Studio Matrx Monthly · Volume 1 · Issue 3 · August 2026
Amogh N P
 In loving memory of Amogh N P — Architect · Designer · Visionary 
Quality, Risk & Project ControlsLesson 6.4
APM for Architecture, Planning & Urban Design/Module 6 · Project Management for Architects

Lesson 6.4 · Project Management for Architects

Quality, Risk & Project Controls

Catching errors before they cost, naming risks before they bite, and controlling change before it runs away

15 min Interactive lessonFree · open lessonByAmogh N P· Architect & interior designer
The hook

What you don't control, controls you

A missed clash on a drawing, a risk nobody named, a client change that slipped through unpriced - none of these feels like much on the day. But these are the small, uncontrolled things that quietly compound into the disputes, overruns and claims that define a bad project. Controls are the unglamorous habits that catch them early - and they are what separate a practice that delivers reliably from one that just gets lucky.

Controls are boring right up until the moment they save the whole project. Then they are the only thing that mattered.

Getting it right

Quality management: assurance and control

Quality on a project has two faces, and confusing them is common. Quality assurance (QA) is about the process - the systems, standards, templates and checks a practice puts in place so that good work is produced reliably, by design rather than by luck. Quality control (QC) is about the product - the actual checking of the specific output, catching the errors in this drawing, this specification, this piece of built work. QA is building a machine that tends to produce good work; QC is inspecting what came off the machine. A good practice needs both: standards and systems so quality is the default, and rigorous checking because no system is perfect.

For a design practice, quality management is intensely practical. It means office standards - drawing conventions, specification templates, a checked and coordinated set of details - so that every project starts from a reliable baseline rather than reinventing everything. It means a checking discipline: no drawing leaves the office un-reviewed, coordination between disciplines is verified before issue, and someone other than the author looks at important output, because we are all blind to our own errors. And it means, in construction, the inspection of the works - the architect visiting site to check that what is built matches what was designed and specified, and that quality standards are met, within the scope of the appointed services.

The stakes are high because quality failures are expensive and they are a liability. An error that escapes into a construction drawing becomes a defect on site, a variation, a delay, a cost - and potentially a professional indemnity claim against the practice. The cheapest place to catch an error is at the desk, before issue; the most expensive is in the finished building. This is the whole economic argument for quality systems: they cost time up front and save far more down the line, and they protect the practice's reputation and its professional standing. Invest in the machine, and check what it makes.

The controls loopPlan and checkDesign reviewRisk registerChangecontrolReport andlearnCost of catching an errorat the deskin docson sitecheapruinous
Zoom
The controls loop and the cost of catching an error. Quality checks, design review, risk management, change control and reporting run continuously, feeding lessons back in. Inset: the later an error is caught, the more it costs - cheapest at the desk, ruinous in the finished building.

The cheapest place to catch an error is your own desk. The most expensive is the finished building.

Reviewing the design

Design review: the structured second look

One specific, high-value quality practice deserves its own discussion: the design review. This is the deliberate, structured examination of the design at key points by people other than its authors - a stepping-back to ask, before the design is frozen and built upon, whether it actually works. A good review looks across several dimensions at once: does it meet the brief; is it coordinated across disciplines (do the structure, services and architecture actually fit together); is it buildable; is it compliant with codes and regulations; is it within budget; and is it, still, good? Reviews are best held at stage transitions, precisely when a decision is about to be locked in and revisiting it later would be costly.

The value of a review comes from the outside eye and the structured questions. Designers fall in love with their solutions and go blind to their flaws; a fresh, senior, or peer perspective catches what the author cannot see. Structure helps too - a checklist or a set of standard questions ensures the review covers the unglamorous essentials (compliance, coordination, cost) and not just the exciting ones (does it look good). Crucially, a review is not a critique for its own sake; it produces actions - specific things to fix or verify, with owners and dates - and those actions are tracked to closure like any other task. A review whose findings evaporate is theatre.

Design review connects directly to risk, because many project risks are born in the design and are cheapest to kill there. A coordination clash caught in a review is a five-minute fix; the same clash discovered on site is a stoppage, a variation and an argument. A compliance issue caught before submission is a redraw; caught after construction it can be a catastrophe. This is why mature practices build reviews into their programme as non-negotiable gates, not optional extras squeezed out when time is tight - because the review is exactly the thing that prevents the crisis that would have cost far more time than the review ever did.

A clash caught in review is a five-minute fix. The same clash on site is a stoppage, a variation and an argument.

Naming the dangers

The risk register: writing down what could go wrong

Risk management begins with a deceptively simple act: writing down, deliberately and early, what could go wrong. The tool for this is the risk register - a living list of the project's risks, each described, assessed and assigned an owner and a response. The discipline of actually naming risks is more powerful than it sounds, because most project disasters are not truly unforeseeable; they are foreseeable risks that nobody bothered to name, so nobody prepared for them. The difficult ground conditions, the slow approval, the client who might change their mind, the long-lead item that might not arrive - these are knowable in advance, and a register forces the team to say them out loud.

Each risk is assessed on two axes: how likely it is to happen (probability) and how bad it would be if it did (impact). Multiplying or combining these gives a sense of the risk's severity and lets you rank them - which is the whole point, because you cannot give equal attention to everything. A high-probability, high-impact risk demands a plan now; a low-probability, low-impact one can be noted and watched. Plotting risks on a simple matrix of probability against impact - the classic red/amber/green risk matrix - turns a long list into a picture that instantly shows where the real dangers are and where to spend your limited management attention.

A register is only alive if it is used. It should be created early, reviewed regularly (risks change - some pass, some grow, new ones appear), and owned - every significant risk needs a named person responsible for watching and managing it, or it will be watched by no one. On larger projects the register is a formal document, sometimes maintained by a dedicated PM or PMC; on smaller ones it can be a simple sheet the architect keeps. The size matters less than the habit. The practices that seem lucky - rarely blindsided, always somehow prepared - are almost never lucky; they are the ones who named the risks in advance and quietly did something about them.

Risk matrix and responsesImpactProbabilitylowmedhighhighmedlowact nowFour responsesAvoidchange the plan so it cannot happenReducelower its probability or impactTransferinsurance, warranty, contract clauseAcceptlive with it - back it with contingency
Zoom
The risk matrix and the four responses. Each risk is placed by probability and impact; the red top-right cluster is where management attention belongs. For each risk you choose one of four responses - avoid, reduce, transfer or accept - matched to its severity.

Most disasters are foreseeable risks nobody wrote down. The register is just the act of writing them down.

Doing something about it

Risk response: the four things you can do

Naming a risk is only half the job; the register must also say what you will do about each one, and there are essentially four responses to choose from. You can avoid the risk - change the plan so it cannot happen (redesign to remove a dangerous detail, choose a proven material over an experimental one, drop a scope that carries too much danger). You can reduce (mitigate) it - lower its probability or its impact (order the long-lead item early, do extra site investigation, add a design review). You can transfer it - shift it to someone better placed to carry it (insurance, a warranty, a contract clause that allocates it to the party who controls it). Or you can accept it - consciously decide to live with it, usually for low-severity risks, ideally with a contingency set aside if it bites.

The art is matching the response to the risk. It is wasteful to spend heavily avoiding a trivial risk, and reckless to merely accept a severe one. The register's probability-and-impact assessment guides this: the high-severity risks earn active avoidance or mitigation and a real plan; the minor ones are accepted and watched. Transfer deserves special care, because it is often misunderstood - insurance and contract clauses move the financial consequence of a risk, but they rarely remove the disruption, the delay or the reputational damage, and a risk transferred on paper to a party who cannot actually manage it is not really controlled at all.

Risk response also links straight to the money and the programme. Mitigations cost time and money now to save more later - ordering early, investigating the ground, adding reviews - and these costs belong in the budget and the programme, not as afterthoughts. Accepted risks are exactly what the contingency exists for. And the professional dimension matters in India as everywhere: some risks are managed through professional indemnity insurance and careful contracts, but the principle throughout is to explain the risk and its treatment plainly and, for the legal and insurance specifics, defer to a lawyer, an insurer and the current contract - never to assume. A risk response plan is where risk management stops being a list and becomes action.

Risk matrix and responsesImpactProbabilitylowmedhighhighmedlowact nowFour responsesAvoidchange the plan so it cannot happenReducelower its probability or impactTransferinsurance, warranty, contract clauseAcceptlive with it - back it with contingency
Zoom
The risk matrix and the four responses. Each risk is placed by probability and impact; the red top-right cluster is where management attention belongs. For each risk you choose one of four responses - avoid, reduce, transfer or accept - matched to its severity.
Managing change

Change control: the discipline that saves projects

Change is inevitable on every project - the client's needs evolve, the ground surprises you, the design develops, the authority requires something. Change is not the problem; uncontrolled change is. Change control is the formal process by which every proposed change is captured, assessed for its effect on scope, time and cost, decided upon by the right person, and recorded, before it is implemented. Without it, a project dies the death of a thousand cuts: dozens of small, unpriced, undocumented changes that each seemed trivial but that collectively blow the budget, wreck the programme and poison the relationship when the final account arrives full of surprises.

The process is not bureaucracy for its own sake; it is the mechanism that keeps the iron triangle honest. When a change is proposed - by anyone - it is written down, its impact on cost and programme is assessed, and it is put to the person with authority to decide (usually the client, for changes that affect their money or their building). Only when it is approved is it implemented and formally recorded, typically as a variation or change order under the building contract. The magic of the process is that it makes every change a conscious, visible, agreed decision rather than a silent drift, so the client is never surprised and the record is never in doubt. 'Yes, we can add that, and here is what it costs in money and time - shall we proceed?' is the whole of change control in one sentence.

The hardest part is discipline under pressure. On a busy site, with a client asking for 'just one small thing', the temptation to say yes informally and sort out the paperwork later is enormous - and it is exactly how projects lose control. The professional habit is to welcome the change but insist on the process: capture it, price it, get it agreed, record it, then do it. This protects everyone - the client from surprise bills, the contractor from unpaid work, the architect from disputes and claims. In contract terms these become variations with their own valuation and time implications, and administering them fairly is a core duty of the architect as contract administrator. A project with strong change control has no nasty surprises at the final account; a project without it has almost nothing else.

The controls loopPlan and checkDesign reviewRisk registerChangecontrolReport andlearnCost of catching an errorat the deskin docson sitecheapruinous
Zoom
The controls loop and the cost of catching an error. Quality checks, design review, risk management, change control and reporting run continuously, feeding lessons back in. Inset: the later an error is caught, the more it costs - cheapest at the desk, ruinous in the finished building.

Change is not the enemy. Silent, unpriced, undocumented change is.

Watching and learning

Progress reporting, earned value and lessons learned

All the controls need a heartbeat - a regular rhythm of measuring where the project actually is against where it should be, and telling the people who need to know. Progress reporting is that heartbeat: a periodic, honest report showing status against programme, cost against budget, the open risks, the changes in train, and the decisions needed. Its cardinal virtue is honesty. A report that hides bad news to keep the client calm is worse than useless, because it removes the chance to act while there is still time; the report's whole job is to surface trouble early enough to do something about it. Good reports are concise, regular, and action-oriented - what is the status, what is off track, what will we do, what do we need from you.

A sharper way to measure progress is earned-value thinking. The trap in naive reporting is confusing spend with progress - having used half the budget does not mean half the work is done. Earned value compares three things: the value of work you planned to have done by now, the value of work actually done (the earned value), and what you have actually spent. Comparing planned to earned tells you if you are ahead or behind on schedule; comparing earned to spent tells you if you are over or under on cost. You do not need the full formal apparatus of earned value management to use the idea - simply asking 'how much have we actually earned, versus what we have spent and what we planned' cuts through the comforting fog of activity to the truth of progress.

Finally, controls close the loop with lessons learned. At the end of every project - and ideally at milestones along the way - the team should honestly review what went well, what went badly, and what they would do differently, and capture it so the next project benefits. This is the step almost everyone skips, because the project is over and everyone is exhausted and already on the next thing - and it is precisely why practices repeat the same mistakes for decades. A practice that genuinely runs post-project reviews and feeds the lessons back into its standards, its estimates and its risk registers gets steadily, compoundingly better; one that does not relearns the same painful lessons on every job. The final control is the discipline to learn.

The controls loopPlan and checkDesign reviewRisk registerChangecontrolReport andlearnCost of catching an errorat the deskin docson sitecheapruinous
Zoom
The controls loop and the cost of catching an error. Quality checks, design review, risk management, change control and reporting run continuously, feeding lessons back in. Inset: the later an error is caught, the more it costs - cheapest at the desk, ruinous in the finished building.
Bodies, documents and frameworks

PMBOK / APM - risk, quality and change management

Established frameworks for identifying and responding to risk, managing quality, and controlling change on projects

Reference them for the vocabulary of QA/QC, the risk register, response strategies (avoid, reduce, transfer, accept) and change control.

Risk register and probability-impact matrix

A living list of assessed risks, each with an owner and a response, ranked by likelihood and consequence

The core risk tool; the matrix turns a long list into a picture of where management attention should go.

Change control / variations under the building contract

The formal process for capturing, pricing, approving and recording changes - implemented contractually as variations or change orders

Administering variations fairly is a core duty of the architect as contract administrator; the specifics live in the particular contract (e.g. FIDIC, JCT, NEC, or a local form).

Professional indemnity insurance and COA conduct

The insurance and professional-conduct framework within which design risk and quality failures are managed in India

Manage quality and risk to protect your professional standing; for the specifics of cover, contracts and liability, defer to a lawyer, your insurer and the current COA regulations.

Hands-on workshop

Workshop - build a risk register and a change-control rule

This exercise produces the two controls that save the most projects: a real risk register with responses, and a one-line change-control process you will actually follow under pressure.

A spreadsheet or paper, and honest imagination about what could go wrong.

Given & goal
Goal: create a working risk register and a change-control routine for one project
Inputs: one project you know or are imagining
Time: ~60 minutes
  1. 1Brainstorm at least ten things that could go wrong on this project - design, site, client, statutory, supply, weather, money. Do not filter yet; the point is to name them, because unnamed risks are unmanaged risks.
  2. 2For each risk, rate probability (low/medium/high) and impact (low/medium/high), then place it on a 3x3 matrix. The top-right cluster - likely and severe - is where your attention must go.
  3. 3For each high-severity risk, choose a response - avoid, reduce, transfer or accept - and write the specific action and the person who owns it. Note which mitigations cost time or money now, and add them to your programme and budget.
  4. 4Write your change-control rule in one sentence you could say on site under pressure - for example: 'Any change gets written down and priced before we do it, and agreed by the client if it affects their cost or building.' Make it short enough to actually keep.
  5. 5Sketch a one-page monthly progress report template: status vs programme, cost vs budget, open risks, changes in train, decisions needed. This is your project's heartbeat.

You’ll walk away with
A one-page risk register with rated risks, responses and owners; a placement on a probability-impact matrix; a one-sentence change-control rule; and a progress-report template.

The worked example

Three altitudes on the same idea

Read the band that fits you — or all three.

For the architectRun projects and a practice with command

Build quality into the practice as a system - office standards, templates, a no-drawing-leaves-unchecked rule - because it protects both your buildings and your professional indemnity position, and because errors are cheapest to catch at the desk. Treat risk registers, design reviews and change control as non-negotiable habits rather than paperwork squeezed out when time is tight; they are exactly what prevents the disputes and claims that threaten a practice. And insist on lessons learned - the single cheapest way to get compoundingly better - while deferring the legal and insurance specifics of risk to a lawyer and your insurer.

For the project leadDeliver on time, on budget, on brief

As the project lead, you run the controls: a live risk register with named owners and real responses, design reviews gated at stage transitions with actions tracked to closure, and above all ironclad change control - every change captured, priced, agreed and recorded before it happens, no matter how small it seems or how much pressure you are under. Report progress honestly, using earned-value thinking to tell real progress from mere spend, and surface bad news early enough to act. You are the person who ensures nothing at the final account is a surprise.

For the studentThe business of architecture, made clear

Learn that the controls in this lesson are how good practices avoid the disasters that sink careless ones - and that almost every disaster was a foreseeable risk nobody wrote down, or a change nobody priced. Practise the habit now: on your own studio projects, keep a tiny risk list and get a peer to review your design before you commit to it. The instinct to check your own work, name what could go wrong, and learn honestly from what did is the foundation of everything reliable in practice.

Misconception check

Risk registers, change control and progress reports are corporate bureaucracy - fine for a big PMC on a huge job, but overkill for a small practice doing a house. They just slow the real work down.

The scale of the paperwork should match the project, but the disciplines themselves are exactly what protect a small practice, which can least afford a disaster. A single blown project - an unpriced change that becomes a fee dispute, a foreseeable risk that nobody named and that then materialises, an error that escapes into construction and becomes a professional indemnity claim - can wound a small firm far more deeply than a large one. These controls are not corporate ritual; they are the cheapest insurance a practice can buy, and at small scale they are correspondingly small: a one-page risk list, a simple rule that changes get written down and priced before they are done, a short honest note to the client each month, and a habit of getting a colleague to check important work. None of that slows the real work; it is the real work, the part that keeps the beautiful design from being destroyed by a preventable crisis. The practices that seem to sail through projects untroubled are not lucky and they are not free of process - they have quietly made these habits second nature, sized sensibly to the job in front of them.
Try it

Do it yourself

Test your grip on controls.

  1. 1Distinguish quality assurance from quality control in one sentence each, using a construction drawing as your example.
  2. 2A client asks for 'one small change' on site and wants you to 'sort the paperwork later.' What is the professional response, and why?
  3. 3For a risk that is unlikely but catastrophic, which of the four responses is usually right, and which is usually wrong?
  4. 4You have spent half the budget. Why does earned-value thinking refuse to conclude that half the work is done?
Take this with you

The one idea to carry out

Quality, risk and change are the things that go wrong when you do not control them - so build quality in through systems and checking, catch design errors early through structured review, name and rank your risks in a living register with real responses, and above all control change so every alteration is captured, priced, agreed and recorded before it happens. Report progress honestly, use earned-value thinking to tell real progress from mere spend, and close every project with honest lessons learned. These unglamorous habits, sized to the job, are what separate a practice that delivers reliably from one that merely gets lucky.
Take it further
References & further reading

Peer-reviewed journals & authoritative standards

  1. 01APM Body of Knowledge - risk, quality and change controlAssociation for Project Management (APM), 2019.
  2. 02PMBOK Guide - project risk, quality and earned value managementProject Management Institute (PMI), 2021.
  3. 03Risk register, change control and earned value - knowledge articlesDesigning Buildings Wiki, 2024.
  4. 04Quality management and construction inspection - professional guidanceChartered Institute of Building (CIOB), 2024.
Related lessons
Recap
Quality has two faces: assurance (systems that produce good work) and control (checking the output). Design review is the structured second look that kills errors and risks early. The risk register names, rates and owns what could go wrong; risk response chooses to avoid, reduce, transfer or accept each one. Change control captures, prices, agrees and records every change before it happens - the discipline that prevents final-account surprises. Progress reporting and earned-value thinking measure honestly, and lessons learned make the next project better.
Carry forward →

You now hold the full project-management toolkit - constraints and roles, planning and programme, cost and budgets, and the controls that catch trouble early. Together they are how an architect turns a good design into a well-delivered building. Carry them into the studio: the discipline you have just learned is what protects, in the real world, everything you care about as a designer.

A

The author

Amogh N P

Architect, interior designer, and creative polymath. Studio Matrx began in his notebooks — his vision of design made honest, useful, and open to everyone. Its Academy is written and taught in his memory, and free, forever.

More about Amogh →