The moment you take on leadership of a research group, a degree programme, a laboratory or a standing committee, you become responsible not only for its work but for the things that can go wrong with it. A key researcher leaves mid-project. An external examiner resigns weeks before an exam board. A single funder underwrites most of the unit's activity. A piece of shared equipment fails with no maintenance budget. Individually these are manageable; collectively, and unanticipated, they are how good units drift into crisis.
A risk register is the discipline that keeps them anticipated. Borrowed from corporate and project governance but stripped to its essentials, it is simply a living list of what could go wrong, how likely and serious each threat is, and who is doing what about it. This article shows academic leaders anywhere, from a departmental chair in Nairobi to a programme director in Manchester or a laboratory head in Bengaluru, how to run one that is genuinely useful rather than a box-ticking artefact.
Why academic leaders need a risk register
Academic units are unusually exposed to correlated, people-centred risk, yet they rarely manage it explicitly. Universities maintain elaborate institutional risk frameworks, but these operate at a level far above the daily reality of a research group or programme, where the risks that actually bite are local: one departing postdoc, one lapsed ethics approval, one over-relied-upon colleague. Leaders tend to hold these worries in their heads, which means the knowledge is invisible to the team and lost entirely when leadership rotates.
A written register solves three problems at once. It externalises the leader's private anxieties into a shared, reviewable document. It forces the unit to distinguish trivial worries from genuine threats through explicit scoring. And it creates accountability by attaching an owner and an action to each significant risk. The payoff is not the document itself but the conversations it prompts, the surfacing of a dependency no one had voiced, the realisation that three separate plans all rely on the same person. For the wider context of leadership responsibilities, see our Leadership, Service and Committees hub.
Identifying risks across research, teaching and people
Good risk identification is systematic, not free-associative. Work through the domains your unit spans and ask, in each, what could realistically go wrong in the next twelve to eighteen months. In the research domain, consider funding cliffs, missed reporting deadlines, ethics and data-governance lapses, equipment failure, and delivery slippage on funded milestones. In the teaching and programme domain, consider staffing gaps, external examiner and accreditation risks, student experience and progression problems, and curriculum obsolescence. In the people domain, consider key-person dependency, succession, burnout, and unresolved conflict.
The domain most academic leaders under-examine is people, precisely because it is uncomfortable. Yet key-person dependency, where one individual holds relationships, know-how or credentials no one else can replace, is the most common serious risk in academic units and the least often written down. Run the identification exercise with your team, not alone, because colleagues will name exposures a leader cannot see, and the act of naming them together builds shared ownership of the response.
Distinguish risks, which are future possibilities, from issues, which are already happening; the register handles the former, while the latter need immediate action. When a risk touches research integrity, data protection or human participants, anchor your thinking in the recognised expectations of bodies such as UK Research and Innovation and its regional equivalents, whose funding conditions define much of your compliance exposure. The individual-level counterpart to this unit register is covered in our article on personal career risk.
Scoring likelihood and impact
A list of everything that could go wrong is paralysing until you prioritise it, and scoring is how you prioritise. For each risk, rate two dimensions on a simple scale, likelihood and impact, from low to high or one to five. Multiply or plot them to get a combined severity. This crude arithmetic does something important: it separates the risks that feel frightening from the risks that are actually dangerous, which are often not the same. A dramatic but improbable event may score lower than a mundane, near-certain staffing gap.
Keep the scale coarse. Three or five points per dimension is plenty; finer gradations imply a precision academic risk assessment does not possess and invite unproductive argument over whether something is a three or a four. Focus attention on the high-likelihood, high-impact quadrant, these are your priority risks and deserve active management, and the low-impact, low-likelihood quadrant, which you can note and ignore. The value of scoring is comparative, not absolute: it tells you what to work on first, which is exactly the decision a busy leader needs made. Record the scores so you can track whether a risk is worsening or easing across review cycles.
Mitigation, contingency and ownership
A scored risk with no response is just anxiety with a number attached. For every priority risk, decide on two things: mitigation, the actions that reduce its likelihood or impact before it happens, and contingency, what you will do if it happens anyway. For key-person dependency, mitigation is cross-training a second person and documenting critical knowledge; contingency is a named interim cover and a recruitment plan you can trigger. Distinguishing the two prevents the common error of preparing to respond to a disaster while doing nothing to prevent it.
Every risk must have a single named owner, not a committee, because shared ownership is no ownership. The owner is accountable for the mitigation actions and for reporting whether the risk is changing. Give each action a date, and treat undated actions as fiction. AcademicStaff's leadership planner is designed for exactly this, letting you hold a live register with scores, owners, mitigation actions and review dates in one shared view that your whole team and your line manager can see, so that risk management becomes a routine rather than an annual scramble. For the connection between risk ownership and evidencing your leadership for promotion, see our playbook on turning service into career capital.
Reviewing risk in the governance cycle
A register written once and filed is worthless; the discipline is in the review. Tie your risk review to an existing rhythm rather than inventing a new meeting no one attends, the monthly research-group meeting, the termly programme board, the standing committee's agenda. Make "risk review" a short recurring item where you walk the top handful of risks, confirm owners are acting, retire risks that have passed, and add new ones the term has surfaced.
Frequency should match volatility. A fast-moving funded project may review monthly; a stable programme may review each term. What matters is that review is scheduled and brief, not exhaustive and rare. Escalate deliberately: risks that exceed your authority to manage, a compliance exposure, a resource shortfall, a serious conflict, should be reported up to the relevant institutional committee with a clear ask, not held privately until they become crises. This upward reporting also protects you, demonstrating that you identified and flagged a threat rather than concealing it. Aligning your unit's cycle with your institution's own governance calendar, and with accreditation and quality-assurance timelines, keeps the two levels in step.
Common risk blind spots in academic units
Certain risks are systematically under-registered in academia because they are cultural rather than technical. The first is succession: brilliant units built around a charismatic founder rarely plan for that person's departure, and the register should name it openly. The second is burnout, which functions as a slow-motion key-person risk, degrading capacity across the team while everyone treats overwork as normal. The third is over-reliance on a single funder or a single high-performing individual, a concentration that feels like strength until it becomes fragility.
A fourth blind spot is compliance drift, lapsed ethics approvals, outdated data-management practices, expired accreditations, that accumulates quietly because no one owns the calendar. A fifth is reputational risk arising from the conduct of the unit's own members, which leaders are reluctant to name but which can undo years of work. The remedy for all of these is the same: put them on the register explicitly, assign an owner, and review them on a cycle. Naming an uncomfortable risk does not create it; it simply gives you the chance to manage it before it manages you. The best academic leaders are not those who avoid every risk, an impossibility, but those whose units are never surprised by the risks they took.
The Academic Unit Risk Register Template
A pre-built risk register with likelihood-and-impact scoring, a prompt list covering research, teaching and people risks, and columns for owner, mitigation, contingency and review date, ready to drop into your next group or programme meeting.
Want the full article?
Enter your email for free access to the rest of this guide and our TEQSA resource library.
Frequently asked questions
Isn't a formal risk register overkill for a small research group?
The formality should scale with the unit, but the discipline should not. A small group may keep a single shared page listing its top five risks with a score, an owner and a next action each. That is enough to surface hidden dependencies and prompt the conversations that matter. The value is in the thinking and the shared visibility, not in the length of the document.
How often should an academic risk register be reviewed?
Match the frequency to the unit's volatility and tie it to a meeting you already hold. A fast-moving funded project may warrant a short monthly review; a stable degree programme may need only a termly one. What matters is that review is scheduled and brief, not that it is frequent. An unreviewed register decays into fiction within a term.
What is the most commonly missed risk in academic units?
Key-person dependency: one individual holding relationships, expertise or credentials that no one else can replace. It is the most frequent serious risk and the least often written down, because naming it feels awkward. Mitigate it by cross-training a second person and documenting critical knowledge, and prepare a contingency for interim cover.
The AcademicStaff editorial team writes practical, evidence-based guidance for university staff — drawing on sector reporting, funder guidelines and the lived administrative reality of academic work. Every guide is reviewed for accuracy against current Australian higher-education practice.
