3.7 Risk management
A risk is an uncertain event that could affect scope, quality, schedule, confidentiality, or usefulness. A problem that has already occurred is an issue, not a risk. Both should be tracked, but they require different language.
A risk register should include:
- a concise description of the risk;
- its possible cause and consequence;
- an assessment of likelihood and impact;
- warning signs or trigger conditions;
- a prevention or mitigation action;
- a contingency response if it occurs; and
- an owner responsible for monitoring it.
Common risk categories include data access, data quality, scope growth, weak model performance, missing context, team availability, incompatible software, confidentiality constraints, and insufficient time for integration.
Worked Example: Planning for a Geographic-Matching Risk
Risk: Geographic categories in the client data may not match the available population projections.
Mitigation: Compare identifiers and boundary definitions during the first week of data review.
Contingency: Aggregate both sources to the smallest geography that can be matched defensibly and explain the loss of detail.
Trigger: More than 5 percent of client records remain unmatched after standardized identifiers are applied.