Risk register
Names, ranks and assigns the risks to a plan. Becomes bureaucracy when it lists everything, and becomes useful when it lists five things with triggers and owners.
The printable canvas and the handoff into Claude Code are part of a paid plan. See what a plan includes. It needs the Claude desktop app on this machine, and your team and the prompt library already installed in that project — we cannot see your disk, so open it there.
What it is
A structured list of what could go wrong with a plan, scored and assigned. Its usefulness is inversely proportional to its length: a short register with owners and triggers changes behaviour, and a long one records that a process was followed.
- The risk
- A specific event that would damage the plan, stated as something that could happen rather than as a general concern.
- Likelihood and impact
- Scored separately. The combination determines ranking, but keeping them apart preserves the distinction between frequent nuisances and rare catastrophes.
- Mitigation
- What reduces likelihood or impact, and what it costs. Reserved for the top few — everything else is accepted.
- Trigger
- The observable signal that this is happening now. Without one, mitigation begins after the event.
- Owner
- A named person with the authority to act, not the person who raised it.
- Accepted risks
- What you are deliberately not mitigating. Recording this is as valuable as the mitigation plan and is almost never done.
How you run it
- Identify risks against the actual planGeneric sector risks belong in a different document. What could go wrong with these moves, in this business, this year?
- Score likelihood and impact separatelyThen rank. Scoring on a combined gut feel loses the distinction between likely-and-survivable and unlikely-and-fatal.
- Mitigate only the top fewA register with forty entries and forty mitigations is a document nobody reads. Take the top five seriously and record the rest as accepted.
- Give each a trigger, not just a mitigationThe observable event that says this risk is materialising. Without a trigger, mitigations activate after the damage.
- Name an owner who can actSomeone with the authority to pull the trigger, not the person who happened to raise it.
The prompt
Run this tool in your own Claude
The short prompt starts your partner against the library on your disk. The long one carries everything with it and needs nothing installed.
Your playbook
It lands in the earliest stage this tool suits. Move it on the Playbook page.
You’ll need
- An agreed plan with defined moves
- People from delivery, not just governance
- Someone with authority to accept risk explicitly
You’ll end up with
- Risks scored by likelihood and impact
- Mitigation, owner and trigger for the top few
- An explicit list of risks being accepted