Novus Blog Banners

Planning and delay analysis | 25 August 2026

How to conduct a mid-project risk audit in construction

Halfway through a construction project, the risks you planned for are rarely the only risks you face. Scope changes, subcontractor issues, design delays, cost increases, programme pressure and new site hazards can all alter a project's risk profile.

A mid-project risk audit catches those changes early. It helps the project team identify new risks, reassess known risks, test whether controls are working and update the risk register before issues become costly delays or disputes.

This guide explains how to conduct a mid-project risk audit in construction. It is written for project managers, contractors, employers, commercial teams and construction risk professionals who want to stay ahead of project risks rather than react when problems escalate.

Done properly, a risk audit protects the budget, programme and project relationship. It also creates a clearer evidence trail if problems later develop into a claim, adjudication or wider construction dispute.

Audit purpose and timing

A mid-project risk audit has a clear purpose: to identify new risks, reassess existing risks and test whether the project’s risk management process is working in practice.

The audit should not be treated as a paperwork exercise. Its purpose is to answer practical questions. Are the right risks being tracked? Are mitigation actions being completed? Are risks still allocated correctly? Are new commercial, programme or operational issues emerging? Does the risk register reflect the project as it stands today?

Timing matters. A risk audit is most useful around major project milestones, after significant scope changes, following subcontractor disruption, or when market conditions affect cost, procurement or programme. On long-duration projects, a single mid-project audit may not be enough. Regular audits or deeper reviews can sit alongside weekly or fortnightly risk meetings.

The expected outcomes should be agreed at the start. A good audit should produce an updated risk register, prioritised mitigation actions and a concise report that supports decision-making at project or steering committee level.

Prepare the audit team and allocate resources

Good preparation saves time and improves the quality of the findings. Start by assembling an audit team with relevant construction, commercial and risk management experience.

Where possible, include at least one person who is not involved in day-to-day delivery. Independent review helps challenge assumptions and reduce the risk of optimistic reporting.

Assign a lead auditor to own the process. This person should define the scope, coordinate interviews, review evidence and make sure findings are converted into clear actions. Other team members can be assigned to review specific areas, such as programme, cost, contract administration, site operations or health and safety.

Resource allocation should reflect the size and complexity of the project. A complex multi-package scheme will need more audit time than a smaller single-site build. The audit should be thorough enough to be useful, but planned carefully so it does not disrupt live delivery.

Gather the right documentation

Before the audit begins, gather the documents that show the current state of the project. These records provide the evidence base for the review.

Useful documents include:

  • The latest risk register
  • Contract documents and amendments
  • Change order and variation logs
  • Programme updates and progress reports
  • Cost reports and forecasts
  • RFI and design query logs
  • Payment records and notices
  • Site reports and meeting minutes
  • Safety records and incident logs
  • Subcontractor correspondence.

The risk register should be treated as the central reference point. It should record identified risks, likelihood, impact, owner, mitigation action and current status. If the register is incomplete, out of date or disconnected from live project activity, that is itself a risk.

For health and safety-related risks, the audit should also consider whether the project documentation remains aligned with the current construction phase plan. HSE guidance confirms that planning for construction work should address arrangements, site rules and specific measures for higher-risk activities. HSE construction planning guidance is a useful reference point.

Conduct the risk assessment

The heart of the audit is a fresh risk assessment. This is where the team identifies project risks, reassesses their likelihood and impact, and tests whether existing controls remain suitable.

Identify project risks

Begin with the existing risk register. Review what has already been logged, what has been closed and what remains active.

Then go beyond the document. Interview site supervisors, commercial leads and subcontractor representatives to capture risks that may not have been formally recorded. The people closest to the work often see issues before they appear in reports.

A site walk is also important. Independent fieldwork can verify physical progress against documentation and reveal gaps between what is written down and what is actually happening on site. This can highlight sequencing issues, access problems, unsafe interfaces, material shortages or subcontractor performance concerns.

Reassess probability and impact

Once risks have been identified, rate each one again. Use a standard probability and impact scale so ratings stay consistent across the audit team.

Where possible, quantify impact in cost and programme terms. A risk matrix can help rank risks by likelihood and impact, making it easier to identify which items require immediate attention.

Do not assess risks in isolation. Construction risks often interact. Two moderate risks can create a serious combined effect if they occur together, particularly where delay, design change and subcontractor performance are linked.

Evaluate controls and responses

The audit should test whether current controls are effective. Do not assume a mitigation action is working because it appears in the register.

Check whether the action has been completed, whether it is still suitable and whether it has a named owner. Where controls are weak, late or missing, record the gap clearly.

Identifying gaps between documented processes and actual practice is one of the most valuable outcomes of a mid-project risk audit. These gaps often reveal where disputes may later arise.

Review and update the risk register

The risk register is a living document. It should guide current project decisions, not simply record what the team thought at the start of the job.

Add any new risks uncovered during the audit. Update probability and impact ratings where circumstances have changed. Close risks that are no longer relevant, but only where the evidence supports that decision.

For every material change, record the audit evidence behind it. A short note explaining why a rating changed, where a new risk came from, or why a mitigation action is required protects the integrity of the register.

This evidence trail can be important if the project later faces a delay claim, payment dispute or adjudication. Good records help show what the team knew, when they knew it and how they responded.

Assess the wider risk management process

A mid-project audit should not only review individual risks. It should also assess how well the project’s risk management system is working.

Ask whether risks are being logged, reviewed and owned in line with the project’s risk management plan. Check whether mitigation actions are being implemented on time. Review meeting minutes and communication logs to confirm whether stakeholders are being kept informed.

Poor communication is often the hidden cause of escalating risk. If decisions are unclear, instructions are informal, or records are incomplete, risks can quickly become disputes.

RICS’ Management of risk guidance provides a useful professional reference for risk management principles in construction and related project environments.

Create a mitigation action plan

Findings only matter if they lead to action. The audit should produce a clear, prioritised mitigation plan.

For each priority risk, set out the:

  • Risk being addressed
  • Recommended mitigation action
  • Owner responsible for delivery
  • Required resources
  • Deadline for completion
  • Progress (i.e. how it will be monitored).

Prioritise high-impact risks first. These are the risks most likely to affect cost, programme, quality, safety or the project relationship.

Recommendations should be specific. Avoid vague actions such as “monitor programme risk” or “improve communication”. A stronger action would be: “Review critical path progress weekly, record causes of delay and issue contractual notices where required.”

Report the findings clearly

Clear reporting drives better decisions. The audit report should be concise, structured and focused on what the project team needs to do next.

The report should include:

  • The audit purpose and scope
  • Documents reviewed
  • People interviewed
  • Key risks identified
  • Control gaps
  • Updated risk ratings
  • Recommended mitigation actions
  • Owners and deadlines
  • Follow-up review dates.

For major risks, include the likely cost and programme impact of acting versus not acting. This helps the project team, employer or steering committee make informed decisions.

The report should lead with the risks that matter most. Decision-makers may not read every detail, so the executive summary should make the priority issues clear from the start.

Follow up, monitor and close the audit

An audit is not finished when the report is issued. Follow-up is what turns the findings into protection.

Track each mitigation task through regular risk reviews. Where actions are delayed, escalate them early. Where actions are completed, update the risk register to reflect the reduced exposure.

Once the key mitigation actions have been implemented, the audit can be formally closed. The final audit record should be stored with the project documents and lessons learned.

This is particularly useful for future projects. It helps the business improve its risk management process and provides a reliable record if the project later becomes contentious.

Common questions about risk audits

How do you conduct a risk audit?

Conduct a risk audit by defining the objectives, gathering project data, reviewing the risk register, interviewing the team, checking site conditions, assessing controls, updating risk ratings and producing a clear action plan with owners and deadlines.

How do you conduct a risk assessment in construction?

A construction risk assessment identifies hazards across cost, programme, safety, quality and operations. Each risk is rated by likelihood and impact, recorded in the risk register, assigned to an owner and reviewed regularly throughout the project.

How is a project audit different from a risk audit?

A project audit reviews the wider project against its objectives, processes, controls and performance. A risk audit focuses specifically on whether project risks are being identified, assessed, controlled and reviewed effectively.

How do you perform a risk-based audit?

A risk-based audit focuses effort where the exposure is highest. Risks are ranked by likelihood and impact, then audit activity is concentrated on the areas most likely to cause serious cost, programme, safety or contractual consequences.

Appendix: Tools, templates and audit evidence

Consistent tools make risk audits faster and more reliable. Useful audit aids include:

  • A standard risk register template
  • A probability and impact scoring rubric
  • A risk matrix
  • An interview checklist
  • A document review checklist
  • A mitigation action tracker
  • A ‘lessons learned’ template.

Keep a snapshot of the audited risk register as it stood at the time of the review. This provides a clear baseline for the next audit and helps explain why decisions were made.

Reusing the same tools across projects builds a dependable and repeatable audit process.

Contact Novus Resolve

A strong risk audit protects your budget and programme, but expert support can make the difference when risks turn into disputes.

At Novus Resolve, we help project managers, contractors, and construction professionals strengthen risk management, improve documentation and resolve disputes efficiently. From mid-project risk audits and risk register reviews to mitigation planning and adjudication support, we help you stay ahead of project risks and protect your position.

Contact Novus Resolve today to discuss your mid-project risk audit and find out how we can help keep your project on track and on budget.


Related articles:

Planning and delay analysis | 12 August 2026

Top construction project risk management tools and how to use them effectively

Every construction project carries risk. Delays, budget overruns, design changes, payment issues, safety incidents and quality problems can all affect delivery. The right construction project risk management tools help teams identify risks early, track decisions and reduce the likelihood of...

Read more

Planning and delay analysis | 12 August 2026

The role of forensic analysis in post-project audits

When a construction project ends late, over budget or in dispute, the key questions are often the same. What went wrong? Who was responsible? Could the problems have been prevented? A post-project audit helps answer those questions. Forensic analysis gives...

Read more