AI for risks and issues

Updated · Thomas A. Thejn

Risk management is where AI is simultaneously most useful and most dangerous, and the line between the two is sharp enough to state precisely.

Useful for breadth. Dangerous for depth.

Where it genuinely helps

Generating candidates

The structural weakness of a risk workshop is that it is populated by people invested in the plan. Optimism is not a personal failing there; it is a property of the group.

AI has no stake. Give it your actual plan, architecture, vendor arrangements and timeline and ask what could go wrong, and it will produce a long list — much of it obvious, some of it wrong, and reliably a few items that make the room go quiet.

Those few are the entire value. You are not looking for a register; you are looking for the three things nobody said.

The pre-mortem

The strongest single technique available:

It is eighteen months from now. This programme has failed badly and an independent review has been commissioned. Write that review's findings, explaining what went wrong and when it became inevitable.

This works better than forward-looking risk identification for the same reason it works with humans: the framing removes the optimism. Asking "what might go wrong?" invites reassurance. Asking "explain the failure that already happened" invites causes.

Run it on your plan before a major gate. It takes ten minutes and it surfaces things the workshop will not.

Pattern-finding across the register

Once a register has a few hundred items, nobody holds it in their head. Ask what these thirty open issues have in common, and the answer is often that twenty of them trace to one integration, one team, or one decision that was never made.

That is the finding that matters, and it is invisible when everyone is working the list item by item.

Drafting mitigations

Fine as a first pass. Adequate mitigations are usually well known; the difficulty is writing them all down. Draft, then have the owner make them real and specific.

Where it is dangerous

Scoring

Ask for probability and impact and you get them: confident, precisely formatted, entirely invented.

The model has no basis for judging whether your vendor will deliver on time, because it does not know your vendor, your contract, your relationship, or what happened on the last three programmes. It produces numbers because numbers were requested.

This is the most dangerous failure mode in the whole series, because invented scores look exactly like analysis. A risk register with fabricated ratings is worse than one with none — it launders a guess into something that gets presented to a board.

Score with the people who own the risk. That conversation is itself half the value.

Knowing what is politically live

Every programme has a risk everyone knows about and nobody writes down: the sponsor who has lost interest, the vendor relationship that is failing, the team that cannot deliver but cannot be said to. AI cannot see any of this, and its output will read as though these do not exist.

That is not a flaw to fix with better prompting. It is the boundary of the tool.

A working method

StepWhoTool
Generate candidates from the planAIBroad prompt plus a pre-mortem
Filter to what is real hereYouJudgment
Score probability and impactRisk ownersConversation
Draft mitigationsAIFirst pass only
Make mitigations specific and ownedOwnerJudgment
Find patterns across the registerAIMonthly
Decide what goes to the steering groupYouJudgment

Three of seven steps are AI. Four are judgment, and they are the four that determine whether the register is worth anything.

One data caution

Risk registers frequently contain things you would not want repeated: doubts about a vendor's competence, concerns about a named individual's capacity, commercially sensitive contingencies.

Before pasting a register into a general-purpose tool, check what is actually in it. Anything naming individuals is personal data. Anything about a vendor's performance may be commercially damaging if it leaks, and could be disclosable in a dispute.

For registers with that content, an EU-hosted model with proper contractual terms is the baseline, and stripping names before analysis is good practice regardless of tool.

Frequently asked questions

Can AI score risks for me?
It will, and you should not let it. Probability and impact depend on your organisation, your vendor's actual track record and what happened last time — none of which the model knows. It will produce plausible numbers because that is what it was asked for. Invented scores are worse than no scores, because they get treated as analysis.
What is the best single prompt?
A pre-mortem. Give it the plan and ask: it is eighteen months from now and this programme has failed badly — write the post-mortem explaining why. It reliably surfaces failure modes that a forward-looking risk workshop misses, because the framing removes the optimism that workshops are structurally full of.
Will it just generate generic risks?
If you give it a generic prompt, yes — 'scope creep' and 'resource constraints' help nobody. Feed it your actual plan, architecture, vendor arrangements and organisational context and the output becomes specific. Quality of input is the whole variable.
What about issues rather than risks?
The most useful application is pattern-finding across a live issue log. Ask what these thirty issues have in common. Often they cluster around one root cause — a single integration, a single team, a single unmade decision — that nobody spotted because everyone was working the list item by item.

← Back to Transformation and project management

Programme not behaving?

A programme review is a contained piece of work: a few weeks, an honest status picture, the risks that matter, and a prioritised list of what to do now.

thomas@thejn.dk +45 2048 3147

Copenhagen, Denmark · Nordic coverage · Independent & platform-agnostic