| name | planning-risk-assessment |
| description | Risk assessment: likelihood/impact, mitigations, residual risk |
Identify risks, assess them, and define concrete mitigations
Change description + impact areas (if available)
Critical business processes and SLA
Release/window/process constraints
<risk_categories>
data
security
performance
reliability
ops
business
</risk_categories>
Create a list of risks tied to specific planned changes
Assess likelihood and impact (qualitative: low/medium/high)
For each high-impact risk, add a mitigation (test/flag/staged rollout/scope reduction/monitoring)
Define residual risk and the decision (accept/reduce/avoid)
<output_format>
Residual risks / decisions
<quality_rules>
Risks are not generic; they are tied to planned changes
High-impact risks have concrete mitigation actions
</quality_rules>