Risks, assumptions, issues and dependencies — four logs, each with the columns it actually needs rather than one shape stretched over all four. Fill it in here and export to Excel, or take the blank template and go.
A RAID log is the project's single record of everything it does not yet know for certain: Risks, Assumptions, Issues and Dependencies. It exists so that uncertainty has somewhere to live other than the project manager's head, and so that a handover, an audit or a claim can be answered with a record instead of a recollection.
Its real value is at the boundaries. Most project trouble arrives from something the team assumed, something another party owed them, or something they saw coming and did not escalate — and none of those are captured by a task list.
| Log | Tense | The defining column | The test |
|---|---|---|---|
| Risk | Might happen | Likelihood × impact | Can you describe the cause, the event and the effect? |
| Assumption | Believed true | Validate by (a date) | What breaks if this turns out to be wrong? |
| Issue | Has happened | Action and resolve-by date | Who is doing what about it, by when? |
| Dependency | Owed | Direction and needed-by date | Whose name is on it, and does they know? |
Purely a question of tense. A risk is in the future and carries a likelihood; an issue is in the present and carries an action. When a risk occurs, close the risk with a note pointing at the new issue rather than deleting it — the record that you saw it coming is often the most valuable line in the log, particularly in a claim.
If there is a name and a date attached, it is a dependency. If there is only a belief, it is an assumption. "Council will approve in 15 days" is an assumption; "the certifier issues the fire engineering approval by 12 March" is a dependency, because someone specific owes it.
Outbound dependencies — the things you owe someone else. They never feel like your problem until the day a subcontractor's delay claim points at a lay-down area you were supposed to hand over three weeks ago. That is why the dependency log here has a direction column rather than assuming everything is inbound.
The failure mode to watch for is a log with twenty rows in exactly the same state three months running. That is not a maintained log, it is an abandoned one that someone keeps tidying.
Risks, Assumptions, Issues and Dependencies — the four kinds of uncertainty a project needs to track somewhere other than in someone's head.
Tense. A risk might happen and carries a likelihood; an issue already has and carries an action and a date. When a risk occurs, close it with a pointer to the issue rather than deleting it.
If there is a name and a deadline attached, it is a dependency. If there is only a belief, it is an assumption.
Every reporting cycle, in the same meeting as the schedule. Any entry whose date has passed should force a decision rather than roll forward.
Only in this browser's local storage on this device. Nothing is sent to a server. Export the CSV to keep or share it.
Yes — the download is CSV with a byte-order mark, so Excel, Google Sheets and Numbers all open it with the characters intact.
A RAID log tells you what might go wrong. Aegis holds those risks against the schedule and cost they threaten, so the status report says what the exposure is worth and which milestone it lands on — every period, from your own P6 or MS Project file.
Start your 14-day trial →