Link your risk register to contingency for South African tenders
A tender-stage risk register must be project-specific, scored to show inherent versus residual risk, carry named owners, and offer mitigations that connect directly to your contingency figure. If the tender involves construction or site work, alignment with the client's baseline health and safety assessment is usually mandatory, not optional. Pair the register with a short risk management approach statement so evaluators see the thinking behind the numbers.
*TL;DR:>
- Building a project-specific risk register with clear owners and mitigations linked to contingency is essential for tender success.*
- The register must include detailed fields like risk description, category, trigger, scores, mitigation, owner, and status, scored on a consistent 5x5 matrix.
- Tailored mitigations that specify actions and triggers are more credible than generic statements and directly influence residual risk and pricing.
- Alignment with the client's baseline health and safety assessment is mandatory, requiring proof of matching documents, competent persons, and method statements.
- Using structured templates and platforms like Protenders can streamline the process, ensuring compliance, capturing site-specific risks, and improving evaluation scores.
Table of Contents
- What to include: exact fields and risk categories for a tender return
- How do you show inherent versus residual risk clearly?
- Writing mitigations that link to price and programme
- Tender compliance and health and safety expectations at tender stage
- Building a tender-ready risk register step by step
- What evaluators look for, and quick fixes for common mistakes
- Where Protenders fits into tender risk documentation
- The overlooked cost of a "safe" generic register
- Get tender-ready risk templates without starting from a blank page
- Sources
- FAQ
What to include: exact fields and risk categories for a tender return
Evaluators aren't grading your risk register on prose. They're scanning for specific, complete fields that prove you understand the project rather than copied a template from your last bid. A register missing even one of these columns reads as rushed, and rushed reads as risky.
Your register needs these fields, in this order:
- Risk ID: a simple reference number for tracking across revisions
- Description: one clear sentence stating what could go wrong, not a vague category label
- Category: which risk type this falls under (see below)
- Trigger: the specific event or condition that would activate the risk
- Inherent likelihood and consequence: the raw score before any mitigation
- Inherent risk rating: the calculated result of that likelihood and consequence
- Mitigation: the concrete action that reduces the risk
- Residual risk rating: the score after mitigation is applied
- Owner: a named person, not a department or "project team"
- Target date and status: when the mitigation happens and where it currently stands
Each field earns its place. Pricing teams use the inherent versus residual gap to justify contingency line items. Evaluators use named owners to judge whether accountability is real or theoretical.
Tender risk categories tend to cluster into seven recognizable groups: commercial and cost (currency exposure, retention terms), programme and schedule (weather delays, approval lead times), technical and design (unproven methods, incomplete specifications), supply chain (single-source materials, import delays), health and safety (site-specific hazards, competent-person availability), environmental and regulatory (permit timing, water use restrictions), and stakeholder or reputational (community objections, subcontractor disputes). A commonly used categorisation groups these under commercial, technical, legal, supply, schedule, and reputational headings. Mapping your risks to a recognized structure like this signals process maturity before an evaluator reads a single mitigation.
How do you show inherent versus residual risk clearly?
A 5x5 qualitative matrix is the standard tool here, and it works because it's fast to apply and easy for evaluators to audit. Score likelihood from rare to almost certain, score consequence from insignificant to severe, and multiply the two to get a rating from 1 to 25.
The presentation matters as much as the scoring itself:
- List your highest inherent risks first, not alphabetically or by category
- Show the inherent rating and residual rating side by side so the drop is visible at a glance
- Include a scoring legend defining what each likelihood and consequence level means in plain terms
- Keep the scale consistent across every risk. Switching methodologies mid-register looks careless
Pro Tip: Don't just show a lower residual number and hope evaluators trust it. Write the mitigation in enough detail that the score reduction is obviously earned, not assumed.
The gap between inherent and residual scores is where contingency decisions get made. A tender's risk profile is meant to sit alongside pricing during evaluation, so a scoring approach that can't be defended under questioning weakens the whole submission, not just that one line.
Writing mitigations that link to price and programme
Generic mitigations are the fastest way to lose evaluator confidence. "Monitor closely" or "manage proactively" tell the reader nothing about what you'd actually do if the risk materialized.
Stronger mitigation language names the action and the trigger:
- Early procurement of long-lead items to absorb supplier delays before they hit the programme
- Pre-qualifying an alternative supplier so a single-source failure doesn't stall the site
- Sequencing temporary works to reduce exposure during high-risk phases
- Adding an inspection regime beyond the contract minimum where quality failure carries heavy rework cost
Each mitigation needs a trigger event (what condition activates it) and an owner responsible for acting on it. Without both, the mitigation is decoration, not a plan.
You don't need exact arithmetic linking every risk to a contingency rand value unless the tender explicitly asks for it. What you do need is qualitative linkage. Say plainly that a residual programme risk of this scale is covered by a specific contingency allowance or float in the programme. That single sentence does more for evaluator confidence than a spreadsheet of unexplained numbers, because it shows the register informed the price rather than being built after the fact to look thorough.
Tender compliance and health and safety expectations at tender stage
Construction tenders in particular carry a compliance layer that sits outside your risk scoring entirely. Many require your submission to align with a client-supplied baseline risk assessment and a documented health and safety plan before your technical or commercial content is even weighed.
Contractor tenders within cidb Grades 2 to 9 are commonly subject to compliance with the cidb Best Practice Project Assessment Scheme, and [contractors must show how their tender-stage register aligns to the client's baseline [contractor health and safety specification]](https://www.etenders.gov.za/home/Download/?blobName=8af0bdc1-4eae-491a-b9a7-6dda459eea80.pdf\&downloadedFileName=Contractor+Health+and+Safety+Specification+%28Security+Equip+-+GH+15-06-22%29.pdf) or risk being marked non-compliant.
The typical H&S returnables evaluators expect alongside your risk register include:
- Evidence that your baseline risk assessment matches the client's own baseline document
- Method statements for the highest-risk activities on site
- An outline health and safety file or a commitment to produce one before mobilisation
- Proof of competent persons assigned to key roles, plus attendance registers where required
Client specifications frequently mandate a baseline assessment before site establishment and construction site pest control: a site manager's IPM plan, often quarterly or whenever conditions change. Skipping this section, or submitting a generic H&S statement that doesn't reference the client's own specification, is one of the more common reasons technically strong bids fail on compliance alone.
Building a tender-ready risk register step by step
You don't need weeks to produce a defensible register. A tight, disciplined process gets you there in a matter of days, even on a compressed submission timeline.
- Extract the constraints first. Read the tender documents for baseline H&S requirements, site conditions, and any project-specific clauses before you write a single risk line.
- Run a short risk identification workshop. Pull in your estimator, site lead, and procurement contact. Capture triggers and assign a real owner to each risk in the room, not afterward.
- Score and mitigate. Apply your 5x5 matrix, write the mitigation, calculate the residual rating, and note the contingency implication in one sentence per risk.
- Draft the one-page approach statement. Cover your methodology, review cadence, and reporting structure. Referencing a recognized framework such as ISO 31000 here signals process maturity, provided the register itself backs it up with practice.
- Package and check. Confirm formatting matches the tender's returnable requirements and every field is complete before it goes into the submission.
| Step | Output | Time estimate |
|---|---|---|
| Extract constraints | Baseline H&S summary, project constraints list | 1 to 2 hours |
| Risk workshop | Draft risk list with triggers and owners | 2 to 3 hours |
| Score and mitigate | Completed register with inherent/residual ratings | Half a day |
| Approach statement | One-page methodology document | 1 to 2 hours |
| Final check | Submission-ready returnable | 1 hour |
A practical template speeds this up considerably. Structured tender risk templates exist specifically to keep this workflow consistent across multiple bids, which matters if your team is submitting several tenders in the same month.
What evaluators look for, and quick fixes for common mistakes
Evaluators are reading dozens of registers that look almost identical. What separates a pass from a fail is usually visible in under a minute of reading.
They're checking for risks tailored to the actual site and scope, named individuals (not departments) against each risk, mitigations specific enough to be believable, and a clear line from residual risk to contingency or procurement strategy.
The mistakes that sink otherwise solid bids are fixable fast:
- Generic register copied from a previous bid: rewrite the top five risks with project-specific detail. Fifteen minutes, real impact.
- Missing or vague owners: assign a named person to every line. Ten minutes.
- Mitigations that just restate the risk: rewrite each one as a concrete action with a trigger. Twenty to thirty minutes.
- No reference to the client's H&S baseline: add one paragraph confirming alignment. Fifteen minutes.
Bidders who tailor their registers to site-specific conditions consistently score better than those submitting boilerplate, because a generic register signals to the evaluator that you haven't actually engaged with their site documents.
Where Protenders fits into tender risk documentation
Building a compliant register is only half the job. Finding the right tenders and matching your compliance documents to what each client actually asks for is the other half, and it's where most SMMEs lose time.
Protenders aggregates tenders from national, provincial, and municipal buyers, so you're working from the correct baseline H&S specification and scope documents from the start rather than guessing. The platform's compliance scorecards flag gaps against a specific tender's requirements, and its document templates give you a returnable-ready register structure and a one-page risk approach statement you can adapt rather than build from scratch under deadline pressure. For contractors who also need contingency or mobilisation funding once a risk register shows real cost exposure, Protenders' funding partnerships connect that gap to actual financing options.
The overlooked cost of a "safe" generic register
Most bid teams treat the risk register as a compliance formality, something to fill in after the pricing and technical sections are locked. That order is backwards, and it shows in the final document. A register bolted on at the end almost always reads generic, because it wasn't allowed to influence the numbers it's supposed to justify.
The conventional advice tells bidders to "be thorough" and "cover all risk categories." That's not wrong, but it's incomplete. Thoroughness without specificity is just a longer generic register. What actually moves an evaluator is seeing five or six risks that could only apply to this exact site, this exact client, and this exact scope, each with an owner who clearly exists and a mitigation that costs something real.
If you take one thing from this: build the register before you finalize your price, not after. Let the residual risks tell you what your contingency should look like, instead of writing contingency first and reverse-engineering a register to match it. That single sequencing change fixes most of the credibility problems evaluators flag.
— Dolene April
Get tender-ready risk templates without starting from a blank page
Protenders gives contractors a faster route from tender document to compliant returnable than building every template from scratch. You get a register structure with the fields evaluators expect, compliance scorecards that flag gaps against a specific tender's H&S and technical requirements, and access to live tenders across national, provincial, and municipal buyers without needing to sign up just to browse.
If you're preparing a submission right now, start by searching live government tenders to pull the exact baseline risk documents your register needs to align with. From there, Protenders' compliance tools and funding match service can help you turn a strong risk register into a complete, submission-ready bid.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Project risk management: risk register and mitigation | IQ Academy
- Management of risk — RICS practice guidance
- What to include in a construction risk register for tenders | Bid Writing Service (2026)
FAQ
What is the purpose of a risk register?
A risk register identifies, scores, and tracks project risks so a team can plan mitigations and justify contingency, and at tender stage it also proves to evaluators that a bidder understands the specific project rather than submitting boilerplate.
Is it a legal requirement to have a risk register?
There's no blanket legal requirement for a risk register in every tender, but many construction tenders require alignment with a client baseline H&S risk assessment, and submitting without one often causes non-compliance.
How do I create a risk register?
Extract project constraints from the tender documents, run a short risk identification session with named owners, score each risk on a 5x5 matrix for inherent and residual ratings, add concrete mitigations, and pair the register with a one-page approach statement.
What are the 7 types of risks?
For tenders, the seven categories that matter most are commercial and cost, programme and schedule, technical and design, supply chain, health and safety, environmental and regulatory, and stakeholder or reputational risk.
Does Protenders provide risk register templates?
Yes. Protenders' document workspace includes returnable-ready register templates and compliance scorecards that check your submission against a specific tender's stated requirements.