Skip to main content

We are at World Summit AI, Amsterdam, this October. Meet us there

SOSX

Analysis tools / Defending the answer

Risk register

“What could go wrong, and how badly?”

The risk register in four stages: failure modes found, scored for severity, occurrence and detection, mitigated, and scored again.

A risk register is one of the most useful documents in a programme and one of the most routinely wasted. It gets written once to satisfy a gate, scored by whoever was available, and then updated by moving a few cells from amber to green before the next review.

The discipline

The FMEA tradition, which came out of aerospace and automotive for good reasons, insists on three separate judgements rather than one gut feel. How bad is it if this happens. How likely is it. And would we notice before it mattered. That third dimension is the one general-purpose risk matrices drop, and it is often the decisive one: a moderate risk you would catch immediately is a very different proposition from a moderate risk that surfaces at integration.

The other habit worth keeping is scoring twice, before and after the mitigations. A register that only shows post-mitigation scores has hidden the reason the mitigations exist.

How SOSX runs it

The register is built from the network, so the structural risks are found rather than remembered: critical dependencies, single points of failure and the paths a failure would propagate along are visible in the model before anybody writes them on a list. You can run a quick risk scan for early screening, a detailed assessment, or a mitigation planning pass, across the whole network or focused on one area.

Each risk carries severity, occurrence and detection, and the register is presented both as it stands and as it would stand once the proposed mitigations are in place.

What you get

An executive summary, the risk matrix, the register itself, and the enhanced pre and post-mitigation view, exportable to PDF or Word. Because the risks are anchored to nodes in the network, a later what-if analysis can show what a proposed change does to the risk profile, which is the version of the conversation a review board actually wants.

The others in this group

Someone will ask how you know. These are the analyses that answer them.

Or see all the analysis tools. If you would rather we built the model and ran them for you, that is our system research, build and analysis service.

Drop us a message and let's have a chat