| name | arckit-risk |
| description | Create comprehensive risk register following HM Treasury Orange Book principles |
You are helping an enterprise architect create a comprehensive risk register following the UK Government Orange Book (2023) risk management framework.
About Orange Book Risk Management
The Orange Book is HM Treasury's guidance on risk management in government. The 2023 update provides:
- Part I: 5 Risk Management Principles (Governance, Integration, Collaboration, Risk Processes, Continual Improvement)
- Part II: Risk Control Framework (4-pillar "house" structure)
- 4Ts Risk Response Framework: Tolerate, Treat, Transfer, Terminate
- Risk Assessment Methodology: Likelihood × Impact for Inherent and Residual risk
- Risk Appetite: Amount of risk organization is prepared to accept/tolerate
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
This command creates a comprehensive risk register following HM Treasury Orange Book principles and integrates with ArcKit's stakeholder-driven workflow.
When to use this:
- After:
/skill:arckit-stakeholders (MANDATORY - every risk needs an owner)
- Before:
/skill:arckit-sobc (SOBC Management Case Part E uses risk register)
- Purpose: Identify, assess, and manage project risks using Orange Book methodology
-
Read existing artifacts from the project context:
MANDATORY (warn if missing):
- STKE (Stakeholder Analysis) — Extract: risk owners from RACI matrix, affected stakeholders, conflict analysis (conflicts ARE risks), stakeholder drivers (drivers under threat = strategic risks)
- If missing: STOP and warn user to run
/skill:arckit-stakeholders first — every risk MUST have an owner
RECOMMENDED (read if available, note if missing):
- PRIN (Architecture Principles, in 000-global) — Extract: technology standards, compliance requirements — non-compliance creates risks
projects/000-global/risk-appetite.md — Extract: risk appetite thresholds for assessment calibration
- REQ (Requirements) — Extract: complex requirements that create risks, NFRs that mitigate risks
OPTIONAL (read if available, skip silently):
- SOBC (Business Case) — Extract: financial risks, ROI assumptions at risk
- DPIA (Data Protection Impact Assessment) — Extract: data protection risks, privacy risks
-
Understand the request: The user may be:
- Creating initial risk register (most common)
- Updating existing risk register with new risks
- Reassessing risks after changes
- Creating organizational risk appetite (advanced - if user asks for this specifically)
-
Read external documents and policies:
- Read any global policies listed in the project context (
000-global/policies/) — extract risk appetite, risk tolerance thresholds, threat landscape, industry benchmarks
- Read any external documents listed in the project context (
external/ files) — extract previous risk findings, mitigation effectiveness, residual risks, lessons learned
- Read any enterprise standards in
projects/000-global/external/ — extract enterprise risk frameworks, threat intelligence reports
- If no external risk docs exist but they would improve the assessment, ask: "Do you have a risk appetite statement, previous risk assessments, or external threat reports? I can read PDFs directly. Place them in
projects/000-global/policies/ and re-run, or skip."
Identify risks that require immediate action:
- Critical risks (score 20-25): Escalate to steering committee immediately
- Risks exceeding appetite: Escalate to risk owner + approval authority
- Increasing risk trends: Risks getting worse over time
- Unmitigated high risks: High risks with no treatment plan
-
Write the output:
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks plus the RISK per-type checks pass. Fix any failures before proceeding.
- Create or update
projects/NNN-project-name/ARC-{PROJECT_ID}-RISK-v1.0.md
- Use project directory structure (create if doesn't exist)
- File name pattern:
ARC-{PROJECT_ID}-RISK-v{VERSION}.md
- Update date and version in header
IMPORTANT - Auto-Populate Document Information Fields:
Before completing the document, populate document information fields:
Auto-populated fields
[PROJECT_ID] → Extract from project path (e.g., "001")
[VERSION] → Start with "1.0" for new documents
[DATE] / [YYYY-MM-DD] → Current date in YYYY-MM-DD format
[DOCUMENT_TYPE_NAME] → Document purpose
ARC-[PROJECT_ID]-RISK-v[VERSION] → Generated document ID
[STATUS] → "DRAFT" for new documents
- Classification → comes from the resolved Document Control header, not from a placeholder.
_partials/RENDERING.md fixes the ladder from the artefact's own regime; ${default_classification} applies only where that regime falls through to user config.
User-provided fields
[PROJECT_NAME] → Full project name
[OWNER_NAME_AND_ROLE] → Document owner
Revision History
| 1.0 | {DATE} | ArcKit AI | Initial creation from `/skill:arckit-risk` command |
Generation Metadata Footer
**Generated by**: ArcKit `/skill:arckit-risk` command
**Generated on**: {DATE}
**ArcKit Version**: {ARCKIT_VERSION}
**Project**: {PROJECT_NAME} (Project {PROJECT_ID})
**AI Model**: [Actual model name]
Output Format
Provide:
- Location:
projects/NNN-project-name/ARC-{PROJECT_ID}-RISK-v1.0.md
- Summary:
- "Created comprehensive risk register following HM Treasury Orange Book"
- "Identified [X] risks across 6 categories"
- "Risk profile: [X] Critical, [Y] High, [Z] Medium, [W] Low"
- "Overall residual risk score: [X]/500 ([Y]% reduction from inherent)"
- "All [X] risks have owners from stakeholder RACI matrix"
- "[N] risks require immediate escalation (exceed appetite or critical)"
- Top 3 Risks:
- "1. R-001 (STRATEGIC, Critical 20): [Title] - Owner: [Name]"
- "2. R-002 (TECHNOLOGY, High 16): [Title] - Owner: [Name]"
- "3. R-003 (FINANCIAL, High 15): [Title] - Owner: [Name]"
- 4Ts Distribution:
- "Tolerate: X% | Treat: Y% | Transfer: Z% | Terminate: W%"
- Next steps:
- "Review with [Risk Owners] to validate assessment"
- "Escalate [N] critical/high risks to Steering Committee"
- "Use risk register for SOBC Management Case Part E"
- "Implement priority actions from Action Plan"
- "Schedule monthly risk review meeting"
Orange Book Compliance Checklist
Ensure the risk register demonstrates Orange Book compliance:
- ✅ Governance and Leadership: Risk owners assigned from senior stakeholders
- ✅ Integration: Risks linked to objectives, stakeholders, and business case
- ✅ Collaboration: Risks sourced from stakeholder concerns and expert judgment
- ✅ Risk Processes: Systematic identification, assessment, response, monitoring
- ✅ Continual Improvement: Review framework and action plan for ongoing management
Common Risk Patterns
Pattern 1: Technology Modernization:
- TECHNOLOGY: Legacy system failure during migration (High)
- OPERATIONAL: Skills gap in new technology (Medium)
- FINANCIAL: Cloud costs exceed estimates (Medium)
- REPUTATIONAL: Service outage during cutover (High)
Pattern 2: New Digital Service:
- STRATEGIC: User adoption below target (High)
- TECHNOLOGY: Scalability limitations at peak (High)
- COMPLIANCE: GDPR/Accessibility non-compliance (Critical)
- OPERATIONAL: Support team not ready for go-live (Medium)
Pattern 3: Vendor Procurement:
- FINANCIAL: Vendor pricing increases post-contract (Medium)
- OPERATIONAL: Vendor delivery delays (Medium)
- TECHNOLOGY: Vendor lock-in limits future options (High)
- REPUTATIONAL: Vendor security breach affects reputation (High)
UK Government Specific Risks
For UK Government/public sector projects, include:
STRATEGIC:
- Policy/ministerial direction change mid-project
- Manifesto commitment not delivered
- Machinery of government changes
COMPLIANCE/REGULATORY:
- Spending controls (HMT approval delays)
- NAO audit findings
- PAC scrutiny and recommendations
- FOI requests reveal sensitive information
- Judicial review of procurement
REPUTATIONAL:
- Parliamentary questions and media scrutiny
- Citizen complaints and service failures
- Social media backlash
- Select Committee inquiry
OPERATIONAL:
- GDS Service Assessment failure
- CDDO digital spend control rejection
- Civil service headcount restrictions
- Security clearance delays
Error Handling
If stakeholder analysis doesn't exist:
- DO NOT proceed with risk register
- Tell user: "Risk register requires stakeholder analysis to identify risk owners and affected parties. Please run
/skill:arckit-stakeholders first."
If risks are very high/critical:
- Flag explicitly: "⚠️ WARNING: [N] Critical risks (score 20-25) identified. Immediate escalation required. Consider if project should proceed."
If all risks exceed appetite:
- Flag: "⚠️ WARNING: Project risk profile significantly exceeds organizational appetite. Senior approval required to proceed."
Template Reference
Use the template at .arckit/templates/risk-register-template.md as the structure. Fill in with:
- Stakeholder analysis data (owners, affected parties, concerns)
- Architecture principles (non-compliance risks)
- Organizational risk appetite (if exists)
- User's project description
- Industry/sector specific risks
- UK Government risks (if applicable)
Generate a comprehensive, Orange Book-compliant risk register that enables informed decision-making and effective risk management.
Important Notes
- Markdown escaping: When writing less-than or greater-than comparisons, always include a space after
< or > (e.g., < 3 seconds, > 99.9% uptime) to prevent markdown renderers from interpreting them as HTML tags or emoji
Suggested Next Steps
After completing this command, consider running:
/skill:arckit-sobc -- Feed risk register into SOBC Management Case
/skill:arckit-requirements -- Create risk-driven requirements
/skill:arckit-secure -- Validate security controls against risks
/skill:arckit-tenders -- Ground supplier-concentration risk in real UK procurement award data (when UK government procurement context)