Event risk management, as usually practised, means the risk assessment for a specific event: crowd safety, fire evacuation, electrical testing, contractor insurance. That work is necessary and it is not what this page is about.

This page is about risk that only becomes visible when you look at the whole programme at once, and which is structurally invisible where each event is arranged by whoever needed it. Risk to people is treated separately on duty of care.

The aggregation problem

Consider a hypothetical organisation running forty meetings a year across six departments. Each booking is individually modest, each contract individually reasonable, and nobody has done anything wrong.

Now ask the questions that only make sense at programme level. What is committed under contracts signed but not yet delivered? How much of that would be payable if every event were cancelled tomorrow? How much of the year’s spend sits with one hotel group? Has anyone accepted an attrition clause without knowing what attrition means?

In an organisation with no central record, none of those can be answered — not because the answer is bad but because the data does not exist in one place. That is the argument for programme-level risk management, and the same structural argument made about money on meetings spend visibility.

A programme risk register

The table below is an illustrative structure. It is a prompt for your own risk function, not a completed assessment — the likelihood and impact of each line depend on your portfolio.

Illustrative programme-level risk register for meetings and events

Contractual exposure

How it shows up
Cancellation scales, attrition, minimum spend and force majeure accepted booking by booking, with no aggregate view.
Typical mitigations to discuss
Standard terms negotiated once with regular venues; legal review of non-standard clauses; a register of committed exposure by month.

Supplier concentration

How it shows up
A large share of annual spend with one venue, hotel group or agency, unnoticed until someone totals it.
Typical mitigations to discuss
Concentration reported at the quarterly review; alternatives kept warm; treated as a deliberate choice rather than an accident.

Supplier financial failure

How it shows up
A venue ceasing to trade between deposit and delivery, with prepayments at risk.
Typical mitigations to discuss
Payment terms and deposit levels reviewed; checks proportionate to exposure; contingency venues identified for major events.

Key-person dependency

How it shows up
One internal person holds the relationships, the rates and the history. They leave.
Typical mitigations to discuss
Central records rather than personal inboxes; documented supplier arrangements; a second person familiar with the programme.

Reputational exposure

How it shows up
Venue or destination choice conflicting with the organisation’s stated positions or client expectations.
Typical mitigations to discuss
Criteria agreed in advance with communications input; destination decisions escalated rather than made in sourcing.

Continuity

How it shows up
An event cannot proceed — venue failure, travel disruption, an incident, or wider disruption affecting many events at once.
Typical mitigations to discuss
Rescheduling and virtual fallback considered at contracting; force majeure wording reviewed by legal; a decision-maker identified in advance.

Data and record-keeping

How it shows up
No reliable record of who is attending what, what was signed, or which supplier holds which personal data.
Typical mitigations to discuss
Single programme record; retention agreed with the data protection lead; supplier data-handling addressed in agreements.

Governance failure

How it shows up
Contracts signed without authority; exceptions granted informally; no review cycle, so nothing is caught.
Typical mitigations to discuss
Clear decision rights and signature authority — see meetings governance.

Contractual exposure in more detail

Venue contracts are not simple purchases. They routinely include a sliding cancellation scale rising towards the event date, an attrition provision on contracted room blocks, a minimum food and beverage spend, and force majeure wording determining what happens when neither party can perform.

Each is negotiable to some degree, and far more so at the point of sourcing than after a verbal agreement — the commercial argument for sequencing set out on meetings approval process.

What a programme view adds is the ability to see these terms together. If contracted exposure peaks in one quarter because three large events fall in the same period, that is worth knowing in advance. The attrition clause entry explains the mechanic; what it means for your contracts is a legal question.

Concentration risk

There is a tension here worth stating plainly, because much writing on the subject pretends it does not exist. Consolidating volume with fewer suppliers is how a programme obtains better terms — the basis of a preferred venue programme and of meetings procurement generally. It is also, by definition, concentration.

The answer is not to avoid concentration but to make it deliberate and review it. Concentration resulting from a negotiated agreement with a supplier whose performance is monitored is a commercial decision. Concentration that emerged because one department always uses the same hotel and nobody added it up is an accident. The second is what produces unpleasant surprises.

Practically, this belongs in the quarterly review alongside supplier management.

Key-person dependency

The least discussed risk here is internal. In many organisations the practical knowledge of how meetings get arranged — which venue does what well, what rate was agreed last time, who to call — sits with one or two people, usually in executive support or a small events function.

They are typically very good at it, which is why it has not been a problem. The exposure appears the week they leave, when the organisation discovers the supplier relationships, rate history and contract copies were personal rather than institutional.

The fix is unexciting: records held centrally, agreements documented, and more than one person who understands the programme — one of the quieter arguments developed in decentralised meetings management.

Continuity and cancellation

Every organisation that ran events through 2020 and 2021 learned what force majeure wording was worth, and many learned it expensively. The lesson worth retaining is not a clause but a habit: at the point of contracting, someone should ask what happens if this cannot go ahead.

Programme-level continuity planning is modest work. Know who decides whether an event proceeds. Know the cancellation position on each committed booking and when each scale steps up. Know which events could run in a different format and which are contractually rescheduleable.

None of this prevents disruption. It changes how quickly and how expensively the organisation responds, which across a programme is not a small difference.

Where this fits

Programme risk is one of the more persuasive arguments for a coordinated approach, because unlike savings it needs no baseline to demonstrate. An organisation that cannot state its committed event exposure does not need a benchmark to recognise that as a gap.

If you are building an internal argument, this sits alongside building the business case and the outcome measures on meetings KPIs. Read it with duty of care, which covers the risks attaching to people rather than money.

Frequently asked questions

01How is this different from an event risk assessment?

An event risk assessment covers a single event: the venue, the activity, the people on the day. Programme risk management covers the portfolio — aggregate exposure, supplier concentration, continuity and internal dependency. Both are needed; they answer different questions.

02How do we work out our total committed exposure?

You need every signed contract in one place, with the cancellation position and the date each scale changes. Most organisations discover they do not have that, which is itself the finding.

03Is supplier concentration always bad?

No. Concentration is how a programme earns better terms. It becomes a risk when nobody has decided on it, nobody reviews it and no alternative has been kept viable.

04Can an external partner take on this risk?

Only where it is contractually agreed. A partner can hold the records, surface the exposure and negotiate terms. Liability sits where the contracts say it sits — a question to settle at engagement, as outsourced meetings management discusses.

05How often should a programme risk register be reviewed?

Quarterly alongside the commercial review suits most organisations, with committed exposure looked at more often if the programme is concentrated into peaks.

  1. 01GovernanceDuty of careThe people side of risk, handled separately and deliberately.
  2. 02The ongoing relationshipSupplier managementPerformance, concentration and the review cycle.
  3. 03GovernanceMeetings governanceSignature authority, decision rights and the review that catches this.
  4. 04GlossaryAttrition clauseWhat attrition actually means in a venue contract.
  5. 05The disciplineWhat is Strategic Meetings Management?The full explanation of the discipline this page sits inside.