
Software projects are complex, dynamic, and full of uncertainties. To manage these uncertainties, project managers rely on structured tools like Risk Logs and RAID Logs. While they sound similar, they serve different purposes and complement each other in project governance.
🔹 Define Risk Log
A Risk Log (or Risk Register) is a document that records potential risks that may negatively impact a project. It ensures risks are identified, assessed, and mitigated before they become issues.
📑 Structure of a Risk Log (Mandatory Fields)
- Risk ID
- Risk Description
- Probability (High/Medium/Low)
- Impact (High/Medium/Low)
- Severity (Probability × Impact)
- Mitigation / Contingency Plan
- Owner
- Status (Open/Closed/Mitigated)
- Target Date

🔹 RAID Log
Definition
A RAID Log expands beyond risks. It tracks Risks, Assumptions, Issues, and Dependencies in one place, giving a holistic view of project health.
Structure (Mandatory Fields)
- Risks → Description, Probability, Impact, Owner, Status
- Assumptions → Statement, Validation Plan, Owner, Status
- Issues → Description, Resolution Plan, Owner, Status
- Dependencies → Description, Linked Task/Team, Owner, Status, Due Date
Detailed Example
Same mobile banking app project, RAID Log entries:
| Category | Description | Owner | Status | Action / Plan | Due Date |
|---|---|---|---|---|---|
| Risk | Server downtime during migration | Infra Lead | Open | Add backup server | 20 Sept |
| Assumption | Client will provide test data by 10 Sept | Client PM | Pending | Validate in kickoff | 10 Sept |
| Issue | Test environment not ready | QA Lead | Open | Escalate to infra team | 05 Sept |
| Dependency | Compliance approval required before go‑live | Compliance Officer | Pending | Submit docs early | 25 Sept |
👉 This log captures all blockers in one place, not just risks.


🔹 When to Use Each
- Risk Log → For deep risk analysis, compliance documentation, and executive reporting.
- RAID Log → For day‑to‑day project tracking, Agile ceremonies, and holistic visibility of blockers.
- Best Practice: Use both together — RAID for operational visibility, Risk Log for formal risk management.
🎯 Conclusion
- Risk Log = deep dive into risks only.
- RAID Log = broader tool covering risks, assumptions, issues, dependencies.
- Combined Approach = ensures both breadth and depth in project governance.
Together, they form a powerful toolkit for proactive management, stakeholder trust, and successful delivery in software development.