← Back to Blog

Project Management and AI

Risk register on a monitor with sticky notes and ticket printouts for new risks

Risk Registers That Update Themselves (Almost)

Most risk registers I meet are either empty, ancient, or so padded that nobody believes them. The honest ones get updated when something hurts. By then the register is a diary of late discoveries, not a tool for early action.

AI will not fix that by itself. What it can do is mine the places risk shows up in plain language before someone opens the RAID spreadsheet: tickets, standup notes, incident comments, vendor emails, decision logs. Almost automatic is the right ambition. Fully automatic is how you get a long list of noise that trains people to ignore the register again.

Where new risks usually hide

They rarely introduce themselves as “Risk ID 47.” They sound like:

  • “Waiting on security review, no date yet”
  • “Vendor said maybe next sprint”
  • “Only one person knows that batch job”
  • “Data quality in the feed is messy”
  • “Legal still reviewing the clause”
  • “We will parallel-run if we have time”

Those phrases are risk seeds. A model can flag them. A human still decides whether they are real, new, duplicate, or already accepted.

A practical almost-automated loop

  1. Collect sources weekly: RAID export, open tickets tagged delay or blocked, standup notes, major meeting decisions.
  2. Ask AI for candidates: new risks, possible triggers, related existing risks, and wording that might understate severity.
  3. Human triage: keep, merge, discard. No candidate becomes official without a short yes.
  4. Score and own: probability, impact, proximity, owner, response type (avoid, mitigate, transfer, accept).
  5. Respond and review: actions with dates. Kill stale risks. Escalate the ones that sit red too long.

Notice the pattern. AI proposes. People dispose. If you skip triage, you get a risk cemetery with great formatting.

What humans must still do

Scoring is judgment. Two delays are not equal. A missing icon on a UI is not the same as a regulatory filing window. Models can suggest scores. They do not feel the sponsor’s patience or the regulator’s calendar.

Ownership is a name. “Team” is not an owner. “IT” is not an owner. If nobody’s performance or credibility is tied to the response, the risk is decoration.

Response is work. Logging a risk is not managing it. Mitigation often means a backup plan, a spike, a vendor call, a scope cut, or a decision requested from steering. AI can draft the mitigation sentence. Someone still has to do the thing.

False positives and false comfort

Ticket mining can over-flag. Every blocked story is not a program-level risk. Standup venting is not always a signal. On the other side, quiet risks stay quiet: the stakeholder who stopped replying, the dependency nobody wrote a ticket for, the assumption that “prod data will be clean enough.”

So I treat AI output as a second set of eyes, not as the risk manager. I still walk the board. I still ask, “What would embarrass us in four weeks if it were true today?”

Keep the register usable

A good register is short enough to review in a real meeting. Group related items. Separate issues (already happening) from risks (might happen). Link each top risk to a decision or action. If leadership only ever sees a heat map with no names and no next steps, they learn that red is a color, not a call to act.

For smaller projects, a simple RAID view inside a lightweight plan is often enough. I put a free Agile and Waterfall tool on this site for that kind of work. The point is visibility and ownership, not a 40-column enterprise risk ontology nobody maintains.

What changes for the PM

You spend less time hunting for wording and more time on which risks deserve airtime. You might catch weak signals earlier. You also have a new failure mode: a beautiful auto-updated register that is wrong in subtle ways. Review cadence matters more when generation is cheap.

My bias from years of delivery work is simple. Risk management is a conversation with evidence, not a document cult. AI can widen the evidence scan. Humans still decide what is real, who owns it, and what we will do before the surprise becomes the plan.

If you are starting from a dead register, do not try to rebuild history in one afternoon. Seed it with the top five risks you would put in front of a sponsor tomorrow. Wire the weekly scan. Kill anything that has no owner after two reviews. Momentum beats a perfect taxonomy.

Almost automatic is fine. Accountable is non-negotiable.

How I Can Help

I help delivery teams build risk habits that catch weak signals early without turning the RAID log into noise. That can include:

  • Designing a weekly AI-assisted risk scan over tickets, notes, and RAID history
  • Triage rules so candidate risks get scored, owned, and actioned by humans
  • Facilitating risk reviews that force decisions, not just color ratings
  • Light RAID and plan tooling for projects that need clarity more than ceremony

Reach out for a quick chat on how I can help at Suganth@AruviConsultancyServices.com