Organisations know the most about their project risks at the moment a project ends. The team knows which risks materialised, which were missed entirely, which responses worked, how much contingency was really needed and what they would do differently. Then the team disperses to new work, a lessons-learned report is written if there is time, and it is filed where nobody will read it. The next project team meets the same ground conditions, the same supplier problems, the same interface surprises and the same estimating optimism, and pays for them again.
Risk management that does not learn is expensive ritual. Registers are filled in, matrices coloured and reports sent, but the organisation’s ability to foresee and handle uncertainty does not improve. Learning requires three things: a disciplined way to capture and test what projects experienced, a culture in which people report problems and mistakes early and honestly, and humility about what any risk process can predict, so the organisation builds resilience as well as forecasts.
This article explains how to run risk lessons-learned reviews that produce usable knowledge, how independent project risk audits add evidence, how to close the loop so lessons change practice, how culture determines whether risk information flows, how maturity models help organisations assess themselves, and how to prepare for events no register will predict. It is general information for project managers, sponsors, executives and risk professionals.
Lessons learned and risk audits are different
| Aspect | Lessons learned | Project risk audit |
|---|---|---|
| Who | The project team | People independent of the project |
| Perspective | What did we experience and learn? | What does the evidence show about how risk was managed? |
| Timing | At phase ends and project close, while memories are fresh | After lessons are captured, or at key points on large projects |
| Strength | Rich, practical insight | Objectivity, comparison across projects |
| Weakness | Blind spots and reluctance to criticise | Less detailed knowledge of the work |
Both are valuable. Lessons learned capture what only the team knows; audits test whether the team’s view is complete and whether the organisation’s risk process works.
Running a useful risk lessons-learned review
Hold reviews throughout, not just at the end
Reviews at the end of each phase capture lessons while they are fresh and while the project can still use them. A final review then brings them together.
Prepare with evidence
Before the session, gather the risk register’s history: which risks were identified and when, which occurred, which did not, which events occurred that were never on the register, how responses worked and how contingency was used against what was estimated. Evidence turns a discussion of impressions into an analysis.
Ask the right questions
- Which risks occurred, and were they identified in time to act?
- What happened that we never identified, and why did we miss it?
- Which responses worked, which did not and why?
- Were our probability and impact estimates realistic?
- How much contingency did we use, on what, and was the estimate right?
- What early warning signs did we see, and did we act on them?
- What would we do differently, specifically?
Make lessons specific and actionable
“Communication could have been better” is not a lesson. A useful lesson states the situation, what happened, why, and what to do next time, for example: “On brownfield upgrades, existing services drawings were unreliable. Survey and pothole all services in the work area before detailed design, and allow contingency for unknown services until the survey is complete.” Each lesson needs an owner responsible for turning it into a change.
Keep it blame-free and honest
People will not discuss mistakes if they expect to be blamed. Facilitate with a focus on systems, decisions and information, not individuals. An independent facilitator helps, and so does asking people to describe what they knew at the time, rather than judging decisions with the benefit of hindsight.
Learning while the project runs
Not all learning should wait for reviews. Risk triggers, early warning indicators that a risk is becoming more likely, let teams learn and act during the project. Examples include late responses to technical queries, rising numbers of open defects, slipping supplier milestones or unusual staff turnover. Agree triggers for major risks, monitor them in regular meetings and record what happened when they fired. Over several projects, this builds knowledge of which indicators genuinely give warning and how much time they allow.
Project risk audits
An independent project risk audit examines how well risk was managed. It asks whether the risk process was followed, whether it was effective, whether risk estimates were calibrated, whether escalation worked, and whether contingency and reserves were set and used sensibly. Audits that look across several projects can find patterns no single team sees, such as consistently underestimated risks for a type of work, recurring supplier problems or risks repeatedly identified but never treated.
Calibration is a particularly useful audit finding. If risks rated as unlikely keep happening, or contingency is consistently exhausted early, the organisation’s estimates are biased, and future projects should adjust.
Checking calibration with simple numbers
Calibration can be checked without sophisticated tools. Suppose the organisation sets contingency at a level it believes has an 80% chance of being sufficient. Across ten comparable projects, it should expect about two to need more. If eight of ten exceed their contingency, the estimates are clearly optimistic. Similarly, if the organisation rates a group of risks at about 10% likelihood each, roughly one in ten should occur; if a third of them occur, the ratings are too low. Keeping a simple table of estimated and actual outcomes across projects turns these checks into routine practice, and over time it provides the historical data that better quantitative analysis needs.
Sharing lessons beyond the project
Some of the most useful lessons involve other parties. Joint reviews with clients, designers, subcontractors and suppliers at the end of significant projects can reveal problems no single party saw, such as late information flows or unclear interfaces. Agree in advance that the purpose is learning, not claims, and respect confidentiality. Industry associations, professional bodies and published investigation reports are further sources of lessons from other organisations’ projects, often at no cost.
Closing the loop
Lessons create value only when they change what the organisation does. Practical mechanisms:
- A searchable lessons register, organised by type of work, phase and risk category.
- “Lessons in” at project start: new projects review relevant lessons before planning and tendering, not just “lessons out” at the end.
- Updated tools: risk identification checklists, estimating norms, contingency guidelines, templates and design standards.
- Training and induction that use real lessons from the organisation’s projects.
- Policy changes where lessons show systemic issues, such as approval thresholds or contract strategies.
- Tracking adoption: check whether lessons actually changed later projects.
The making a risk register change decisions article covers keeping registers connected to real choices during a project.
Risk culture: whether information flows
The most sophisticated risk process fails if people are afraid to speak up. Risk culture, the shared values and behaviours around risk, decides whether a junior engineer reports a defect, whether a subcontractor warns of a delay before it becomes a crisis, and whether a project manager tells the sponsor the truth about the forecast.
Signs of a healthy risk culture include:
- Bad news travels quickly upward and is thanked rather than punished.
- People raise concerns outside their own area.
- Forecasts change as information changes, without stigma.
- Near misses and small failures are reported and investigated.
- Leaders admit their own mistakes and uncertainty.
No-blame does not mean no accountability. A just culture distinguishes honest errors, which call for learning and system changes; risky choices where people drifted from good practice, which call for coaching and removing the pressures that caused the drift; and reckless disregard of known risks, which warrants consequences. Making this distinction clear helps people report honestly while keeping standards. The small failures worth explaining article shows how investigating minor problems builds this habit.
Risk maturity models
Risk maturity models describe stages through which an organisation’s risk capability develops, typically from ad hoc and reactive, through repeatable and defined processes, to managed and continually improving practice. Many are adapted from capability maturity models first developed for software processes.
Used honestly, they help an organisation see where it stands and choose the next improvement. An organisation without reliable historical data, for example, should improve data and basic processes before investing in sophisticated quantitative analysis. Used as a badge, maturity ratings encourage paperwork without improvement.
The limits of common practice
Many organisations manage risk as a list of discrete events, each with a probability and impact score on a matrix. This catches some risks but misses much of the uncertainty that drives project outcomes: variability in productivity and quantities, ambiguity in scope and requirements, dependencies between risks, and systemic issues such as optimism bias in estimates. Critics of common practice, including the risk management researcher Chris Chapman, argue for understanding sources of uncertainty, using ranges rather than single figures and focusing on the decisions risk analysis should inform. The what a risk score cannot tell you article explains the limits of scoring.
Black swans, perfect storms and resilience
Some of the most consequential events cannot be predicted from past experience. The writer Nassim Nicholas Taleb called these black swans, after the European belief that all swans were white until black swans were found in Australia. A black swan is rare, has an extreme impact and seems predictable only in hindsight. A perfect storm is different: a combination of individually foreseeable factors that together produce an extreme outcome.
These ideas do not make risk management pointless. They call for humility and for building resilience alongside prediction:
- Keep buffers of time, money and capacity proportionate to uncertainty.
- Preserve flexibility: options to change suppliers, methods, sequence or scope.
- Stress test plans against severe scenarios, asking what would happen if several things went wrong together.
- Avoid single points of failure in suppliers, people and systems.
- Watch for weak signals and empower people to act on them.
- Build response capability, such as crisis management arrangements, rather than only planning for specific events.
- Be wary of false precision in models and forecasts.
A worked example
This is an illustrative example. A mid-sized engineering contractor completes about a dozen projects a year. Every project ends with a lessons-learned report, but staff admit nobody reads them. Several recent brownfield upgrades, in which new equipment is installed in operating plants, have overrun their contingency.
Audit. The contractor commissions an independent review of six recent brownfield projects. It finds that on five of the six, contingency for unknown existing services and interfaces with operating plant was exhausted early. These risks appeared on registers but were rated as unlikely and given small allowances. Lessons reports had noted the problem each time, in general terms, without any change to estimating practice.
Changes.
- Lessons are rewritten as specific, actionable statements with owners, in a searchable register by work type.
- The tendering process requires a “lessons in” review for every brownfield bid, with a checklist of known interface risks.
- Estimating norms for brownfield contingency are revised using the audit’s evidence.
- Phase-end risk reviews replace a single close-out workshop.
- Leaders publish a just culture statement and thank teams publicly for early warnings, including those that turn out to be false alarms.
Result. The next three brownfield projects are tendered with more realistic contingency, survey existing services before detailed design and finish within their contingency. Lessons from those projects are added to the register and used in the following tenders.
Applying this in an Australian business
- Review risk at phase ends, using register history as evidence.
- Write specific, actionable lessons with owners.
- Use independent audits to test calibration and find patterns.
- Require “lessons in” at the start of projects and tenders.
- Update checklists, estimating norms and training.
- Build a just culture where early warnings are welcomed.
- Assess maturity honestly and improve step by step.
- Plan for resilience, not just predicted events.
Where risk learning goes wrong
- Lessons reports filed and forgotten.
- Vague lessons that nobody can act on.
- Reviews only at the very end.
- Blame that silences honest discussion.
- No independent view of how risk was managed.
- Maturity ratings as badges.
- Overconfidence in models that cannot foresee the unprecedented.
- Lessons collected only from failures, ignoring what went unexpectedly well.
Questions for leaders
- What did our last three projects teach us, and what changed as a result?
- Which risks do we keep underestimating?
- Do new projects read lessons before they plan?
- How do people react when someone brings bad news?
- How mature is our risk practice, honestly, and what is the next step?
- How would our projects cope with something nobody predicted?
Bringing it together
Project risk management improves only when organisations learn. Capture specific, evidence-based lessons throughout projects, test them with independent audits, and close the loop by building them into tenders, estimates, checklists, training and policy. Foster a just culture in which bad news travels fast, assess maturity honestly and recognise the limits of prediction by building resilience. The result is an organisation that meets each new project knowing more than it did before, rather than paying again for the same lessons.
Source: KEVOS editorial notes, drawing on earlier KEVOS project risk management study material on lessons learned and project risk audits, risk culture and the no-blame organisation, risk maturity models, the limitations of common practice and black swans and the limits of prediction, together with established project risk practice. The worked example is illustrative. This article is general information.