How to structure risk management in public works by integrating planning, design, estimating, the risk matrix, contract, inspection, and execution.
Check it out!
Risk management in public works is the continuous process of identifying, analyzing, evaluating, treating, monitoring, and communicating uncertainties capable of compromising project objectives for cost, schedule, performance, quality, safety, procurement, and delivery. It begins before bidding and does not end when the contract is signed: it follows the investment from definition of the need through acceptance and entry into operation.
In public-sector engineering, risk should not be treated merely as a probability-and-impact table or confused with the contractual risk-allocation matrix. The first question is operational: which events can prevent the investment from achieving the expected result? The second is decisional: which actions reduce exposure before the event occurs? The third is contractual: when a risk remains, which party is better able to manage it and bear its effects?
Brazilian Law No. 14,133/2021 reinforces this logic by requiring continuous and permanent risk-management and preventive-control practices in public procurement. For engineering works and services, this connects planning, preliminary technical studies, design, estimating, contracting strategy, risk matrix, inspection, changes, measurements, and acceptance within the same governance system.
A risk register only creates value when it changes decisions. Identifying “project delay” as a generic risk is insufficient. Causes, events, consequences, responsible parties, indicators, preventive actions, contingencies, deadlines, and residual risk need to be explicit. In other words, risk management needs to transform uncertainty into engineering and governance work.
Risk management is more than a risk matrix
A relevant risk without an owner, deadline, action, and evidence of treatment remains only a documented concern. Structure the process to turn uncertainty into traceable decisions and actions.
One of the most common sources of confusion in public procurement is using “risk management,” “risk analysis,” and “risk matrix” as synonyms. They are related, but they serve different functions.
Risk management is the continuous system that organizes objectives, identification, analysis, evaluation, treatment, monitoring, and communication. Risk analysis is part of that process and focuses on understanding the nature, probability, impact, causes, and consequences of uncertainty. The risk allocation matrix, in turn, is a contractual instrument that distributes responsibilities between the public authority and contractor for supervening events and their economic and financial effects.
This difference matters because a project may have a formally correct contractual matrix and still be poorly managed. Design risks, interferences, permitting, land acquisition, site availability, interfaces, critical supplies, productivity, operating constraints, and documentation need to be monitored as live exposures, not merely as static clauses.
| Instrument | Central question | Expected outcome |
| Risk management | what can affect the objectives and how should we respond? | continuous process for controlling exposure |
| Risk analysis | what is the nature and severity of the uncertainty? | criticality and prioritization |
| Risk register | which risks are active and who owns them? | traceability of owners, actions, and status |
| Risk allocation matrix | who bears each contractual risk? | distribution of responsibilities |
| Contingency | how much should be reserved for residual exposure? | cost and schedule protection |
| Gate review | does residual exposure allow the project to proceed? | decision to proceed, proceed with conditions, or return |
The TCU emphasizes that procurement risk analysis is not the same as the contractual risk matrix. The former should support planning and treatment of events that may compromise the procurement; the latter formalizes risk allocation between the parties when applicable.
Risk needs to be defined in relation to investment objectives
There is no risk without an objective. If the organization has not clearly defined what the project must deliver, by when, at what performance level, and within which constraints, any risk register tends to become a generic list of concerns.
In a public works project, objectives may include:
- delivering a defined functional capacity;
- meeting a deadline associated with an agreement, financing, or public policy;
- keeping cost within budget authorization;
- ensuring performance, safety, and service life;
- preserving existing operations during implementation;
- meeting environmental and regulatory conditions;
- providing sufficient documentation for operations and maintenance;
- performing technical acceptance with objective evidence.
A sound risk process starts from these objectives and asks what can prevent them from being achieved. Thus, “delay” stops being a standalone risk and becomes a possible consequence of concrete causes: incomplete design, pending permit, unidentified interference, unidentified long-lead item, scope change, low productivity, unavailable work front, weather event, late decision, or a contractual interface without an owner.
The risk cycle follows the entire public-works life cycle
When survey, design, estimating, and contracting risks remain open before bidding, the organization may transfer uncertainty to the most expensive phase of the investment. Technical maturity review helps address exposure before contractual commitment.
Exposure changes as the investment matures. Risks that can be eliminated during preliminary technical studies cost much more when discovered in the field. Others arise only during execution or operations. The register therefore needs to evolve with the project.
Planning and preliminary technical studies
During planning, risk management should test fundamental assumptions: existing conditions, site availability, demand, technology alternatives, interfaces, requirements, permits, constraints, and institutional capability. A well-structured preliminary technical study reduces uncertainty before it becomes embedded in the scope.
When field surveys are insufficient, risk does not disappear; it is merely transferred to phases where correction is more expensive. The Capital Projects in Public Works framework applies this maturity principle before each significant commitment.
Design and technical definition
During preliminary design, Basic Design, and Detailed Engineering, the focus shifts to interfaces, performance criteria, coordination, constructability, quantities, construction methods, access, sequencing, interferences, and testability.
Incomplete design is a source of cost, schedule, and change risk. Therefore, Design Review can function as a preventive mechanism: it identifies incompatibilities before they become purchases, contracts, or executed work.
Estimate and schedule
Risk needs to connect with cost and schedule. The public-works estimate should make explicit the assumptions and exposures that may change quantities, productivity, logistics, mobilization, prices, and duration.
A deterministic schedule can also conceal risk. When critical dates depend on permitting, approval, imports, site release, or external decisions, those dependencies need to appear as drivers rather than side notes.
Bidding and contract
During bidding, some risks should be eliminated by improving the technical package; some should be mitigated through requirements, measurement criteria, insurance, guarantees, governance, and change mechanisms; and some may be formally allocated between the parties.
The contractual matrix should not be used to transfer to the contractor any uncertainty that the public authority failed to study. Efficient allocation depends on actual management capability, available information, and its relationship to contractual obligations.
Execution e fiscalização
During construction, risk management increasingly depends on field evidence, physical progress, quality, submittals, RFIs, nonconformities, changes, productivity, interfaces, and cost and schedule trends.
A risk that remains “high” for months without effective action is not being managed. Monitoring needs to verify whether actions were implemented, whether they reduced probability or impact, and whether secondary risks emerged.
Commissioning, acceptance, and operations
At closeout, attention shifts to open items, testing, documentation, training, performance, As-Built documentation, the Data Book, and operating conditions. A physically completed project may still carry high residual risk if acceptance criteria have not been demonstrated.
How to write a useful risk statement
Design risks should be reduced before incompatibilities become purchases, executed work, or claims. Independent review makes it possible to verify interfaces, requirements, constructability, and maturity.
A well-formulated risk should separate cause, event, and impact. This avoids vague records and connects risk more directly to treatment actions.
Poor example: “risk of project delay.”
Better example: “because the utility has not approved the design by the mobilization date, permanent energization may be delayed, resulting in postponement of integrated testing and technical acceptance.”
This formulation makes it possible to identify specific actions: person responsible for submission, approval deadline, utility interface, temporary alternative, affected milestone, and contingency trigger.
A consistent risk register may contain:
| Field | Function |
| ID | traceability |
| category | group exposure by nature |
| cause | condition that originates the risk |
| event | uncertain occurrence |
| consequence | effect on objectives |
| probability | estimated likelihood of occurrence |
| impact | magnitude of effect |
| criticality | prioritization |
| owner | person responsible for managing the risk |
| preventive action | reduce probability |
| mitigation action | reduce impact |
| contingency | response if the event occurs |
| trigger | indicator of materialization |
| deadline | latest date for action |
| residual risk | exposure after treatment |
| status | open, monitored, materialized, or closed |
Qualitative assessment: probability and impact are not enough on their own
A probability x impact matrix is useful for prioritization, but it can create false precision when the criteria are undefined. “High probability” needs to mean something within the context of the project. The same applies to impact.
Criteria can be established by dimension:
- financial impact relative to the budget;
- schedule impact in days or milestones;
- effect on performance or capacity;
- safety severity;
- regulatory consequence;
- reputational impact;
- effect on operational continuity;
- impact on the expected public benefit.
Complex projects may require separate analysis by dimension instead of a single aggregate score. A risk may have a low financial effect and a critical safety impact, for example.
It is also important to distinguish inherent risk from residual risk. The former represents exposure before treatment; the latter, after controls and actions. The decision to proceed should focus primarily on residual risk.
Quantification: when risk needs to enter cost and schedule
Not every project requires probabilistic simulation. However, larger, long-duration, or highly uncertain projects may benefit from quantitative techniques.
Quantification can support:
- definition of cost contingency;
- schedule contingency;
- comparison among alternatives;
- assessment of the probability of meeting a given date;
- aggregate exposure analysis;
- mitigation prioritization;
- economic evaluation of treatment.
The central point is not to confuse contingency with an arbitrary margin. A technically defensible reserve should relate to identified risks, assumptions, maturity, and the estimating method.
Brazilian Law No. 14,133/2021 provides that risk allocation may affect the estimated procurement value. This reinforces the need for consistency among risk, estimate, and contract.
Risk matrix: allocating risk is not the same as managing it
Brazilian Law No. 14,133/2021 allows bidding documents and contracts to include a risk allocation matrix and makes it mandatory for large-scale works and services and for integrated and semi-integrated contracting.
The matrix should seek efficient allocation. This means assigning the risk to the party best able to prevent it, control it, insure it, or respond to its effects — not simply to the party with less bargaining power.
Useful allocation questions include:
- who controls the cause of the risk?
- who has better access to information?
- who can reduce probability or impact?
- is the risk insurable?
- can the receiving party price it?
- does the transfer create an excessive risk premium?
- is the event related to an obligation already allocated in the contract?
- is the allocation compatible with the delivery model?
The Risk Allocation Matrix in Engineering Contracts should be built consistently with the risk register, but it does not replace it.
Typical risks in public works
The specific list varies by project, but some categories recur.
Definition and scope
- poorly characterized need;
- incomplete requirements;
- solution selected prematurely;
- unidentified interfaces;
- change in demand during development.
Existing conditions
- incomplete existing-condition survey;
- underground interferences;
- insufficient capacity of existing infrastructure;
- outdated As-Built documentation;
- unidentified liabilities.
Design
- incompatibility among disciplines;
- insufficient sizing;
- missing performance criteria;
- inadequate constructability;
- dependency on a late decision.
Estimate and schedule
- inconsistent quantities;
- inadequate cost build-ups;
- incompatible productivity assumptions;
- outdated base date;
- schedule without constraints and interfaces;
- contingency without methodology.
Contracting
- delivery model incompatible with design maturity;
- disproportionate qualification requirements;
- inconsistent risk matrix;
- ambiguous measurement criteria;
- interface responsibilities without an owner.
Execution
- low productivity;
- late submittals;
- recurring nonconformities;
- changes without integrated analysis;
- late critical supplies;
- pending technical decisions;
- unavailable work fronts.
Closeout
- incomplete testing;
- insufficient documentation;
- critical open items;
- divergent As-Built documentation;
- incomplete training;
- performance criteria not demonstrated.
Risk owner: every relevant risk needs an owner
Recording a risk without an owner creates diffuse responsibility. The owner is not necessarily the person who performs every action, but the person who must ensure that the risk is monitored, treated, and escalated.
In public works, owners may sit in different areas: engineering, procurement, legal, estimating, inspection, contract management, operations, utilities, or third parties. The register therefore needs to connect with governance and the responsibility matrix.
The owner should know:
- which actions are under their responsibility;
- what deadline exists for executing them;
- what evidence demonstrates completion;
- which trigger requires escalation;
- what residual risk remains after treatment.
Risk review should follow the project’s decision cadence
Risk management loses value when it occurs only in occasional workshops. The process should be integrated into the decision-making routine.
A risk meeting may review:
- newly identified risks;
- changes in probability or impact;
- overdue actions;
- materialized risks;
- treatment effectiveness;
- residual risks above tolerance;
- cost and schedule impacts;
- decisions requiring a sponsor or authority;
- risks that can be closed.
The register needs an update date and a history of decisions. Closed risks should also remain traceable: why they ceased to be relevant, which action was completed, or which event occurred.
Risk management and Project Controls need to work together
Risk, cost, and schedule need to share the same baseline. Project Controls turns exposure into impact on milestones, forecast, trends, and contingency.
Risk, cost, and schedule should not exist in disconnected systems. A relevant delay risk needs to be related to the milestones it affects; a financial risk should connect with forecast and contingency; a mitigation action may consume budget and change the schedule.
Project Controls provides this integration through baseline, progress, trends, forecast, cost, and schedule. When risk is connected to these controls, the organization stops discussing only “possibilities” and starts seeing the impact on the delivery forecast.
Useful indicators may include:
- aggregate exposure by category;
- critical risks without an approved action;
- overdue actions;
- risks materialized during the period;
- contingency consumption;
- potential impact on the critical path;
- number of risks above tolerance;
- aging of open risks.
Change management is part of the response to risk
Changes are not necessarily failures. The problem arises when they are incorporated without analysis of cause, impact, responsibility, and cumulative effect.
A risk may materialize and create a need for change. At that point, the workflow should move from uncertainty to fact: record the occurrence, assess impact, define treatment, establish responsibility, verify cost and schedule effects, and update the baseline when approved.
Technical analysis of contract amendments, scope changes, and claims helps keep this transition documented.
Inspection should use the risk register as a prioritization tool
Inspection does not need to treat every item with the same intensity. A risk-based approach helps concentrate inspections, verifications, tests, and evidence on the points capable of producing the greatest consequence.
Examples:
- safety-critical components may require hold points;
- irreversible interfaces should be verified before closure;
- items with long replacement lead times require early monitoring;
- concealed work requires records before being covered;
- performance testing needs to be planned before physical completion.
Technical Support for Inspection can turn the risk register into a monitoring plan and compliance evidence.
Gate review: residual risk should influence authorization to proceed
The maturity logic used in public investments assumes that each significant commitment has readiness criteria. Residual risk is one of those criteria.
Before publishing bidding documents, for example, the public authority can verify whether critical survey, design, estimate, permit, or interface risks remain untreated. Before starting construction, it can verify site availability, released designs, submittals, critical suppliers, and constraints. Before acceptance, it can verify open items, testing, documentation, and operational risks.
The decision may be:
- Ready: residual exposure is compatible with proceeding;
- Ready with Conditions: proceeding is allowed with explicit conditions;
- Not Ready: exposure is incompatible with the next commitment.
This logic prevents the calendar from replacing technical maturity.
Common mistakes in public-works risk management
Some patterns drastically reduce the usefulness of the process:
- creating a register only to satisfy a documentation requirement;
- recording generic consequences instead of causes and events;
- using only a probability x impact matrix without a treatment plan;
- confusing risk analysis with the contractual matrix;
- transferring to the contractor risks that the public authority should reduce through better planning;
- failing to assign an owner and deadline to the risk;
- failing to connect risk to the estimate and schedule;
- keeping critical risks without escalation;
- closing a risk without evidence;
- failing to update the register after relevant changes;
- treating contingency as an arbitrary percentage;
- discussing risk only after the problem occurs.
How to structure a practical risk management system
An objective implementation can follow this sequence:
- define project objectives and success criteria;
- establish categories and assessment criteria;
- identify risks with multidisciplinary participation;
- write the cause, event, and consequence;
- assess probability, impact, and criticality;
- define the owner;
- select responses: avoid, reduce, transfer, share, or accept;
- detail actions, deadlines, and evidence;
- define contingencies and triggers;
- assess residual risk;
- integrate risks with the estimate, schedule, contract, and inspection;
- review periodically;
- record materialized risks and lessons learned;
- use residual exposure in decision gates.
This system should be proportional to the size and complexity of the investment. A small project does not need to replicate the governance of a megaproject, but every project needs an explicit way to recognize and address its main uncertainties.
Final considerations
Risk management in public works is a decision discipline, not a documentation formality. Its value lies in anticipating events, directing investigation, prioritizing controls, protecting cost and schedule, improving contractual allocation, and making visible the uncertainties that remain before each significant commitment.
Brazilian Law No. 14,133/2021 provides a clear basis for continuous risk-management and preventive-control practices. The TCU reinforces that the process should start from objectives and involve identification, analysis, evaluation, treatment, and reporting. In engineering, this logic needs to be materialized in surveys, design, estimating, scheduling, contracts, inspection, changes, testing, and acceptance.
The most useful question, therefore, is not whether the project “has a risk matrix.” It is whether the risks that may prevent delivery of the public benefit are known, assigned, treated, monitored, and reflected in investment decisions.
During execution, risk-based inspection concentrates inspections, evidence, and decisions on the items capable of compromising safety, quality, schedule, cost, and acceptance.
Technical references
[1] BRAZIL. Law No. 14,133, of April 1, 2021. Public Procurement and Administrative Contracts Law. Available at: [https://www.planalto.gov.br/ccivil_03/_ato2019-2022/2021/lei/l14133.htm](https://www.planalto.gov.br/ccivil_03/_ato2019-2022/2021/lei/l14133.htm)
[2] BRAZILIAN FEDERAL COURT OF ACCOUNTS. Procurement and Contracts: TCU Guidance and Case Law. 5th ed. Section 2.2 — Procurement risk management. Available at: [https://licitacoesecontratos.tcu.gov.br/2-2-gestao-de-riscos-das-contratacoes/](https://licitacoesecontratos.tcu.gov.br/2-2-gestao-de-riscos-das-contratacoes/)
[3] BRAZILIAN FEDERAL COURT OF ACCOUNTS. Procurement and Contracts: TCU Guidance and Case Law. Section 4.5.5 — Risk matrix. Available at: [https://licitacoesecontratos.tcu.gov.br/4-5-5-matriz-de-riscos/](https://licitacoesecontratos.tcu.gov.br/4-5-5-matriz-de-riscos/)
[4] BRAZILIAN FEDERAL COURT OF ACCOUNTS. Procurement and Contracts: TCU Guidance and Case Law. Section 4.4.1 — Delivery models for engineering works and services. Available at: [https://licitacoesecontratos.tcu.gov.br/4-4-1-regimes-de-execucao-de-obras-e-servicos-de-engenharia-2/](https://licitacoesecontratos.tcu.gov.br/4-4-1-regimes-de-execucao-de-obras-e-servicos-de-engenharia-2/)
[5] BRAZILIAN ATTORNEY GENERAL’S OFFICE. Templates under Law No. 14,133/2021 for electronic bidding and competitive tendering — Engineering Works and Services. Available at: [https://www.gov.br/agu/pt-br/composicao/cgu/cgu/modelos/licitacoesecontratos/14133/pregao-e-concorrencia](https://www.gov.br/agu/pt-br/composicao/cgu/cgu/modelos/licitacoesecontratos/14133/pregao-e-concorrencia)
Frequently asked questions
Risk management is the continuous process of identifying, analyzing, evaluating, treating, monitoring, and communicating risks. The risk matrix is a contractual instrument that allocates specific risks and responsibilities between the public authority and contractor.
No. It should begin during planning and continue through preliminary technical studies, surveys, design, estimating, contracting, execution, commissioning, and acceptance.
Law 14,133 allows its use and makes it mandatory for large-scale works and services and for integrated and semi-integrated contracting. Procurement risk analysis and risk management, however, have a broader scope and are not the same as the contractual matrix.
Useful fields include cause, event, consequence, probability, impact, criticality, owner, preventive actions, mitigation, contingency, trigger, deadline, residual risk, and status.
Risks with potential cost or schedule effects need to be linked to estimates, contingencies, milestones, the critical path, and forecast, preventing risk, budget, and schedule from being managed in isolated systems.
The owner should be the function or person responsible for ensuring monitoring, treatment, escalation, and evidence of response. They do not need to execute every action personally.
It is the exposure that remains after controls and treatment actions are applied. This residual risk should be considered in readiness decisions and authorization to proceed.
Additional technical materials
Related services
- Engineering Risk Management
- Technical Support for Construction and Contract Inspection de Engenharia
- Project Management: Schedule, Costs, and Earned Value (Project Controls)
- Technical Planning for Engineering Procurement
Core content on this topic
- Capital Projects in Public Works: structuring public investments from need to operations
- From Preliminary Technical Study to Technical Acceptance: the complete engineering cycle of a public investment
- Public Works Estimating: structuring quantities, costs, BDI, and risks
Related technical content
- Risk Matrix in Engineering Projects: classifying criticality and prioritizing technical decisions
- Risk Allocation Matrix in Engineering Contracts: allocating responsibilities under Law 14,133
- Public Works Management: preventing stoppages, protecting investment, and reducing management risk
- 7 Maturity Gates for Public Engineering Investments