The risk register nobody opens until the audit
Traditional project risk management produces a document: probability × impact matrices, colored heat maps, quarterly reviews. By the time someone reads it, the real risks already moved—stuck approvals, silent budget drift, one engineer carrying three critical paths.
AI to identify project risks works differently when grounded in delivery systems. Instead of generating generic "vendor delay" rows, assistants query live signals—aging work, finance trends, capacity heat, pending approvals—and leadership tools like executive_brief and decision_inbox turn signals into owned decisions.
A practical risk identification framework
Group risks into five lenses your PM platform already touches:
1. Flow and delivery risks
- Tasks aging in Review or Testing (
flow_aging) - Blocked items without comments
- Dependency chains on overdue predecessors
2. Capacity and people risks
- One assignee red across projects (
workload_heatmap) - Vacation without backup owner
- Approval queues waiting on a single executive
3. Financial risks
- Spend trending above plan without matching scope (
finance_summary) - Missing ETC when percent-complete looks green
- Vendor invoices without linked delivery tasks
4. Decision and governance risks
- Open forks in
decision_inboxpast SLA - Contradictory wiki guidance (
smart_searchsurfaces conflicts) - Approvals blocking release (
list_pending_approvals)
5. Strategic and portfolio risks
- Same milestone threatened on multiple projects (
portfolio_overview) - Officer lenses disagree—CEO
executive_briefexposesboard.tensions
AI narrates patterns across these lenses; humans classify severity and assign owners.
executive_brief: officer-grade risk signals
executive_brief applies role-specific analysis—ceo, cfo, cto, coo, chro, cpo, ciso—to the same underlying portfolio. Each lens emphasizes different risk types:
- CFO — Burn, margin, finance-linked delivery gaps (via
finance_summarycontext) - CTO — Engineering quality, git/CI signals where integrated
- COO — Delivery SLA, flow bottlenecks
- CHRO — Capacity and overload patterns
Briefs return structured FACTS → diagnosis → decisions. They report data gaps honestly—if finance entries are missing, the brief says so instead of inventing variance.
Use briefs as Monday pre-read, not replacement for PM judgment.
decision_inbox: risks that need a human fork
Not every signal becomes a project task. Some require executive choice: delay release, cut scope, approve overtime budget, escalate vendor contract.
decision_inbox prioritizes these items. Background monitors may auto-raise entries when thresholds cross; PMs can add_decision_item manually when debate stalls in chat.
Weekly leadership loop:
- Pull
executive_brieffor relevant roles - Triage
decision_inboxtop three - Attach evidence—aging list, finance summary, scenario output
- Resolve with owner and date; log for calibration
AI prompts that identify real risks
Via WKFGo MCP—always require citations:
- "List top flow_aging hotspots on Project Beta with task IDs."
- "Pull finance_summary—flag categories trending high; report gaps."
- "What decision_inbox items are oldest?"
- "Run executive_brief role=cfo—summarize delivery-linked financial risks."
Avoid: "Give me all project risks" without scope—too vague, invites hallucination.
Anti-patterns
- AI-generated risk registers with no task or finance linkage
- Treating brief diagnosis as proof without reading cited facts
- Logging risks only in meeting notes—not
publish_meeting_wikior decisions - Ignoring low-probability key-person dependencies until quit day
Culture: risks are signals, not blame
Risk reviews fail when they become performance theater. Frame flow_aging and heatmap findings as system fixes—WIP limits, approval SLAs, staffing— not "why were you slow?"
Risk review cadence that scales
Daily (5 min) — Standup mentions top flow_aging items only; no full risk workshop.
Weekly (30 min) — PM triages new signals: heatmap rows turning red, finance categories drifting, inbox items aging.
Monthly (60 min) — Leadership reads executive_brief pre-work; resolves top decision_inbox items with logged outcomes.
AI reduces prep time for weekly and monthly layers—it does not eliminate human ownership of severity ratings.
When to escalate from task to inbox
If the "fix" requires budget, contract, or release date authority, add_decision_item instead of creating another IC task labeled "urgent." Mixed backlogs confuse teams and hide executive latency. simulate_scenario attachments give decision-makers the same evidence PMs saw in risk review.
Risk appetite per project tier
Tier-1 client projects warrant weekly executive_brief touches; internal tooling may need only flow_aging. AI scales prep to tier—do not run CEO brief theater on every small initiative.
FAQ — AI project risk identification
Does AI replace formal risk management?
It feeds it with live data. Regulated programs may still need documented registers—populate them from tool output.
Which tool first for risk reviews?
Start with flow_aging and decision_inbox— highest signal-to-effort for most software teams.
Can contractors use executive_brief?
MCP enforces feature access; contractors typically see project-scoped tools only.
What if data is incomplete?
Good briefs and assistants report gaps—fix logging hygiene instead of trusting invented numbers.
Try it now
Put these patterns on live project data—not slide decks.