“Project risk registers should be formally reassessed at every major milestone, not only at project approval. Risks evolve as assumptions change — vendors, regulations, technology and stakeholders shift over time. Organisations that treat risk reassessment as a continuous governance responsibility identify emerging problems earlier and avoid costly late-stage escalation.”
Farhan Khan, Senior Director – Forensics & Risk Advisory, BDO Saudi Arabia
There is a moment in almost every major project when the risk register stops being a living document and becomes a historical record. It gets signed off at the start, filed in the project management system and quietly forgotten as delivery accelerates. By the time leadership recognises that the project's risk profile has changed, many of the most effective response options have already disappeared. This is not usually a failure of planning. More often, it is a failure of reassessment.
In my experience advising organisations on governance, risk and major transformation programmes, one pattern repeats itself: organisations often identify the right risks at the beginning but fail to recognise when those risks evolve, or when entirely new ones emerge. Decisions continue to be made on assumptions that were valid at project approval but no longer reflect reality on the ground.
In the context of Saudi Arabia's accelerating Vision 2030 agenda, where organisations across sectors are delivering an increasing number of complex capital, infrastructure and digital transformation programmes simultaneously, the ability to reassess risk continuously has become a critical governance capability rather than a project management exercise.
Why risk reassessment cannot wait until the project ends
Assessing risk at the outset of a project is essential. It informs budgets, resource planning, governance structures and stakeholder expectations. The problem begins when leadership treats that initial assessment as a completed exercise rather than the starting point of a continuous process. Risk registers should evolve at the same pace as project decisions.
Key suppliers change. Regulations evolve. Technology requirements shift. Project sponsors move on. Decisions made in month three often create risks that nobody anticipated during project approval. The greatest risk is not that these changes occur. It is that they occur without anyone formally asking: “Has our risk profile fundamentally changed?”
Leadership teams can therefore find themselves making important decisions based on an increasingly outdated understanding of the programme.
What mid-project risk reassessment looks like in practice
Illustrative scenario
Consider a large digital transformation programme where the implementation partner is selected after a competitive procurement process. At project approval, the vendor is financially stable, key specialists are committed to the engagement and the implementation timeline appears achievable.
Six months into delivery, several senior vendor resources have been replaced, integration with legacy systems proves more complex than anticipated and new regulatory requirements necessitate changes to the solution design. Individually, none of these developments may appear significant. Collectively, however, they fundamentally alter the project's risk profile. None of these changes would necessarily justify stopping the project. Collectively, however, they should trigger a reassessment of delivery assumptions, governance arrangements and financial exposure.
By the time these issues reach the steering committee as a formal escalation, leadership's options have often narrowed significantly. A structured mid-project reassessment could have identified these changes earlier, allowing leadership to revisit mitigation plans before the issues escalated into delays, cost overruns or a dispute with the implementation partner that could have been avoided entirely.
The objective of reassessment is not to predict every future event. It is to ensure that leadership decisions continue to reflect the programme's current reality rather than its original assumptions.
Why project risks change: it is the assumptions that shift
One of the most overlooked aspects of project governance is that risks evolve because the underlying assumptions evolve. A supplier assessed as financially stable may begin experiencing operational challenges. A regulatory interpretation accepted at project initiation may no longer reflect current supervisory expectations. Technology that appeared compatible during procurement may prove difficult to integrate once implementation begins.
In most programme reviews, the issue is not that risks were unidentified. It is that the assumptions supporting those risks quietly changed without anyone formally asking whether the original assumptions still reflected reality.
Common risk categories that emerge during project delivery
The risks that ultimately cause the greatest disruption are rarely the ones discussed at project initiation. Across large programmes, the same categories appear repeatedly.
Scope expansion without risk assessment
Projects evolve. Changes that individually appear manageable collectively transform the programme, yet each scope adjustment is assessed for cost and timeline impact without reconsidering the broader risk profile.
Vendor and third-party performance
The real vendor due diligence assessment begins once delivery starts. Whether key personnel remain assigned, whether the supplier's financial position has changed and whether subcontractors are creating new dependencies are questions rarely asked with the same rigour applied during procurement.
Technology and integration challenges
Systems that perform well during testing do not always behave the same way under operational conditions. Integration risks tend to surface late in the delivery cycle, at precisely the moment when project flexibility has reduced significantly.
Commercial and financial pressures
Cost inflation, supply chain disruption, changes in funding assumptions or pressure to accelerate delivery frequently introduce risks that were not anticipated at project approval. These commercial realities can significantly alter the project's risk profile and should be reassessed alongside operational and technical risks.
Stakeholder alignment
As projects progress, leadership priorities, funding expectations and stakeholder interests often evolve. Unless governance structures ensure continued alignment, projects can remain technically on track while gradually moving away from the outcomes originally intended.
Regulatory developments
Large programmes span several years. During that period, regulations and supervisory expectations continue to evolve. A project compliant by design at inception may require significant redesign midway through delivery.
Organisational change
Projects are sponsored by people, not organisations. Executive sponsors move roles. Internal champions leave. Many programmes become exposed not because the project changed, but because the organisation around it did.
Why governance means challenging assumptions, not just tracking risk
Effective governance depends as much on asking the right questions as on receiving the right reports. It is not about eliminating uncertainty. It is about ensuring leadership continues to receive timely, accurate information as the programme evolves. Risk reassessment is one of the most practical ways to keep governance aligned with the realities of project delivery rather than the assumptions made at project approval.
Leadership should not only ask whether existing risks are being managed effectively. It should also ask whether the assumptions behind those risks remain valid. A programme approved six months ago is unlikely to face exactly the same environment today.
Where the programme's risk profile has materially changed, leadership should also consider whether the project continues to operate within the organisation's approved risk appetite and whether any additional governance actions or approvals are required.
How leadership teams should respond to emerging risk
Review risks at predefined milestones
Every stage gate, budget refresh or major delivery milestone should trigger a structured reassessment. Leadership should routinely ask: what has changed, which assumptions are no longer valid, what new risks have emerged and are existing mitigation plans still fit for purpose.
Separate delivery from independent oversight
Project managers are naturally focused on delivery. Independent risk oversight through a PMO, Internal Audit, Risk Management or an external adviser provides leadership with a more objective assessment of emerging risks, one that is not filtered through the pressure of meeting the next milestone.
Create a culture that encourages escalation
Many project failures are preceded by concerns that were visible within the project team but never reached executive leadership. People must feel able to raise concerns early without fearing that doing so will be interpreted as failure. Organisations that surface problems early consistently resolve them at lower cost.
Use leading indicators, not only lagging indicators
Leadership should monitor indicators that signal emerging risks before they affect cost or schedule. Contractor turnover, unresolved design issues, repeated governance exceptions, delayed decisions and increasing change requests often provide earlier warning than traditional project reports.
Act before certainty arrives
Waiting for conclusive evidence before responding to an emerging risk is one of the most common and costly leadership mistakes. By the time certainty arrives, options have usually narrowed. Early intervention may occasionally prove unnecessary. Late intervention almost always proves expensive.
Key questions leadership should ask mid-project
- Which project assumptions have changed most since approval?
- What new risks have emerged since project approval?
- Which existing risks have materially increased, changed in nature or become more difficult to mitigate?
- What emerging issues or delayed decisions could escalate into cost overruns, delays or other material project impacts?
- Would we still approve this project today, based on what we now know about its risks, assumptions and delivery environment?
Frequently asked questions
How often should a project risk register be reviewed?
At every stage gate, budget refresh or major delivery milestone, not only at project initiation. Fixed review points ensure leadership reassesses assumptions as they change rather than relying on ad hoc escalation.
What triggers a mid-project risk reassessment?
Vendor personnel changes, new regulatory requirements, integration issues, funding changes or shifts in stakeholder priorities. Individually minor, these developments can collectively alter a project's risk profile.
Who should lead risk reassessment on major programmes?
Independent oversight functions such as PMO, Internal Audit, Risk Management or an external adviser, working alongside — but separate from — the delivery team, to avoid delivery pressure filtering the assessment.
What are leading indicators of emerging project risk?
Contractor turnover, unresolved design issues, repeated governance exceptions, delayed decisions and rising change requests. These typically surface earlier than cost or schedule variance in standard project reports.
Key takeaway
The organisations that consistently deliver successful programmes share one characteristic. Their leadership teams do not treat risk reassessment as a project management exercise. They treat it as an executive governance responsibility. They continuously challenge assumptions, revisit decisions and encourage difficult conversations before problems become crises.
Projects rarely fail because leadership ignored known risks.
More often, they fail because leadership continued managing yesterday's risks while today's risks were quietly taking shape.
To discuss how BDO Saudi Arabia's Forensics & Risk Advisory team can support risk governance on your major programmes, speak to our team.

