PRIME PRODUCTS · MISSION CONTROL
AI-first transformation · by TPL · vanos.tpl.one

Docs / 08-transformation/02-program/risk-register

Risk Register

Living risk register for the Prime Products AI transformation — scored, owned, mitigated; reviewed monthly at steering.

type: register updated: 2026-07-03 owner: kotsalidis

Risk Register — Prime Products AI Transformation

Living document. Reviewed at every monthly steering meeting (per governance-model.md): re-score, update mitigations, close retired risks, add new ones. Each risk has one owning role. Initial scores are pre-discovery estimates (2026-07-03) — re-baseline at M1 steering.

Scoring model: Probability (P) 1–5 (1 = <10%, 2 = 10–30%, 3 = 30–50%, 4 = 50–70%, 5 = >70%) × Impact (I) 1–5 (1 = negligible, 3 = slips a phase or costs €[TBD, minor], 5 = threatens program objectives or the company). Score = P × I. RAG: 🟢 1–6 monitor · 🟡 8–12 active mitigation, owner reports at steering · 🔴 15–25 escalation, standing steering agenda item.

Technology & infrastructure

IDRiskPIScoreOwnerMitigationContingencyEarly-warning signal
RSK-01Infrastructure delays — site (power/cooling/rack) or platform build slips, pushing GA past M6 and compressing pilots34🟡 12Prime Products ITSite survey in M2 (WBS 3.6); site prep during hardware lead time (4.3); interim dev sandbox (4.4) keeps software on scheduleRe-gate GA to early M7 with 2-week remediation sprint; shorten pilots, not their measurement rigorSite-readiness checklist items open at M4; burn-in failures
RSK-02Hardware procurement — 6–10-week GPU lead times stretch, or prices swing between BoM and PO44🔴 16Prime Products ITOrder in M3 at the latest (4.2); ≥2 vendors quoted with delivery weighted heavily (4.1); price-validity window in RFQ; 10-week case already in planLoaner/rental GPUs or extended cloud sandbox (no business data) to hold Phase 5 schedule; descope to smaller initial config, expand laterVendor ETA slips at weekly check-in; GPU market price alerts; budget gate slipping past M3
RSK-06SoftOne integration difficulty — API limits, missing endpoints, or customization debt block ERP read/write use cases34🟡 12TPL leadAPI capability assessment in systems inventory (1.8); v1 scoped read-only (5.5); SoftOne partner engaged early; write-back deferred to year 2Fall back to export/file-drop integration or DB-level read replicas; re-score affected use cases in pipelineTest-environment access (0.7) delayed; first API spike fails or hits rate limits
RSK-07Microsoft 365 integration/licensing — Graph permissions, tenant policies, or licensing tiers block SharePoint/Teams integration23🟢 6Prime Products ITTenant/licensing review in M1 (0.7); least-privilege app registrations designed in 3.5; licensing delta priced into OpEx envelope €[TBD]Scope RAG to Obsidian KB only until resolved; manual export bridge for critical librariesAdmin-consent requests stuck; licensing quote exceeds envelope
RSK-08Local LLM capability limits — open-weight models on our hardware underperform cloud frontier models; users who know ChatGPT are disappointed33🟡 9TPL leadBenchmark on Prime Products-realistic tasks before commitment (5.2); pick use cases within local-model competence (2.6); RAG grounding narrows the gap; expectation-setting in training (§8 of change plan)Quarterly model-refresh cycle (12.2) adopts better open models; re-scope affected use cases; hybrid escalation path for non-confidential tasks only, as a policy decisionEval scores below threshold in 5.2; CSAT ≤3.5 with “quality” cited; shadow use of public AI tools
RSK-09Greek-language performance — models handle Greek business/maritime prose, terminology, and inflection poorly34🟡 12TPL leadGreek-specific eval set from real Prime Products documents (5.2); shortlist models with proven Greek capability; bilingual prompt patterns in training; glossary of domain terms in KB feeding RAGGreek-focused fine-tune or adapter €[TBD]; English-first workflows where business-acceptable; translation-assist pattern (draft EN → translate)Greek eval materially below English on same tasks; pilot users defaulting to English against preference
RSK-10Security breach / data leak — platform breach, prompt-injection exfiltration, or confidential data leaving via misuse25🟡 10Prime Products ITSecurity architecture with segmentation + SSO + audit logs (3.5); hardening & pen check pre-GA (5.7); least-privilege agents with approval steps (9.1); usage policy §6 + training; on-prem design keeps data in-building by defaultIncident-response runbook (security-and-operations.md): isolate platform, preserve logs, notify per GDPR 72-h rule if personal data affected; disable affected agents immediatelyAudit-log anomalies; failed pen-check findings unremediated; policy-violation flags in #ai-help

Adoption & people

IDRiskPIScoreOwnerMitigationContingencyEarly-warning signal
RSK-03User adoption failure — platform ships but staff don’t use it; WAU stalls below targets35🔴 15CEOEntire change plan: CEO-led messaging, champions, hands-on training on real tasks, no-layoffs commitment, use cases chosen for felt pain (2.6)Laggard-department action plans (11.7): re-training, use-case redesign with the department, champion swap; in extremis re-scope M12 targets with board transparencyWAU plateau 4+ weeks; queries/user/day falling; pulse-survey usefulness score <3; labs with no follow-on usage
RSK-04Poor documentation habits — departments don’t write/maintain KB content; RAG starves, freshness rots43🟡 12dept champion (guild)Champion-run content sprints with TPL support (6.5); templates lower the writing bar (6.2); KB health metrics public on Mission Control (6.6); AI-assisted drafting of SOPs from interviewsTPL-led documentation surge for critical corpora €[TBD, scoped]; narrow RAG promise to well-covered domainsSOP coverage flat between steering reviews; orphan/freshness metrics degrading; sprint attendance dropping
RSK-11Change fatigue — 12 months of program touchpoints exhausts goodwill; participation becomes performative33🟡 9TPL leadLoad caps (≤4 h/person/month, change plan §13); wave sequencing avoids seasonal peaks; comms are few and honest; visible “you said → we did” loop closuresInsert a deliberate quiet month (no new asks) for affected departments; compress wave scope rather than pile onPulse-survey sentiment declining 2 months running; training no-shows; guild attendance <60%
RSK-12Lack of ownership in departments — heads treat the program as TPL’s/IT’s project; champions left unsupported34🟡 12CEODept heads own their adoption KPI (heatmap, KPI §4); use-case design workshops make heads authors, not recipients (10.4 table); champion time formally allocated; CEO reviews heatmap at all-handsCEO 1:1 with lagging head; re-assign champion; move department later in wave order rather than dragHead skips briefings/workshops; champion reports no allocated time; dept one-pager review unanswered
RSK-17Key-person dependency — single champion, IT platform owner, or TPL individual becomes a bottleneck; departure stalls a workstream33🟡 9steeringRunbooks + handover as standing deliverables (10.5, 12.4); ≥2 IT staff trained on ops; guild spreads champion knowledge; all program knowledge in this vault, not in headsBackfill from guild/TPL bench; pause affected workstream one wave rather than improviseSingle-owner workstreams visible in WBS reviews; vacation/absence causing missed deliverables
RSK-19Sponsor attention drift — CEO bandwidth consumed by operations; program loses its face and its decision speed24🟡 8steeringCEO commitments are few and scheduled 12 months ahead (kickoff, monthly segment, gate decisions); deputy sponsor named in governance modelDeputy sponsor fronts the segment short-term; TPL lead escalates pattern to boardCEO misses 2 consecutive all-hands segments or a gate decision slips awaiting sponsor

Program & commercial

IDRiskPIScoreOwnerMitigationContingencyEarly-warning signal
RSK-05SoftOne data quality — item/customer/pricing master data too dirty for reliable AI answers and automations44🔴 16TPL leadData-quality sampling in discovery (1.9); use-case scoring includes data-readiness (2.6); RAG answers cite sources so users can verify; cleansing tasks attached to affected use casesScoped master-data cleanup effort €[TBD] before dependent automations ship; human-in-the-loop step retained on affected agentsSampling error rates above threshold in 1.9; pilot users reporting wrong prices/items; agent override rate >25% on ERP-fed tasks
RSK-13Scope creep — enthusiasm (or discovery findings) balloons the use-case list; program becomes 20 half-built things43🟡 12steeringScored pipeline with explicit quick-win/pilot/later gates (2.6); charter out-of-scope list; every addition displaces something at steering — no silent additions; year-2 roadmap (12.5) as the pressure valveFormal descope decision at M8 gate: cut wave-2 automations before cutting rollout/trainingWBS items added without steering minutes; TPL utilization over plan; deliverables slipping while new work starts
RSK-14Budget overrun — hardware, licensing, or effort exceeds envelope €[TBD]34🟡 12steeringBudget envelope with contingency reserve set in 0.4; BoM options at price points (3.3); monthly spend-vs-budget in board pack; mid-program budget review at M8Draw contingency; descope per RSK-13 contingency; defer wave-2 automations or capacity expansion to year 2Spend tracking >10% over profile at any monthly review; PO exceeds BoM estimate; licensing quotes above envelope
RSK-15Vendor dependency — over-reliance on TPL (knowledge), hardware vendor (support), or SoftOne partner (integration access)33🟡 9steeringHandover is a phase, not an afterthought (12.2–12.4); everything documented in-vault; hardware support contract with defined SLA; SoftOne partner scope contracted earlySecond-source support contract €[TBD]; TPL advisory retainer sized for genuine step-back, not disguised dependenceIT can’t resolve incidents without TPL past M9; runbooks failing dry-run tests; SoftOne partner unresponsive >2 weeks
RSK-16Operational disruption during rollout — program load or process changes degrade daily ship-supply operations25🟡 10CEOMinimal-disruption rules (change plan §13): load caps, parallel-run principle, no big-bang cutovers, peak-season avoidance, 2-week deferral mechanismInvoke deferral, roll department back to pre-AI process (always kept available during hypercare); post-incident review before resumingDeferral requests being used; order-to-delivery or error-rate KPIs regressing in an onboarding department; overtime spiking during a wave
RSK-18Regulatory / GDPR non-compliance — employee/customer personal data processed by the platform without proper basis, retention, or transparency25🟡 10Compliance headDPIA for the platform before GA (with 5.7); data-category rules in usage policy §6; audit logging + retention policy in security design (3.5); HR data excluded from RAG corpora by defaultSuspend affected corpora/agents; remediate with DPO/counsel; regulator notification per 72-h rule if breachDPIA findings open at GA gate; personal data found in RAG index sampling; works-council/employee complaints
RSK-20Pilot value shortfall — pilots run but measured KPI deltas are marginal; M8 gate lacks a convincing case24🟡 8TPL leadPilot use cases chosen for measurable, felt pain (2.6, 8.1); baselines captured properly in 1.12; weekly pilot reviews catch drift early (8.6)Extend pilots 4 weeks with redesigned use cases before the rollout decision; swap in next-ranked use case from pipeline; report honestly — a weak pilot killed early is cheaper than a weak rolloutWeek-4 pilot metrics flat vs baseline; pilot users reverting to old process after novelty; CSAT fine but time-saved ≈0

Register operations

  • Add a risk: next RSK-NN, one owning role, scored, with all columns filled — in the same change as the steering minutes that raised it.
  • Close a risk: strike through the row with closure date and reason; never delete (audit trail).
  • Escalation: any 🔴 risk, or any risk whose score rises two reviews running, goes on the steering agenda automatically; 🔴 risks also appear in the board pack.
  • Top risks and their trend are displayed (sanitized) on the Mission Control program-status page.