A risk is a possible future event. An issue is a problem that has already happened. Keep that distinction in the Type column so the team can choose the appropriate response.
Give each row a purpose
Use a stable ID such as R-01 or I-01, describe the effect on the work, assign an owner and record the next response. The due date should be the date of the next action or review, rather than an assumed resolution date.
Fictional example
I-01 · Issue: Six payment tests are blocked because the sandbox account is inactive. Owner: Sam Lee. Response: Restore access and rerun the tests. Due: 12 October 2026. Status: Open.
The template has no automatic risk score or escalation rules. Add those only if your team has agreed a consistent definition.
Read the columns as a workflow
Give every row a stable ID and one responsible owner. Keep the same ID when the record moves to another week; this lets a reviewer trace a change instead of treating it as new work.
- Type
- Use Risk for something that may happen and Issue for a problem already present.
- Description / impact
- Name the affected work and explain what changes if the item is unresolved.
- Response
- Write the next response or decision; avoid “monitor” without saying what will be monitored.
- Review date
- Set the next agreed checkpoint. This is not automatically the resolution date.
- Status
- Use a consistent vocabulary, such as Open, In progress and Closed. Closure should have evidence.
One filled row, with context
This fictional Northstar example is a starting point for your own wording. Replace every placeholder, confirm the owner and agree the next review date.
| ID | Type | Description / impact | Owner | Response | Review date | Status |
|---|---|---|---|---|---|---|
| I-01 | Issue | Test environment unavailable; payment retest delayed. | Sam Lee | Confirm fallback environment access. | 2026-10-12 | Open |
Maintain the record after the first download
Keep one editable copy as the source. When an item changes, update the response, date and evidence together. If a record is closed, retain its ID and outcome instead of deleting the trail. These downloads do not sync, notify owners or validate acceptance.