, payment is pending, and the required site date is close.
The buyer needs a risk register line that management can review quickly during the weekly procurement meeting.
Inputs
| Input | Example entry |
|---|---|
| Risk description | Late shipping documents may delay customs clearance |
| Likelihood | 4 out of 5 |
| Impact | 5 out of 5 |
| Risk score | 20 - high |
| Owner | Buyer with logistics coordinator |
| Mitigation | Daily document follow-up and draft customs pack review |
| Due date | Before supplier dispatch |
Decision
This risk should be escalated because late documents can hold cargo at port even when production is complete. The mitigation owner must confirm certificate of origin, packing list, invoice, test certificates, and shipping documents before dispatch.
Register wording
Suggested wording: High risk of customs delay due to incomplete supplier shipping documents. Buyer to obtain full document pack before dispatch and logistics coordinator to pre-check customs requirements. Review daily until document pack is approved.
What to watch before using this
A risk register fails when it becomes only a list. Every high-risk line should show a named owner, mitigation action, due date, and next review point. Avoid vague actions such as "follow up supplier" without saying what document, date, or decision is required. If the same risk stays open for more than one review cycle, escalate the owner or change the mitigation.
How this would sit in an approval file
In a real procurement review, the risk register line should sit beside the package tracker and action log. The buyer should state the risk, cause, impact, probability, severity, owner, mitigation action, due date, and current status. A strong entry is specific enough that another person can follow it without asking the buyer to explain the background again.
The register should not be used only for reporting. It should drive action. If the risk is late approval, the action may be an escalation meeting. If the risk is supplier capacity, the action may be a factory confirmation and backup quote. If the risk is payment exposure, the action may be revised payment terms or a guarantee requirement.
Common mistakes in this situation
- Writing generic risks such as supplier delay without naming the real cause.
- Leaving risk owners blank or assigning every action to procurement.
- Keeping closed risks open because nobody updates the status.
- Recording risks without mitigation actions or target dates.
Manager review wording: This risk should remain open until the owner completes the mitigation action and procurement confirms the package is no longer exposed on cost, delivery, or approval.
Buyer review checklist
Before adding this risk to the register, the buyer should make sure the entry is specific enough to trigger action. A useful risk line names the package, the supplier or approval point, the likely impact, the owner, and the next action. If the risk is written too generally, such as possible delay, it will sit in the register without changing behavior.
The buyer should also decide when the risk can be closed. Closure criteria may be approved submittal, confirmed production slot, shipment released, documents received, payment guarantee issued, or delivery completed. Without closure criteria, old procurement risks remain open and the register loses credibility.
Evidence to attach
- Supplier quotation, technical request, or project instruction.
- Calculation output from the matching I Love Procurement tool.
- Emails, approvals, dates, or supplier evidence supporting the assumptions.
- The matching template download completed with your real values.
