Part 2 — Assessing Risk
Score it, register it, review it on a schedule
Risk identification runs at three points, not once. Before kickoff, as a pre-mortem. At every stage gate. And monthly through build and rollout. A register written once and filed is worse than no register at all, because it creates the appearance of control without any of the substance.
Score every risk on likelihood (1–5) × impact (1–5) and multiply for a score out of 25.
| Score | Priority | Response |
|---|---|---|
| 15–25 | Critical | Escalate to the steering committee; assign an owner within 48 hours |
| 8–14 | High | Mitigation plan required before the next stage gate |
| 4–7 | Moderate | Monitor; review monthly |
| 1–3 | Low | Log and accept |
The risk register
One row per risk, with these fields: ID, category (from the taxonomy in Part 1), description, likelihood, impact, score, owner, mitigation action, target date, status. Keep it as the single source of truth, reviewed at every steering meeting rather than maintained in one person’s head.
The register is only as good as the person reading it, which is why the governance and cadence in Part 4 matter as much as the scoring itself.