Risk Analysis & Management

Identify, assess, and manage uncertain events that could impact initiative success.

Definition

Risk Analysis is a technique used to identify, assess, and manage potential risks that could positively or negatively impact an initiative. A risk is an uncertain event that, if it occurs, may affect objectives. Risk Analysis answers the question: "What could go wrong (or right), and how do we handle it?" Business Analysts use it to surface threats early, support informed decision-making, and ensure mitigation actions are explicit and owned.

Inputs

  • Business objectives and initiative scope
  • Input from workshops, interviews, historical data, and lessons learned
  • Constraints, assumptions, and dependencies
  • Compliance and regulatory requirements applicable to the domain

Outputs

  • A risk register with identified risks, categories, likelihood, impact, and mitigation actions
  • Prioritized risks using a risk matrix or scoring model
  • Agreed mitigation, avoidance, transfer, or acceptance decisions for each risk
  • Inputs to project planning, solution design, and stakeholder communication

When to Use

  • Planning new initiatives or transformations where proactive risk identification is essential
  • Making investment or solution design decisions with material uncertainty
  • Working in regulated or high-impact environments where risk must be documented and governed
  • Integrating multiple systems or vendors where interface and dependency risks are high

When Not to Use

  • When risks are already fully documented and actively governed through a separate risk management function
  • Very simple, short-lived initiatives with minimal uncertainty
  • When the cost of risk analysis exceeds the value given the initiative's size and impact

See this technique in action with a free RequirementsHub workspace.

Start Free Workspace →