AI for risks and issues
Risk management is where AI is simultaneously most useful and most dangerous, and the line between the two is sharp enough to state precisely.
Useful for breadth. Dangerous for depth.
Where it genuinely helps
Generating candidates
The structural weakness of a risk workshop is that it is populated by people invested in the plan. Optimism is not a personal failing there; it is a property of the group.
AI has no stake. Give it your actual plan, architecture, vendor arrangements and timeline and ask what could go wrong, and it will produce a long list — much of it obvious, some of it wrong, and reliably a few items that make the room go quiet.
Those few are the entire value. You are not looking for a register; you are looking for the three things nobody said.
The pre-mortem
The strongest single technique available:
It is eighteen months from now. This programme has failed badly and an independent review has been commissioned. Write that review's findings, explaining what went wrong and when it became inevitable.
This works better than forward-looking risk identification for the same reason it works with humans: the framing removes the optimism. Asking "what might go wrong?" invites reassurance. Asking "explain the failure that already happened" invites causes.
Run it on your plan before a major gate. It takes ten minutes and it surfaces things the workshop will not.
Pattern-finding across the register
Once a register has a few hundred items, nobody holds it in their head. Ask what these thirty open issues have in common, and the answer is often that twenty of them trace to one integration, one team, or one decision that was never made.
That is the finding that matters, and it is invisible when everyone is working the list item by item.
Drafting mitigations
Fine as a first pass. Adequate mitigations are usually well known; the difficulty is writing them all down. Draft, then have the owner make them real and specific.
Where it is dangerous
Scoring
Ask for probability and impact and you get them: confident, precisely formatted, entirely invented.
The model has no basis for judging whether your vendor will deliver on time, because it does not know your vendor, your contract, your relationship, or what happened on the last three programmes. It produces numbers because numbers were requested.
This is the most dangerous failure mode in the whole series, because invented scores look exactly like analysis. A risk register with fabricated ratings is worse than one with none — it launders a guess into something that gets presented to a board.
Score with the people who own the risk. That conversation is itself half the value.
Knowing what is politically live
Every programme has a risk everyone knows about and nobody writes down: the sponsor who has lost interest, the vendor relationship that is failing, the team that cannot deliver but cannot be said to. AI cannot see any of this, and its output will read as though these do not exist.
That is not a flaw to fix with better prompting. It is the boundary of the tool.
A working method
| Step | Who | Tool |
|---|---|---|
| Generate candidates from the plan | AI | Broad prompt plus a pre-mortem |
| Filter to what is real here | You | Judgment |
| Score probability and impact | Risk owners | Conversation |
| Draft mitigations | AI | First pass only |
| Make mitigations specific and owned | Owner | Judgment |
| Find patterns across the register | AI | Monthly |
| Decide what goes to the steering group | You | Judgment |
Three of seven steps are AI. Four are judgment, and they are the four that determine whether the register is worth anything.
One data caution
Risk registers frequently contain things you would not want repeated: doubts about a vendor's competence, concerns about a named individual's capacity, commercially sensitive contingencies.
Before pasting a register into a general-purpose tool, check what is actually in it. Anything naming individuals is personal data. Anything about a vendor's performance may be commercially damaging if it leaks, and could be disclosable in a dispute.
For registers with that content, an EU-hosted model with proper contractual terms is the baseline, and stripping names before analysis is good practice regardless of tool.
Frequently asked questions
- Can AI score risks for me?
- It will, and you should not let it. Probability and impact depend on your organisation, your vendor's actual track record and what happened last time — none of which the model knows. It will produce plausible numbers because that is what it was asked for. Invented scores are worse than no scores, because they get treated as analysis.
- What is the best single prompt?
- A pre-mortem. Give it the plan and ask: it is eighteen months from now and this programme has failed badly — write the post-mortem explaining why. It reliably surfaces failure modes that a forward-looking risk workshop misses, because the framing removes the optimism that workshops are structurally full of.
- Will it just generate generic risks?
- If you give it a generic prompt, yes — 'scope creep' and 'resource constraints' help nobody. Feed it your actual plan, architecture, vendor arrangements and organisational context and the output becomes specific. Quality of input is the whole variable.
- What about issues rather than risks?
- The most useful application is pattern-finding across a live issue log. Ask what these thirty issues have in common. Often they cluster around one root cause — a single integration, a single team, a single unmade decision — that nobody spotted because everyone was working the list item by item.