| name | risk-management |
| description | Identify, assess, and mitigate risks to ensure project and organizational success |
Risk Management
Purpose
Identify, assess, and mitigate risks proactively to ensure project and organizational success while minimizing negative impacts and maximizing opportunities.
Capabilities
🎯 Tier 1: Foundation
Risk Management Fundamentals
Implement basic risk management practices:
- Risk Identification: Identify potential risks to projects and initiatives
- Risk Assessment: Assess likelihood and impact of identified risks
- Risk Register: Create and maintain a risk register
- Mitigation Planning: Develop plans to mitigate or accept risks
- Risk Monitoring: Monitor risks and trigger mitigation when needed
- Contingency Planning: Create contingency plans for high-impact risks
Example:
"I'm managing a critical project and need to manage risks effectively. Help me:
1. Identify potential risks to project success
2. Assess likelihood and impact of each risk
3. Create a risk register with all identified risks
4. Develop mitigation plans for high-priority risks
5. Monitor risks and trigger mitigation when needed"
🚀 Tier 2: Advanced
Comprehensive Risk Framework
Implement comprehensive risk management across the organization:
- Risk Categories: Classify risks by type (technical, operational, financial, strategic)
- Risk Quantification: Quantify risks in business terms (financial, schedule, impact)
- Risk Culture: Build a culture of risk awareness and proactive management
- Risk Reviews: Conduct regular risk review meetings with stakeholders
- Risk Appetite: Define and communicate risk appetite and tolerance
- Risk Reporting: Create risk reports for leadership and stakeholders
- Lessons Learned: Learn from risks that materialized and improve processes
- Risk Tools: Implement tools and templates for risk management
Example:
"I'm building a risk management framework for my department. Help me:
1. Categorize risks by type and impact area
2. Quantify risks in financial and schedule terms
3. Build a culture of risk awareness across the team
4. Conduct quarterly risk reviews with stakeholders
5. Define risk appetite and tolerance for different types of risks
6. Create executive risk reports
7. Learn from past risks and improve processes
8. Implement risk management tools and templates"
🌟 Tier 3: Anticipatory
Strategic Risk Leadership
Drive organizational risk strategy and resilience:
- Enterprise Risk Management: Implement ERM frameworks across the organization
- Strategic Risk Management: Identify and mitigate strategic risks to the business
- Compliance & Regulatory: Ensure compliance with regulations and standards
- Crisis Management: Lead crisis response and recovery
- Risk Governance: Establish risk governance structures and oversight
- Risk Intelligence: Use data and analytics to predict emerging risks
- Resilience Building: Build organizational resilience to withstand shocks
- Board Reporting: Report risks to board and governing bodies
Example:
"I'm leading risk management for our organization. Help me:
1. Implement an enterprise risk management (ERM) framework
2. Identify and mitigate strategic risks to the business
3. Ensure compliance with all relevant regulations and standards
4. Develop crisis management and business continuity plans
5. Establish risk governance and oversight structures
6. Use predictive analytics to identify emerging risks
7. Build organizational resilience to withstand major shocks
8. Report risks to the board and governing bodies"
Integration
Works Best With:
strategic-planning: Incorporate risks into strategic planning
project-status: Report risks in project status updates
stakeholder-communication: Communicate risks to stakeholders
budget-management: Factor financial risks into budget planning
Manager Pack Skills:
team-management ← Address team-related risks
resource-allocation ← Allocate resources to mitigate risks
performance-review ← Address performance-related risks
strategic-planning ← Incorporate risks
stakeholder-communication ← Communicate risks
risk-management ← You are here
budget-management ← Plan for financial risks
Best Practices
✅ DO:
- Be proactive: Identify risks early, before they materialize
- Involve the team: Gather risk perspectives from all team members
- Be realistic: Don't underestimate likelihood or impact
- Prioritize: Focus on high-impact, high-likelihood risks
- Plan contingencies: Have backup plans for critical risks
- Monitor continuously: Risks change over time, keep watching
- Document everything: Maintain a comprehensive risk register
- Learn from experience: Improve processes based on lessons learned
❌ DON'T:
- Ignore risks: Hope is not a risk management strategy
- Over-optimism bias: Don't assume things will go well
- React only when it's too late: Proactive management is better than reactive
- Neglect low-probability risks: High-impact, low-probability risks still matter
- Keep risks secret: Transparency helps the whole team manage risks
- Forget to monitor: Risk status changes, review regularly
- Ignore positive risks (opportunities): Risks can be opportunities too
- Blame: Focus on learning, not assigning fault
Common Mistakes
- Not identifying risks early: Waiting until risks materialize to address them
- Underestimating impact: Optimism bias leads to inadequate mitigation
- Ignoring low-probability risks: High-impact, low-probability risks still need attention
- Poor risk communication: Not sharing risks with team and stakeholders
- No contingency planning: Having no backup plans for critical risks
- Reactive instead of proactive: Only addressing risks after they occur
- Not monitoring risk status: Risks change over time and need regular review
- Failing to learn: Repeating mistakes from past risks
Quick Commands
Get Started:
- "Help me identify risks for my project"
- "Assess the likelihood and impact of identified risks"
- "Create a risk register for my team"
- "Develop mitigation plans for high-priority risks"
Advanced:
- "Categorize risks by type and impact area"
- "Quantify risks in financial terms"
- "Build a culture of risk awareness across the team"
- "Conduct a risk review meeting with stakeholders"
- "Create executive risk reports"
Expert:
- "Implement an enterprise risk management (ERM) framework"
- "Identify and mitigate strategic risks to the business"
- "Develop crisis management and business continuity plans"
- "Use predictive analytics to identify emerging risks"
- "Report risks to the board and governing bodies"
Example Workflows
Workflow 1: Managing Project Risks
- Brainstorm potential risks with team
- Identify risks from past similar projects
- Assess likelihood and impact of each risk
- Prioritize risks based on risk score (likelihood × impact)
- Create risk register with all identified risks
- Develop mitigation plans for high-priority risks
- Assign risk owners and timelines for mitigation
- Monitor risk status regularly
- Trigger contingency plans when needed
- Update risk register and learn from outcomes
Workflow 2: Quarterly Risk Review
- Review current risk register and status
- Identify new risks that have emerged
- Assess status of existing risks (mitigated, ongoing, materialized)
- Review effectiveness of mitigation efforts
- Update risk scores based on new information
- Identify new high-priority risks requiring action
- Update risk register and communicate to stakeholders
- Plan risk activities for next quarter
- Document lessons learned from materialized risks
Workflow 3: Crisis Risk Management
- Identify that a critical risk has materialized
- Activate crisis response team and communication
- Execute contingency plan for the specific risk
- Monitor situation and adjust response as needed
- Communicate with stakeholders (team, leadership, affected parties)
- Implement mitigation to prevent recurrence
- Conduct post-crisis review and lessons learned
- Update risk register and processes based on lessons
- Build resilience to prevent similar future crises
Success Criteria
✅ Tier 1 Success: Risks are identified, risk register is maintained, mitigation plans exist, monitoring is regular
✅ Tier 2 Success: Risk culture is strong, risk reviews are conducted, risks are quantified, reporting is effective
✅ Tier 3 Success: ERM framework is implemented, strategic risks are managed, resilience is built, board oversight is established
Session Requirements
- Minimum Session: session-21
- Recommended Session: session-22 for Tier 2, session-23+ for Tier 3
- Prerequisites: Managing projects or teams with exposure to risks