Risk Assessor
The Risk Assessor skill helps teams proactively identify, analyze, prioritize, and mitigate project risks before they become problems. It uses systematic risk management frameworks to surface threats, evaluate their likelihood and impact, and create actionable mitigation strategies.
This skill excels at conducting pre-mortem exercises, creating risk registers, assessing probability and impact, developing contingency plans, and establishing early warning indicators to catch risks before they derail projects.
Risk Assessor follows the principle that the best time to handle a risk is before it becomes a crisis. Proactive risk management enables better decisions, realistic planning, and fewer surprises.
Core Workflows
Workflow 1: Conduct Risk Assessment
Steps:
Risk Identification
- Pre-mortem exercise: Imagine project failed; what caused it?
- Brainstorming: Team generates potential risks
- Category review: Check common risk categories
- Technical: Architecture, performance, security, scalability
- Schedule: Deadlines, dependencies, resource availability
- Resource: Team capacity, skill gaps, budget constraints
- External: Market changes, regulatory, vendor dependencies
- Quality: Bugs, tech debt, user experience
- Organizational: Stakeholder alignment, priority shifts
- Historical analysis: Review past project issues
- Expert input: Consult specialists (security, legal, etc.)
Risk Documentation
- For each risk, document:
- Description: What is the risk?
- Category: What type of risk?
- Trigger: What would cause this risk to occur?
- Impact: What happens if risk occurs?
- Owner: Who monitors and manages this risk?
Probability Assessment
- Rate likelihood of occurrence:
- Low (1): < 10% chance
- Medium (2): 10-50% chance
- High (3): > 50% chance
- Base on data, experience, and expert judgment
- Document assumptions behind probability
Impact Assessment
- Rate severity if risk occurs:
- Low (1): Minor delay or cost increase
- Medium (2): Significant schedule or scope impact
- High (3): Project failure or major business impact
- Consider multiple dimensions: time, cost, quality, reputation
- Use worst-case scenario thinking
Risk Prioritization
- Calculate Risk Score = Probability × Impact
- Prioritize by score (1-9 scale):
- Critical (7-9): Address immediately
- High (4-6): Develop mitigation plan
- Medium (2-3): Monitor regularly
- Low (1): Track but no active mitigation
- Focus on top 5-10 highest-priority risks
Output: Risk register with identified, assessed, and prioritized risks.
Workflow 2: Develop Mitigation Strategies
For each high-priority risk:
Choose Strategy Type
- Avoid: Eliminate the risk (change approach, remove feature)
- Mitigate: Reduce probability or impact (add testing, hire expert)
- Transfer: Shift risk to third party (insurance, vendor SLA)
- Accept: Acknowledge risk, plan response if occurs
Create Mitigation Plan
- Specific actions to reduce risk
- Assign owners and due dates
- Define success criteria
- Estimate cost and effort
- Identify dependencies
Develop Contingency Plan
- "If risk occurs, we will..."
- Fallback options and alternatives
- Recovery time objectives
- Communication plan for stakeholders
- Resource requirements
Define Early Warning Indicators
- Leading indicators that risk is materializing
- Monitoring frequency and method
- Threshold for triggering contingency
- Who watches and who gets alerted
Output: Risk mitigation and contingency plans with clear ownership.
Workflow 3: Monitor and Update Risks
Weekly:
- Review early warning indicators
- Update probability/impact if conditions change
- Check status of mitigation actions
- Add newly identified risks
- Close resolved or obsolete risks
Monthly:
- Full risk register review
- Assess effectiveness of mitigations
- Report top risks to stakeholders
- Adjust priorities based on new information
- Update contingency plans
When triggered:
- If risk occurs, activate contingency plan
- Document what happened and lessons learned
- Update risk models for future projects
Workflow 4: Pre-Mortem Exercise
Facilitated team session (60 min):
Set the Stage (5 min)
- "Imagine it's 6 months from now and this project failed spectacularly"
- "We're conducting a post-mortem to understand what went wrong"
- "What caused the failure?"
Individual Brainstorm (10 min)
- Each person silently writes failure scenarios
- Encourage creative and uncomfortable thinking
- No censoring or filtering
Share Round-Robin (20 min)
- Each person shares their scenarios
- Capture all on shared board
- No debate or defense, just listen
Group and Prioritize (15 min)
- Cluster similar failure modes
- Vote on most likely or most impactful
- Identify top 5-10 failure scenarios
Convert to Risks (10 min)
- Reframe failures as current risks
- Add to risk register
- Assign initial owners
Output: List of identified risks from team's collective wisdom.
Quick Reference
| Action |
Command/Trigger |
| Assess risks |
"assess risks for [project]" |
| Pre-mortem |
"run pre-mortem for [project]" |
| Risk register |
"create risk register" |
| Update risks |
"update risk status" |
| Top risks |
"what are the top risks" |
| Mitigation plan |
"create mitigation plan for [risk]" |
| Contingency plan |
"plan contingency for [risk]" |
| Risk report |
"generate risk report" |
Best Practices
- Make it safe: Encourage honest risk identification; reward raising concerns early
- Think like a pessimist: When identifying risks, assume Murphy's Law (what can go wrong, will)
- Quantify when possible: Use data and metrics, not just gut feel, for probability and impact
- Focus on top risks: Can't mitigate everything; focus on highest-priority risks
- Own every risk: Each risk needs a named owner who monitors and drives mitigation
- Plan before crisis: Contingency plans made in calm are better than in panic
- Review regularly: Risks evolve; weekly review keeps register current and actionable
- Learn from history: Past project failures are excellent teachers for future risk identification
- Update probability as you learn: As project progresses, adjust probabilities based on new information
- Don't ignore uncomfortable truths: The risks you avoid discussing are often the most dangerous
- Communicate transparently: Share top risks with stakeholders; surprises destroy trust
- Balance paranoia and progress: Risk management shouldn't paralyze; it should inform action
Risk Categories Checklist
Technical Risks
Schedule Risks
Resource Risks
External Risks
Quality Risks
Organizational Risks
Risk Matrix
IMPACT
Low (1) Med (2) High (3)
PROBABILITY
High (3) 3 (H) 6 (H) 9 (C)
Med (2) 2 (M) 4 (H) 6 (H)
Low (1) 1 (L) 2 (M) 3 (H)
C = Critical (7-9): Immediate action required
H = High (4-6): Develop mitigation plan
M = Medium (2-3): Monitor regularly
L = Low (1): Track in register
Mitigation Strategy Decision Tree
Can we eliminate this risk entirely?
YES → AVOID strategy (change approach)
NO ↓
Can we significantly reduce probability or impact?
YES → MITIGATE strategy (take action)
NO ↓
Can someone else manage this better?
YES → TRANSFER strategy (outsource, insure)
NO ↓
ACCEPT strategy (plan contingency)
Risk Register Template
## Risk Register - [Project Name]
Last Updated: [Date]
### Critical Risks (Score 7-9)
#### R-001: [Risk Title]
- **Description**: [What is the risk?]
- **Category**: Technical | Schedule | Resource | External | Quality | Organizational
- **Probability**: High (3) | Medium (2) | Low (1)
- **Impact**: High (3) | Medium (2) | Low (1)
- **Risk Score**: [P × I]
- **Trigger**: [What causes this?]
- **Owner**: [Name]
- **Status**: Active | Monitoring | Closed
- **Mitigation Strategy**: Avoid | Mitigate | Transfer | Accept
- **Mitigation Actions**:
- [ ] Action 1 - Owner - Due Date
- [ ] Action 2 - Owner - Due Date
- **Contingency Plan**: If risk occurs, we will...
- **Early Warning Indicators**: [What to watch for]
- **Last Reviewed**: [Date]
### High Risks (Score 4-6)
[Same format as above]
### Medium Risks (Score 2-3)
[Same format as above]
Common Project Risks & Mitigations
Risk: Key Developer Leaves Mid-Project
- Mitigation: Pair programming, documentation, knowledge sharing
- Contingency: Contractor backup, timeline extension
- Indicator: Team member disengagement, job searching signals
Risk: Requirements Change Significantly
- Mitigation: Agile approach, frequent stakeholder check-ins, MVP focus
- Contingency: Scope negotiation, timeline adjustment
- Indicator: Stakeholder dissatisfaction, market feedback
Risk: Third-Party API Becomes Unreliable
- Mitigation: Implement caching, retry logic, circuit breakers
- Contingency: Alternative vendor, build in-house
- Indicator: Increased error rates, latency spikes
Risk: Performance Doesn't Meet Requirements
- Mitigation: Early performance testing, architecture review
- Contingency: Optimization sprint, infrastructure scaling
- Indicator: Load test failures, user complaints
Risk: Security Vulnerability Discovered
- Mitigation: Security reviews, penetration testing, dependency scanning
- Contingency: Incident response plan, rollback procedure
- Indicator: Security alerts, CVE notifications
Risk: Project Runs Over Budget
- Mitigation: Accurate estimation, buffer allocation, cost tracking
- Contingency: Scope reduction, additional funding request
- Indicator: Burn rate exceeds projections
Integration Points
- Project Planner: Identifies risks during planning phase
- Sprint Planner: Reviews risks at sprint planning
- Task Manager: Tracks mitigation action items
- Retrospective Facilitator: Captures risk learnings
- Stakeholder Communication: Reports risk status
- Incident Management: Triggers contingency plans
1---2name: risk-assessor-23description: Identify, analyze, and mitigate project risks using systematic risk management frameworks4---5
6# Risk Assessor
7
8The Risk Assessor skill helps teams proactively identify, analyze, prioritize, and mitigate project risks before they become problems. It uses systematic risk management frameworks to surface threats, evaluate their likelihood and impact, and create actionable mitigation strategies.
9
10This skill excels at conducting pre-mortem exercises, creating risk registers, assessing probability and impact, developing contingency plans, and establishing early warning indicators to catch risks before they derail projects.
11
12Risk Assessor follows the principle that the best time to handle a risk is before it becomes a crisis. Proactive risk management enables better decisions, realistic planning, and fewer surprises.
13
14## Core Workflows
15
16### Workflow 1: Conduct Risk Assessment
17
18**Steps:**
191. **Risk Identification**
20 - **Pre-mortem exercise**: Imagine project failed; what caused it?
21 - **Brainstorming**: Team generates potential risks
22 - **Category review**: Check common risk categories
23 - Technical: Architecture, performance, security, scalability
24 - Schedule: Deadlines, dependencies, resource availability
25 - Resource: Team capacity, skill gaps, budget constraints
26 - External: Market changes, regulatory, vendor dependencies
27 - Quality: Bugs, tech debt, user experience
28 - Organizational: Stakeholder alignment, priority shifts
29 - **Historical analysis**: Review past project issues
30 - **Expert input**: Consult specialists (security, legal, etc.)
31
322. **Risk Documentation**
33 - For each risk, document:
34 - **Description**: What is the risk?
35 - **Category**: What type of risk?
36 - **Trigger**: What would cause this risk to occur?
37 - **Impact**: What happens if risk occurs?
38 - **Owner**: Who monitors and manages this risk?
39
403. **Probability Assessment**
41 - Rate likelihood of occurrence:
42 - **Low (1)**: < 10% chance
43 - **Medium (2)**: 10-50% chance
44 - **High (3)**: > 50% chance
45 - Base on data, experience, and expert judgment
46 - Document assumptions behind probability
47
484. **Impact Assessment**
49 - Rate severity if risk occurs:
50 - **Low (1)**: Minor delay or cost increase
51 - **Medium (2)**: Significant schedule or scope impact
52 - **High (3)**: Project failure or major business impact
53 - Consider multiple dimensions: time, cost, quality, reputation
54 - Use worst-case scenario thinking
55
565. **Risk Prioritization**
57 - Calculate Risk Score = Probability × Impact
58 - Prioritize by score (1-9 scale):
59 - **Critical (7-9)**: Address immediately
60 - **High (4-6)**: Develop mitigation plan
61 - **Medium (2-3)**: Monitor regularly
62 - **Low (1)**: Track but no active mitigation
63 - Focus on top 5-10 highest-priority risks
64
65**Output:** Risk register with identified, assessed, and prioritized risks.
66
67### Workflow 2: Develop Mitigation Strategies
68
69**For each high-priority risk:**
70
711. **Choose Strategy Type**
72 - **Avoid**: Eliminate the risk (change approach, remove feature)
73 - **Mitigate**: Reduce probability or impact (add testing, hire expert)
74 - **Transfer**: Shift risk to third party (insurance, vendor SLA)
75 - **Accept**: Acknowledge risk, plan response if occurs
76
772. **Create Mitigation Plan**
78 - Specific actions to reduce risk
79 - Assign owners and due dates
80 - Define success criteria
81 - Estimate cost and effort
82 - Identify dependencies
83
843. **Develop Contingency Plan**
85 - "If risk occurs, we will..."
86 - Fallback options and alternatives
87 - Recovery time objectives
88 - Communication plan for stakeholders
89 - Resource requirements
90
914. **Define Early Warning Indicators**
92 - Leading indicators that risk is materializing
93 - Monitoring frequency and method
94 - Threshold for triggering contingency
95 - Who watches and who gets alerted
96
97**Output:** Risk mitigation and contingency plans with clear ownership.
98
99### Workflow 3: Monitor and Update Risks
100
101**Weekly:**
1021. Review early warning indicators
1032. Update probability/impact if conditions change
1043. Check status of mitigation actions
1054. Add newly identified risks
1065. Close resolved or obsolete risks
107
108**Monthly:**
1091. Full risk register review
1102. Assess effectiveness of mitigations
1113. Report top risks to stakeholders
1124. Adjust priorities based on new information
1135. Update contingency plans
114
115**When triggered:**
116- If risk occurs, activate contingency plan
117- Document what happened and lessons learned
118- Update risk models for future projects
119
120### Workflow 4: Pre-Mortem Exercise
121
122**Facilitated team session (60 min):**
123
1241. **Set the Stage (5 min)**
125 - "Imagine it's 6 months from now and this project failed spectacularly"
126 - "We're conducting a post-mortem to understand what went wrong"
127 - "What caused the failure?"
128
1292. **Individual Brainstorm (10 min)**
130 - Each person silently writes failure scenarios
131 - Encourage creative and uncomfortable thinking
132 - No censoring or filtering
133
1343. **Share Round-Robin (20 min)**
135 - Each person shares their scenarios
136 - Capture all on shared board
137 - No debate or defense, just listen
138
1394. **Group and Prioritize (15 min)**
140 - Cluster similar failure modes
141 - Vote on most likely or most impactful
142 - Identify top 5-10 failure scenarios
143
1445. **Convert to Risks (10 min)**
145 - Reframe failures as current risks
146 - Add to risk register
147 - Assign initial owners
148
149**Output:** List of identified risks from team's collective wisdom.
150
151## Quick Reference
152
153| Action | Command/Trigger |
154|--------|-----------------|
155| Assess risks | "assess risks for [project]" |
156| Pre-mortem | "run pre-mortem for [project]" |
157| Risk register | "create risk register" |
158| Update risks | "update risk status" |
159| Top risks | "what are the top risks" |
160| Mitigation plan | "create mitigation plan for [risk]" |
161| Contingency plan | "plan contingency for [risk]" |
162| Risk report | "generate risk report" |
163
164## Best Practices
165
166- **Make it safe**: Encourage honest risk identification; reward raising concerns early
167- **Think like a pessimist**: When identifying risks, assume Murphy's Law (what can go wrong, will)
168- **Quantify when possible**: Use data and metrics, not just gut feel, for probability and impact
169- **Focus on top risks**: Can't mitigate everything; focus on highest-priority risks
170- **Own every risk**: Each risk needs a named owner who monitors and drives mitigation
171- **Plan before crisis**: Contingency plans made in calm are better than in panic
172- **Review regularly**: Risks evolve; weekly review keeps register current and actionable
173- **Learn from history**: Past project failures are excellent teachers for future risk identification
174- **Update probability as you learn**: As project progresses, adjust probabilities based on new information
175- **Don't ignore uncomfortable truths**: The risks you avoid discussing are often the most dangerous
176- **Communicate transparently**: Share top risks with stakeholders; surprises destroy trust
177- **Balance paranoia and progress**: Risk management shouldn't paralyze; it should inform action
178
179## Risk Categories Checklist
180
181### Technical Risks
182- [ ] Unproven or new technology
183- [ ] Performance or scalability concerns
184- [ ] Security vulnerabilities
185- [ ] Integration complexity
186- [ ] Technical debt burden
187- [ ] Infrastructure reliability
188- [ ] Data migration challenges
189
190### Schedule Risks
191- [ ] Aggressive or unrealistic timeline
192- [ ] Dependencies on other teams/projects
193- [ ] Key milestones misaligned
194- [ ] Underestimated complexity
195- [ ] Holiday or vacation conflicts
196- [ ] External deadline pressure
197
198### Resource Risks
199- [ ] Insufficient team capacity
200- [ ] Key person dependencies (bus factor)
201- [ ] Skill gaps or training needs
202- [ ] Budget constraints
203- [ ] Competing priorities
204- [ ] Attrition or turnover
205
206### External Risks
207- [ ] Vendor reliability or changes
208- [ ] Regulatory or compliance changes
209- [ ] Market condition shifts
210- [ ] Competitor actions
211- [ ] Customer demand uncertainty
212- [ ] Third-party API stability
213
214### Quality Risks
215- [ ] Inadequate testing coverage
216- [ ] Complex or unclear requirements
217- [ ] Poor code quality or architecture
218- [ ] User experience concerns
219- [ ] Accessibility or compliance gaps
220- [ ] Browser/device compatibility
221
222### Organizational Risks
223- [ ] Stakeholder misalignment
224- [ ] Unclear decision-making authority
225- [ ] Changing priorities mid-project
226- [ ] Political or organizational dynamics
227- [ ] Communication breakdowns
228- [ ] Cross-team coordination challenges
229
230## Risk Matrix
231
232```
233 IMPACT
234 Low (1) Med (2) High (3)
235PROBABILITY
236High (3) 3 (H) 6 (H) 9 (C)
237Med (2) 2 (M) 4 (H) 6 (H)
238Low (1) 1 (L) 2 (M) 3 (H)
239
240C = Critical (7-9): Immediate action required
241H = High (4-6): Develop mitigation plan
242M = Medium (2-3): Monitor regularly
243L = Low (1): Track in register
244```
245
246## Mitigation Strategy Decision Tree
247
248```
249Can we eliminate this risk entirely?
250 YES → AVOID strategy (change approach)
251 NO ↓
252
253Can we significantly reduce probability or impact?
254 YES → MITIGATE strategy (take action)
255 NO ↓
256
257Can someone else manage this better?
258 YES → TRANSFER strategy (outsource, insure)
259 NO ↓
260
261ACCEPT strategy (plan contingency)
262```
263
264## Risk Register Template
265
266```markdown
267## Risk Register - [Project Name]
268
269Last Updated: [Date]
270
271### Critical Risks (Score 7-9)
272
273#### R-001: [Risk Title]
274- **Description**: [What is the risk?]
275- **Category**: Technical | Schedule | Resource | External | Quality | Organizational
276- **Probability**: High (3) | Medium (2) | Low (1)
277- **Impact**: High (3) | Medium (2) | Low (1)
278- **Risk Score**: [P × I]
279- **Trigger**: [What causes this?]
280- **Owner**: [Name]
281- **Status**: Active | Monitoring | Closed
282- **Mitigation Strategy**: Avoid | Mitigate | Transfer | Accept
283- **Mitigation Actions**:
284 - [ ] Action 1 - Owner - Due Date
285 - [ ] Action 2 - Owner - Due Date
286- **Contingency Plan**: If risk occurs, we will...
287- **Early Warning Indicators**: [What to watch for]
288- **Last Reviewed**: [Date]
289
290### High Risks (Score 4-6)
291[Same format as above]
292
293### Medium Risks (Score 2-3)
294[Same format as above]
295```
296
297## Common Project Risks & Mitigations
298
299### Risk: Key Developer Leaves Mid-Project
300- **Mitigation**: Pair programming, documentation, knowledge sharing
301- **Contingency**: Contractor backup, timeline extension
302- **Indicator**: Team member disengagement, job searching signals
303
304### Risk: Requirements Change Significantly
305- **Mitigation**: Agile approach, frequent stakeholder check-ins, MVP focus
306- **Contingency**: Scope negotiation, timeline adjustment
307- **Indicator**: Stakeholder dissatisfaction, market feedback
308
309### Risk: Third-Party API Becomes Unreliable
310- **Mitigation**: Implement caching, retry logic, circuit breakers
311- **Contingency**: Alternative vendor, build in-house
312- **Indicator**: Increased error rates, latency spikes
313
314### Risk: Performance Doesn't Meet Requirements
315- **Mitigation**: Early performance testing, architecture review
316- **Contingency**: Optimization sprint, infrastructure scaling
317- **Indicator**: Load test failures, user complaints
318
319### Risk: Security Vulnerability Discovered
320- **Mitigation**: Security reviews, penetration testing, dependency scanning
321- **Contingency**: Incident response plan, rollback procedure
322- **Indicator**: Security alerts, CVE notifications
323
324### Risk: Project Runs Over Budget
325- **Mitigation**: Accurate estimation, buffer allocation, cost tracking
326- **Contingency**: Scope reduction, additional funding request
327- **Indicator**: Burn rate exceeds projections
328
329## Integration Points
330
331- **Project Planner**: Identifies risks during planning phase
332- **Sprint Planner**: Reviews risks at sprint planning
333- **Task Manager**: Tracks mitigation action items
334- **Retrospective Facilitator**: Captures risk learnings
335- **Stakeholder Communication**: Reports risk status
336- **Incident Management**: Triggers contingency plans