RAID Log
Build and maintain a RAID log: the running record of Risks, Assumptions, Issues, and Dependencies that could affect delivery.
Definitions (keep them distinct)
- Risk — something that might happen and would have impact. Has probability + impact + mitigation.
- Assumption — something taken as true without proof; becomes a risk if wrong. Track validation.
- Issue — a risk that has materialized, or a current problem. Needs an owner and resolution.
- Dependency — something you need from (or owe to) another team/vendor, with a date.
When to use
- Standing up risk tracking for a project, or adding/updating entries during delivery.
- Prepping a risk review or steering-committee section.
Process
- Classify each item into exactly one of R / A / I / D.
- For risks: score Probability (H/M/L) and Impact (H/M/L), derive severity, and give a mitigation + owner. Note a trigger/early warning if useful.
- For assumptions: note how/when it will be validated and the impact if false.
- For issues: capture impact, owner, target resolution date, and status.
- For dependencies: capture what, direction (we need / they need), owner on both sides, and needed-by date.
- Give every entry a stable ID, an owner, a status (Open/Mitigating/Closed), and a last-updated date. Sort by severity.
Output format
Use templates/raid-template.md. When updating an existing log, preserve IDs and show what changed.