
IT Project Risk Assessment & Mitigation Planner
Build IT project risk registers with systematic threat identification, impact rating, and mitigat...
What You Can Do
You can build a comprehensive risk register for IT projects by working with Claude to discover threats across technical, organizational, schedule, and external domains. Claude guides you through a structured taxonomy of IT-specific risk categories, helps you rate each threat's impact and probability using consistent frameworks, and drafts mitigation strategies with assigned owners and measurable success criteria. The result is a governance-ready risk register suitable for steering committees, status reports, and escalation decisions.
Features
standardized scoring that ranks risks by severity for prioritization
actionable response plans for each risk with assigned owners and success metrics
export-ready markdown or table format for steering committees and status reports
structured workflow to reassess existing risks and surface new threats as project evolves
identify cascading failure modes when risks interact (schedule slip + resource shortage = compounded impact)
pre-built language for briefing leadership on high-severity, high-probability threats
structured questions to identify gaps that allowed risks to materialize into incidents
Example Output
Risk Register (Excerpt):
| Risk | Category | Probability | Impact | Score | Mitigation | Owner | Success Criteria |
|---|---|---|---|---|---|---|---|
| Database migration performance unknown | Technical | High | Critical | 9 | Conduct PoC with production data subset; engage vendor for performance tuning | DBA Lead | PoC completes 2 weeks pre-cutover; <2% perf degradation |
| Contractor availability during peak phase | Resource | Medium | High | 6 | Negotiate SLA with penalty clause; identify backup contractor by week 4 | PM | Backup contractor named; SLA signed by kickoff |
| Steering committee alignment on scope | Stakeholder | High | High | 8 | Monthly steering meetings with updated requirements matrix; executive sponsor sign-off by phase gate | Sponsor | Zero scope creep after gate 2 |
Mitigation Summary: Identified 12 risks across 5 categories. Top 3 (scores 8–9) require active monitoring and monthly review. 4 risks mitigated by vendor SLA, 3 by resource backfill, 5 by architecture hardening.
What's Included
- IT-project-risk-assessment SKILL.md: instruction file with risk discovery prompts and rating framework
- Risk Register Template: pre-formatted markdown table with headers: Risk | Category | Probability | Impact | Score | Mitigation | Owner | Success Criteria
- IT Risk Taxonomy Checklist: 50+ pre-populated risk examples across technical, schedule, resource, stakeholder, and vendor categories
- Impact & Probability Matrix: 5×5 scoring guide with definitions (Critical, High, Medium, Low) to ensure consistent rating
- Quarterly Risk Review Workflow: structured prompts to reassess risks, close mitigated items, and surface new threats
- Escalation Brief Template: 1-page executive summary format for high-severity risks with business impact and mitigation status
Who It's For
- IT Project Managers — building risk registers for infrastructure, software, or platform deployments
- Solutions Architects — assessing technical and dependency risks during design phase
- Program Managers — managing portfolio-level risk aggregation and steering committee communication
- IT Delivery Leaders — ensuring risks are owned, monitored, and escalated appropriately
- Scrum Masters / Agile Leads — identifying sprint-level and release-level risks in iterative projects
Best For
- Project kickoff risk workshops — 30-minute session to surface threats before detailed planning
- Scope change impact assessment — evaluate new risks introduced by requirement updates
- Quarterly risk reviews — reassess existing risks and identify emerging threats mid-project
- Steering committee preparation — build a defensible risk narrative for executive briefings
- Vendor/contractor onboarding — assess risks from external dependencies and third-party integrations
- Post-incident retrospectives — identify gaps that allowed risks to materialize into failures







