Docs / 08-transformation/02-program/risk-register
Risk Register
Living risk register for the Prime Products AI transformation — scored, owned, mitigated; reviewed monthly at steering.
Risk Register — Prime Products AI Transformation
Living document. Reviewed at every monthly steering meeting (per governance-model.md): re-score, update mitigations, close retired risks, add new ones. Each risk has one owning role. Initial scores are pre-discovery estimates (2026-07-03) — re-baseline at M1 steering.
Scoring model: Probability (P) 1–5 (1 = <10%, 2 = 10–30%, 3 = 30–50%, 4 = 50–70%, 5 = >70%) × Impact (I) 1–5 (1 = negligible, 3 = slips a phase or costs €[TBD, minor], 5 = threatens program objectives or the company). Score = P × I. RAG: 🟢 1–6 monitor · 🟡 8–12 active mitigation, owner reports at steering · 🔴 15–25 escalation, standing steering agenda item.
Technology & infrastructure
| ID | Risk | P | I | Score | Owner | Mitigation | Contingency | Early-warning signal |
|---|---|---|---|---|---|---|---|---|
| RSK-01 | Infrastructure delays — site (power/cooling/rack) or platform build slips, pushing GA past M6 and compressing pilots | 3 | 4 | 🟡 12 | Prime Products IT | Site survey in M2 (WBS 3.6); site prep during hardware lead time (4.3); interim dev sandbox (4.4) keeps software on schedule | Re-gate GA to early M7 with 2-week remediation sprint; shorten pilots, not their measurement rigor | Site-readiness checklist items open at M4; burn-in failures |
| RSK-02 | Hardware procurement — 6–10-week GPU lead times stretch, or prices swing between BoM and PO | 4 | 4 | 🔴 16 | Prime Products IT | Order in M3 at the latest (4.2); ≥2 vendors quoted with delivery weighted heavily (4.1); price-validity window in RFQ; 10-week case already in plan | Loaner/rental GPUs or extended cloud sandbox (no business data) to hold Phase 5 schedule; descope to smaller initial config, expand later | Vendor ETA slips at weekly check-in; GPU market price alerts; budget gate slipping past M3 |
| RSK-06 | SoftOne integration difficulty — API limits, missing endpoints, or customization debt block ERP read/write use cases | 3 | 4 | 🟡 12 | TPL lead | API capability assessment in systems inventory (1.8); v1 scoped read-only (5.5); SoftOne partner engaged early; write-back deferred to year 2 | Fall back to export/file-drop integration or DB-level read replicas; re-score affected use cases in pipeline | Test-environment access (0.7) delayed; first API spike fails or hits rate limits |
| RSK-07 | Microsoft 365 integration/licensing — Graph permissions, tenant policies, or licensing tiers block SharePoint/Teams integration | 2 | 3 | 🟢 6 | Prime Products IT | Tenant/licensing review in M1 (0.7); least-privilege app registrations designed in 3.5; licensing delta priced into OpEx envelope €[TBD] | Scope RAG to Obsidian KB only until resolved; manual export bridge for critical libraries | Admin-consent requests stuck; licensing quote exceeds envelope |
| RSK-08 | Local LLM capability limits — open-weight models on our hardware underperform cloud frontier models; users who know ChatGPT are disappointed | 3 | 3 | 🟡 9 | TPL lead | Benchmark on Prime Products-realistic tasks before commitment (5.2); pick use cases within local-model competence (2.6); RAG grounding narrows the gap; expectation-setting in training (§8 of change plan) | Quarterly model-refresh cycle (12.2) adopts better open models; re-scope affected use cases; hybrid escalation path for non-confidential tasks only, as a policy decision | Eval scores below threshold in 5.2; CSAT ≤3.5 with “quality” cited; shadow use of public AI tools |
| RSK-09 | Greek-language performance — models handle Greek business/maritime prose, terminology, and inflection poorly | 3 | 4 | 🟡 12 | TPL lead | Greek-specific eval set from real Prime Products documents (5.2); shortlist models with proven Greek capability; bilingual prompt patterns in training; glossary of domain terms in KB feeding RAG | Greek-focused fine-tune or adapter €[TBD]; English-first workflows where business-acceptable; translation-assist pattern (draft EN → translate) | Greek eval materially below English on same tasks; pilot users defaulting to English against preference |
| RSK-10 | Security breach / data leak — platform breach, prompt-injection exfiltration, or confidential data leaving via misuse | 2 | 5 | 🟡 10 | Prime Products IT | Security architecture with segmentation + SSO + audit logs (3.5); hardening & pen check pre-GA (5.7); least-privilege agents with approval steps (9.1); usage policy §6 + training; on-prem design keeps data in-building by default | Incident-response runbook (security-and-operations.md): isolate platform, preserve logs, notify per GDPR 72-h rule if personal data affected; disable affected agents immediately | Audit-log anomalies; failed pen-check findings unremediated; policy-violation flags in #ai-help |
Adoption & people
| ID | Risk | P | I | Score | Owner | Mitigation | Contingency | Early-warning signal |
|---|---|---|---|---|---|---|---|---|
| RSK-03 | User adoption failure — platform ships but staff don’t use it; WAU stalls below targets | 3 | 5 | 🔴 15 | CEO | Entire change plan: CEO-led messaging, champions, hands-on training on real tasks, no-layoffs commitment, use cases chosen for felt pain (2.6) | Laggard-department action plans (11.7): re-training, use-case redesign with the department, champion swap; in extremis re-scope M12 targets with board transparency | WAU plateau 4+ weeks; queries/user/day falling; pulse-survey usefulness score <3; labs with no follow-on usage |
| RSK-04 | Poor documentation habits — departments don’t write/maintain KB content; RAG starves, freshness rots | 4 | 3 | 🟡 12 | dept champion (guild) | Champion-run content sprints with TPL support (6.5); templates lower the writing bar (6.2); KB health metrics public on Mission Control (6.6); AI-assisted drafting of SOPs from interviews | TPL-led documentation surge for critical corpora €[TBD, scoped]; narrow RAG promise to well-covered domains | SOP coverage flat between steering reviews; orphan/freshness metrics degrading; sprint attendance dropping |
| RSK-11 | Change fatigue — 12 months of program touchpoints exhausts goodwill; participation becomes performative | 3 | 3 | 🟡 9 | TPL lead | Load caps (≤4 h/person/month, change plan §13); wave sequencing avoids seasonal peaks; comms are few and honest; visible “you said → we did” loop closures | Insert a deliberate quiet month (no new asks) for affected departments; compress wave scope rather than pile on | Pulse-survey sentiment declining 2 months running; training no-shows; guild attendance <60% |
| RSK-12 | Lack of ownership in departments — heads treat the program as TPL’s/IT’s project; champions left unsupported | 3 | 4 | 🟡 12 | CEO | Dept heads own their adoption KPI (heatmap, KPI §4); use-case design workshops make heads authors, not recipients (10.4 table); champion time formally allocated; CEO reviews heatmap at all-hands | CEO 1:1 with lagging head; re-assign champion; move department later in wave order rather than drag | Head skips briefings/workshops; champion reports no allocated time; dept one-pager review unanswered |
| RSK-17 | Key-person dependency — single champion, IT platform owner, or TPL individual becomes a bottleneck; departure stalls a workstream | 3 | 3 | 🟡 9 | steering | Runbooks + handover as standing deliverables (10.5, 12.4); ≥2 IT staff trained on ops; guild spreads champion knowledge; all program knowledge in this vault, not in heads | Backfill from guild/TPL bench; pause affected workstream one wave rather than improvise | Single-owner workstreams visible in WBS reviews; vacation/absence causing missed deliverables |
| RSK-19 | Sponsor attention drift — CEO bandwidth consumed by operations; program loses its face and its decision speed | 2 | 4 | 🟡 8 | steering | CEO commitments are few and scheduled 12 months ahead (kickoff, monthly segment, gate decisions); deputy sponsor named in governance model | Deputy sponsor fronts the segment short-term; TPL lead escalates pattern to board | CEO misses 2 consecutive all-hands segments or a gate decision slips awaiting sponsor |
Program & commercial
| ID | Risk | P | I | Score | Owner | Mitigation | Contingency | Early-warning signal |
|---|---|---|---|---|---|---|---|---|
| RSK-05 | SoftOne data quality — item/customer/pricing master data too dirty for reliable AI answers and automations | 4 | 4 | 🔴 16 | TPL lead | Data-quality sampling in discovery (1.9); use-case scoring includes data-readiness (2.6); RAG answers cite sources so users can verify; cleansing tasks attached to affected use cases | Scoped master-data cleanup effort €[TBD] before dependent automations ship; human-in-the-loop step retained on affected agents | Sampling error rates above threshold in 1.9; pilot users reporting wrong prices/items; agent override rate >25% on ERP-fed tasks |
| RSK-13 | Scope creep — enthusiasm (or discovery findings) balloons the use-case list; program becomes 20 half-built things | 4 | 3 | 🟡 12 | steering | Scored pipeline with explicit quick-win/pilot/later gates (2.6); charter out-of-scope list; every addition displaces something at steering — no silent additions; year-2 roadmap (12.5) as the pressure valve | Formal descope decision at M8 gate: cut wave-2 automations before cutting rollout/training | WBS items added without steering minutes; TPL utilization over plan; deliverables slipping while new work starts |
| RSK-14 | Budget overrun — hardware, licensing, or effort exceeds envelope €[TBD] | 3 | 4 | 🟡 12 | steering | Budget envelope with contingency reserve set in 0.4; BoM options at price points (3.3); monthly spend-vs-budget in board pack; mid-program budget review at M8 | Draw contingency; descope per RSK-13 contingency; defer wave-2 automations or capacity expansion to year 2 | Spend tracking >10% over profile at any monthly review; PO exceeds BoM estimate; licensing quotes above envelope |
| RSK-15 | Vendor dependency — over-reliance on TPL (knowledge), hardware vendor (support), or SoftOne partner (integration access) | 3 | 3 | 🟡 9 | steering | Handover is a phase, not an afterthought (12.2–12.4); everything documented in-vault; hardware support contract with defined SLA; SoftOne partner scope contracted early | Second-source support contract €[TBD]; TPL advisory retainer sized for genuine step-back, not disguised dependence | IT can’t resolve incidents without TPL past M9; runbooks failing dry-run tests; SoftOne partner unresponsive >2 weeks |
| RSK-16 | Operational disruption during rollout — program load or process changes degrade daily ship-supply operations | 2 | 5 | 🟡 10 | CEO | Minimal-disruption rules (change plan §13): load caps, parallel-run principle, no big-bang cutovers, peak-season avoidance, 2-week deferral mechanism | Invoke deferral, roll department back to pre-AI process (always kept available during hypercare); post-incident review before resuming | Deferral requests being used; order-to-delivery or error-rate KPIs regressing in an onboarding department; overtime spiking during a wave |
| RSK-18 | Regulatory / GDPR non-compliance — employee/customer personal data processed by the platform without proper basis, retention, or transparency | 2 | 5 | 🟡 10 | Compliance head | DPIA for the platform before GA (with 5.7); data-category rules in usage policy §6; audit logging + retention policy in security design (3.5); HR data excluded from RAG corpora by default | Suspend affected corpora/agents; remediate with DPO/counsel; regulator notification per 72-h rule if breach | DPIA findings open at GA gate; personal data found in RAG index sampling; works-council/employee complaints |
| RSK-20 | Pilot value shortfall — pilots run but measured KPI deltas are marginal; M8 gate lacks a convincing case | 2 | 4 | 🟡 8 | TPL lead | Pilot use cases chosen for measurable, felt pain (2.6, 8.1); baselines captured properly in 1.12; weekly pilot reviews catch drift early (8.6) | Extend pilots 4 weeks with redesigned use cases before the rollout decision; swap in next-ranked use case from pipeline; report honestly — a weak pilot killed early is cheaper than a weak rollout | Week-4 pilot metrics flat vs baseline; pilot users reverting to old process after novelty; CSAT fine but time-saved ≈0 |
Register operations
- Add a risk: next RSK-NN, one owning role, scored, with all columns filled — in the same change as the steering minutes that raised it.
- Close a risk: strike through the row with closure date and reason; never delete (audit trail).
- Escalation: any 🔴 risk, or any risk whose score rises two reviews running, goes on the steering agenda automatically; 🔴 risks also appear in the board pack.
- Top risks and their trend are displayed (sanitized) on the Mission Control program-status page.