The list of events that could affect the work but have not yet, each scored for likelihood and impact, with an owner and a planned response.
Risk register and risk log mean the same thing; there is no distinction hiding in the two words. Every line carries a likelihood, and that field is what the artefact is for, because ranking is the only way forty risks turn into the three that get attention. A register closes a line for one of two reasons: the window for it passed, or it happened. The second is not a clean close, and the entry should be marked as occurred and linked to the resulting issue rather than deleted, so the record that the event was foreseen survives it.
See also
The list of events that have already occurred and are affecting the work, each with an owner and a resolution date. Likelihood no longer applies.
A single register holding risks, assumptions, issues and dependencies, and usually decisions, with the type recorded on every line.
The exposure a risk carries before any action has been taken to manage it, scored on the same likelihood and impact scale as the residual score it is compared against.
Where this comes up
One bar per variable, the widest at the top, all of them measured against a baseline down the middle. A tornado diagram ranks what could move an outcome, and by how much.
A risk might happen. An issue already has. That single difference decides which artefact a line belongs in, what you record about it, and who you have to tell.
Contingency reserve sits inside the cost baseline, for risks already named and priced. Management reserve sits above it, for the ones nobody named. Level and authority, not size.
Most risk registers record one number per row. The number that actually justifies spending money is the distance between two of them.