The risk register nobody opens until the audit

Traditional project risk management produces a document: probability × impact matrices, colored heat maps, quarterly reviews. By the time someone reads it, the real risks already moved—stuck approvals, silent budget drift, one engineer carrying three critical paths.

AI to identify project risks works differently when grounded in delivery systems. Instead of generating generic "vendor delay" rows, assistants query live signals—aging work, finance trends, capacity heat, pending approvals—and leadership tools like executive_brief and decision_inbox turn signals into owned decisions.

A practical risk identification framework

Group risks into five lenses your PM platform already touches:

1. Flow and delivery risks

2. Capacity and people risks

3. Financial risks

4. Decision and governance risks

5. Strategic and portfolio risks

AI narrates patterns across these lenses; humans classify severity and assign owners.

executive_brief: officer-grade risk signals

executive_brief applies role-specific analysis—ceo, cfo, cto, coo, chro, cpo, ciso—to the same underlying portfolio. Each lens emphasizes different risk types:

Briefs return structured FACTS → diagnosis → decisions. They report data gaps honestly—if finance entries are missing, the brief says so instead of inventing variance.

Use briefs as Monday pre-read, not replacement for PM judgment.

decision_inbox: risks that need a human fork

Not every signal becomes a project task. Some require executive choice: delay release, cut scope, approve overtime budget, escalate vendor contract.

decision_inbox prioritizes these items. Background monitors may auto-raise entries when thresholds cross; PMs can add_decision_item manually when debate stalls in chat.

Weekly leadership loop:

  1. Pull executive_brief for relevant roles
  2. Triage decision_inbox top three
  3. Attach evidence—aging list, finance summary, scenario output
  4. Resolve with owner and date; log for calibration

AI prompts that identify real risks

Via WKFGo MCP—always require citations:

Avoid: "Give me all project risks" without scope—too vague, invites hallucination.

Anti-patterns

Culture: risks are signals, not blame

Risk reviews fail when they become performance theater. Frame flow_aging and heatmap findings as system fixes—WIP limits, approval SLAs, staffing— not "why were you slow?"

Risk review cadence that scales

Daily (5 min) — Standup mentions top flow_aging items only; no full risk workshop.

Weekly (30 min) — PM triages new signals: heatmap rows turning red, finance categories drifting, inbox items aging.

Monthly (60 min) — Leadership reads executive_brief pre-work; resolves top decision_inbox items with logged outcomes.

AI reduces prep time for weekly and monthly layers—it does not eliminate human ownership of severity ratings.

When to escalate from task to inbox

If the "fix" requires budget, contract, or release date authority, add_decision_item instead of creating another IC task labeled "urgent." Mixed backlogs confuse teams and hide executive latency. simulate_scenario attachments give decision-makers the same evidence PMs saw in risk review.

Risk appetite per project tier

Tier-1 client projects warrant weekly executive_brief touches; internal tooling may need only flow_aging. AI scales prep to tier—do not run CEO brief theater on every small initiative.

FAQ — AI project risk identification

Does AI replace formal risk management?
It feeds it with live data. Regulated programs may still need documented registers—populate them from tool output.

Which tool first for risk reviews?
Start with flow_aging and decision_inbox— highest signal-to-effort for most software teams.

Can contractors use executive_brief?
MCP enforces feature access; contractors typically see project-scoped tools only.

What if data is incomplete?
Good briefs and assistants report gaps—fix logging hygiene instead of trusting invented numbers.

Try it now

Put these patterns on live project data—not slide decks.