← Back to Playbooks

Part 2 — Assessing Risk

Score it, register it, review it on a schedule

Risk identification runs at three points, not once. Before kickoff, as a pre-mortem. At every stage gate. And monthly through build and rollout. A register written once and filed is worse than no register at all, because it creates the appearance of control without any of the substance.

Score every risk on likelihood (1–5) × impact (1–5) and multiply for a score out of 25.

Score Priority Response
15–25 Critical Escalate to the steering committee; assign an owner within 48 hours
8–14 High Mitigation plan required before the next stage gate
4–7 Moderate Monitor; review monthly
1–3 Low Log and accept

The risk register

One row per risk, with these fields: ID, category (from the taxonomy in Part 1), description, likelihood, impact, score, owner, mitigation action, target date, status. Keep it as the single source of truth, reviewed at every steering meeting rather than maintained in one person’s head.

The register is only as good as the person reading it, which is why the governance and cadence in Part 4 matter as much as the scoring itself.