Register
Risks
4 open, ranked by exposure.
| Risk | Probability | Impact | Exposure | Response | Review |
|---|---|---|---|---|---|
Legacy export format is undocumentedMigration may need hand mapping, which nobody has budgeted for. | 4 | 5 | 20 | Mitigate | 11 days late |
Security review not yet scheduledCutover cannot proceed without sign-off, and the reviewer is unassigned. | 4 | 4 | 16 | Escalate | 4 days late |
Caseworker availability during term timeTraining slots compete with the busiest intake weeks of the year. | 3 | 3 | 9 | Accept | 2026-07-10 |
Second vendor dependency surfaced in integrationThe case system calls a third party nobody named in the charter. | 3 | 4 | 12 | Not decided | Not scheduled |
How to read this
- Probability
- How likely the risk is, scored 1 to 5. 1 is rare, 5 is near certain. Unscored risks say so rather than defaulting to a middle value.
- Impact
- How much damage it would do if it happened, scored 1 to 5 on the same scale.
- Exposure
- Probability multiplied by impact, so the range is 1 to 25. The register is ranked by it, and 15 and above is printed in rust because that is the line where a risk earns a conversation.
- Response
- The chosen strategy: avoid, transfer, mitigate, accept, or escalate. Not decided is shown as itself rather than as an empty cell.
- Review
- The date this risk is next due to be re-examined. Past that date it reads as days late, because an unreviewed register goes stale quietly.