Risk Analysis & Management
Identify, assess, and manage uncertain events that could impact initiative success.
Definition
Risk Analysis is a technique used to identify, assess, and manage potential risks that could positively or negatively impact an initiative. A risk is an uncertain event that, if it occurs, may affect objectives. Risk Analysis answers the question: "What could go wrong (or right), and how do we handle it?" Business Analysts use it to surface threats early, support informed decision-making, and ensure mitigation actions are explicit and owned.
Inputs
- Business objectives and initiative scope
- Input from workshops, interviews, historical data, and lessons learned
- Constraints, assumptions, and dependencies
- Compliance and regulatory requirements applicable to the domain
Outputs
- A risk register with identified risks, categories, likelihood, impact, and mitigation actions
- Prioritized risks using a risk matrix or scoring model
- Agreed mitigation, avoidance, transfer, or acceptance decisions for each risk
- Inputs to project planning, solution design, and stakeholder communication
When to Use
- Planning new initiatives or transformations where proactive risk identification is essential
- Making investment or solution design decisions with material uncertainty
- Working in regulated or high-impact environments where risk must be documented and governed
- Integrating multiple systems or vendors where interface and dependency risks are high
When Not to Use
- When risks are already fully documented and actively governed through a separate risk management function
- Very simple, short-lived initiatives with minimal uncertainty
- When the cost of risk analysis exceeds the value given the initiative's size and impact
See this technique in action with a free RequirementsHub workspace.
Start Free Workspace →