Purpose
Enumerate key uncertainties facing the proposed initiative, assess their likelihood and impact, define mitigation strategies, and—critically—link each critical assumption to a specific A2–A4 validation activity that will test it.
Risk mapping without assumption linkage produces static lists (“risk: market adoption may be low”) that governance files and forgets. Assumption-linked risk mapping produces living validation plans: “If adoption is below X by milestone Y, trigger decision Z”—turning risks into testable hypotheses with pre-agreed escalation triggers.
When to Use
Use risk and assumption mapping when:
- Building A1.5 business case risk section (standard requirement for governance approval)
- Initiative involves significant uncertainty in market, technical, organisational, or financial dimensions
- Governance expects risk assessment as part of approval criteria
- Team needs to prioritise which uncertainties to resolve first in A2–A4 (risk-driven learning plan)
- Scenario-based financial model reveals assumptions with high sensitivity (top 2–3 drivers from Method: Scenario-Based Financial Modelling, the referenced method)
Do NOT use when:
- Initiative is incremental with well-understood risks (annual product refresh)—brief risk statement sufficient
- Formal risk management framework already applied at organisational level and covers this initiative—avoid duplication
Sample Size and Duration
Participants: 2–4 people
- Essential: Innovation Manager (facilitator, assumption ownership), domain expert (technical risk assessment)
- Recommended: Finance analyst (financial risk, sensitivity linkage), executive sponsor (organisational risk, political risk)
Duration:
- Light-touch (incremental initiative, well-understood domain): 2 hours
- Standard (moderate uncertainty, 5–8 risks): 3–4 hours
- Complex (high uncertainty, novel domain, regulatory complexity): 5–6 hours (may split across 2 sessions)
Prerequisites
- A1.4 feasibility assessment: Technical, market, and organisational risks identified during exploration
- Scenario-based financial model (the referenced method): Sensitivity analysis revealing high-impact assumptions
- Stakeholder input: Concerns raised during early A1.5 stakeholder engagement (the referenced method)
- Participants: Innovation Manager (facilitator), domain expert, finance analyst
- Time: 2–4 hours (see Sample Size and Duration)
Complete Procedure
Step 1: Identify Risks Across Four Categories (45–60 minutes)
Brainstorm risks using structured categories to ensure comprehensive coverage :
| p9cm Category | Guiding Questions |
|---|---|
| Market | Will customers value this? What if adoption is slower than projected? How might competitors respond? Could pricing pressure erode margins? |
| Technical | Can we build it? Are there integration, scalability, or technology maturity risks? What if a key technical assumption proves wrong? |
| Organisational | Will we implement and adopt it? Which stakeholders might resist? Do we have the capabilities required? Are change management demands realistic? |
| Financial | Will returns justify investment? What if costs overrun? What if revenue ramps slower? What if timeline extends? |
Sources of risk identification:
- A1.4 feasibility flags
- Financial model sensitivity analysis (top 2–3 drivers)
- Stakeholder concerns from engagement rounds
- Comparable initiative post-mortems (what went wrong before?)
- Team brainstorm (“What keeps you up at night about this initiative?”)
Target: 8–15 candidate risks; will be filtered to top 5–8 in Step 2.
Step 2: Assess Likelihood and Impact (30–45 minutes)
For each candidate risk:
- Rate likelihood: Low (unlikely but possible), Medium (plausible, has happened in comparable initiatives), High (probable based on evidence)
- Rate impact: Low (minor cost / timeline adjustment), Medium (significant delay, budget increase, or scope reduction), High (project failure, strategic damage, major loss)
- Plot on likelihood × impact matrix
- Prioritise: focus business case on medium–high risks (typically 5–8); acknowledge low–low risks in appendix only
Step 3: Define Mitigation Strategies (45–60 minutes)
For each priority risk (medium–high likelihood × impact):
- Mitigation action: concrete, specific step to reduce likelihood or impact (not “monitor closely”)
- Owner: named individual responsible for executing mitigation
- Timeline: when mitigation must be in place (often aligned with A2–A4 milestones)
- Residual risk: after mitigation, what risk remains?
Example:
| p1cmp1cmp4cmp2cmp2cm Risk | L | I | Mitigation | Owner | By When |
|---|---|---|---|---|---|
| Regulatory delay (MDR +4 months) | M | H | Engage notified body in Phase 1; build 3-month buffer | A. Fischer | A2 Month 2 |
| Clinician adoption resistance | H | M | Co-design with 5 pilot clinics; clinician advisory board | Dr. Schulz | A2 Month 3 |
| Data integration complexity | M | M | Phase 1 standalone; integration deferred to Phase 2 pending pilot learnings | CTO team | A4 gate |
Step 4: Link Assumptions to Validation Activities (30–45 minutes)
For each critical assumption (high-sensitivity financial driver or high-impact risk), apply the experiment card logic from :
- State the assumption precisely (“Year 1 adoption will reach 50 clinics”)
- Specify validation activity: which A2, A3, A4, or A6 activity will test this? (“A2: secure letters of intent from 10 pilot clinics”)
- Define success criterion: what result validates the assumption? (“≥8 LOIs received by Month 4”)
- Define trigger condition: what result would cause project adjustment or termination? (“4 LOIs by Month 4: escalate to governance for scope review”)
- Pre-agree governance response: if trigger hit, what happens? (Conditional Go conditions, scope reduction, Defer, Decline)
This step transforms the risk register from a static document into a living decision framework that governance can track at milestone reviews .
Step 5: Compile Assumption Register (20–30 minutes)
Consolidate into a single table for the business case appendix:
| p2cmp1.5cmp2.5cmp2cmp2cm Assumption | Value | Confid. | Validation | Success | Trigger |
|---|---|---|---|---|---|
| Y1 adoption | 50 clinics | Medium | A2: 10 pilot LOIs | ≥8 LOIs | 4 LOIs |
| Rev / clinic | 12K | Medium | A6: pilot pricing | ≥10K | 7K |
| Dev cost | 1.8M | High | A4: sprint velocity | ≤2.0M | >2.2M |
| MDR timeline | 6 months | Low | A2: notified body | On track M4 | Delay flag M4 |
Quality Criteria
Excellent risk and assumption mapping demonstrates:
- Four-category coverage: Market, technical, organisational, and financial risks all assessed—not just the team's comfort zone
- Focused prioritisation: 5–8 priority risks, not exhaustive inventory of 30+ items
- Actionable mitigations: Every mitigation specifies who, what, and when—no “monitor closely”
- Assumption transparency: Critical assumptions documented with source, confidence level, and validation plan
- Validation linkage: Each critical assumption linked to specific A2–A4 learning activity with success criterion and trigger condition
- Pre-agreed escalation: Governance response to trigger conditions documented before approval—not improvised when risks materialise
- Living document design: Register structured for ongoing review, not one-time creation
Theoretical Foundation
Seminal references:
- : Introduced risk-driven development through the Spiral Model, establishing the principle that project planning should be organised around resolving the highest risks first. While originally developed for software engineering, the core insight—sequence work to retire risk, not to follow predetermined phases—directly informs the assumption prioritisation and A2 validation linkage in this method.
- : Reframed business planning as assumption identification and testing rather than prediction. The discovery-driven planning framework provides the logic for the assumption register: every key business case number is an assumption until validated by market evidence. Introduced the concept of milestone-triggered checkpoints where invalidated assumptions trigger project redirection.
- : While focused on strategic management, introduced the principle that risk assessment must cover multiple organisational dimensions (financial, customer, internal process, learning / growth)—not just financial risk. This multi-category logic informs the four-category risk identification framework (market, technical, organisational, financial) used in Step 1.
Contemporary references:
- : Provided practical tools for assumption mapping in corporate innovation contexts: the assumption map (importance × evidence), the experiment card (hypothesis, method, success criterion, trigger), and the learning sprint. Directly informs Steps 4–5 of this method.
- : Popularised the build-measure-learn cycle and the concept of validated learning, establishing that assumptions should be tested through minimum viable experiments rather than comprehensive analysis. Influences the validation linkage approach: assumptions linked to the fastest, cheapest experiment that could invalidate them.
- : Contemporary risk management scholarship integrating traditional risk assessment with agile / adaptive approaches. Argues that early-stage innovation risks should be managed through staged commitment and real-options thinking rather than upfront mitigation planning alone—supporting the phased approval and conditional Go patterns in A1.5.
Challenges and Solutions
Challenge 1: Static Risk Lists That No One Revisits
Symptoms:
- Risk register created for business case, never updated during A2–A7
- Risks materialise with no pre-planned response
- Governance surprised by problems that were listed as risks
Solutions:
- Assumption register with validation linkage (Steps 4–5) creates living document with built-in review triggers
- Include assumption review as standing agenda item at A2–A4 milestone reviews
- Pre-agree governance response to trigger conditions—eliminates decision delay when risks materialise
Challenge 2: Generic Mitigations (“Monitor Closely”)
Symptoms:
- Mitigation column reads “monitor,” “track,” “be aware of”
- No named owner, no timeline, no specific action
Solutions:
- Enforce specificity test: every mitigation must answer who does what by when
- If team cannot define concrete mitigation, risk may be unmitigable—document as accepted risk with contingency plan (“If X happens, we will Y”)
- Gate A1.5-1 checklist should reject risk sections with generic mitigations
Challenge 3: Exhaustive Risk Inventories (30+ Items)
Symptoms:
- Risk register lists every conceivable risk regardless of probability
- Governance overwhelmed; cannot distinguish critical risks from noise
- Analysis paralysis—team spends weeks on risk identification
Solutions:
- Target 5–8 priority risks in the business case body; relegate low-probability items to appendix
- Apply Pareto principle: which 3–5 risks account for 80% of potential value destruction?
- Time-box risk identification to 60 minutes (Step 1)—if team cannot identify a risk in 60 minutes, it is probably not top-of-mind enough to be a priority risk
Challenge 4: Confusing Risks with Issues
Symptoms:
- “Risk” register contains items that are already certain (“IT systems are outdated”)
- Team conflates future uncertainty (risk) with current problems (issues)
Solutions:
- Distinguish: risks are uncertain future events; issues are current known problems
- Issues belong in the business case constraints section, not risk section
- For each candidate risk, ask: “Is this something that might happen, or something that has happened?”
Relationship to Other Methods
Risk and Assumption Mapping receives input from:
- A1.4 Feasibility Assessment: Technical, market, and organisational risks identified during exploration
- Scenario-Based Financial Modelling (the referenced method): Sensitivity analysis revealing high-impact financial assumptions
- Stakeholder Analysis and Engagement Design (the referenced method): Stakeholder concerns raised during engagement rounds become organisational risks
Risk and Assumption Mapping provides input to:
- Structured Business Case Development (the referenced method): Risk section and assumption register (Step 5)
- Scenario-Based Financial Modelling (the referenced method): Risk register informs conservative scenario assumptions (bidirectional)
- Governance Presentation Design (the referenced method): Top risks and assumption register are key governance slides
- A2 Ideation: Assumption validation priorities shape A2 learning plan and experiment sequence
*Example: Digital Patient Engagement Platform
Context: Medical device company; business case for orthopaedic digital patient engagement platform (1.8M, 14 months).
Risk register (top 5):
| p2.5cmp0.8cmp0.8cmp3.5cmp2cmp2.5cm # | Risk | L | I | Mitigation | Owner | By When |
|---|---|---|---|---|---|---|
| 1 | MDR regulatory delay | M | H | Engage notified body Phase 1; 3-month buffer | A. Fischer | A2 Month 2 |
| 2 | Clinician adoption resistance | H | M | Co-design with 5 pilot clinics; advisory board | Dr. Schulz | A2 Month 3 |
| 3 | Data integration complexity | M | M | Phase 1 standalone; defer integration to Phase 2 | CTO team | A4 gate |
| 4 | Patient engagement drop-off | H | M | Behavioural design expertise; gamification pilot | M. Park | A3 prototype |
| 5 | Revenue model unvalidated | M | H | A6 pilot with 5 clinics; test 3 pricing tiers | J. Weber | A6 Month 10 |
Assumption register (top 3):
| p1.5cmp1.3cmp2.8cmp2cmp2.5cm Assumption | Value | Confid. | Validation | Success | Trigger |
|---|---|---|---|---|---|
| Y1 adoption | 50 clinics | Med | A2: 10 pilot LOIs by M4 | ≥8 LOIs | 4 LOIs scope review |
| Rev / clinic | 12K | Med | A6: 5-clinic pricing pilot | ≥10K avg | 7K model pivot |
| MDR timeline | 6 months | Low | A2: notified body engagement M2 | On track at M4 | Delay flag Phase 2 timeline adjustment |
Tools and Templates
- Risk Assessment Matrix (the referenced method)
- Assumption Register (integrated into Risk Assessment Matrix)
- Assumption Map—importance × evidence plot
- Experiment Card template (hypothesis, method, success criterion, trigger)
- B. W. Boehm (1991). Software Risk Management: Principles and Practices. IEEE Software. 8(1). pp. 32–41.
- D. J. Bland & A. Osterwalder (2020). Testing Business Ideas. Wiley.
- E. Ries (2011). The Lean Startup: How Today's Entrepreneurs Use Continuous Innovation to Create Radically Successful Businesses. Crown Business.
- F. O'Brien (2019). Risk Management for Project Driven Organizations. J. Ross Publishing.
- R. G. McGrath & I. C. MacMillan (1995). Discovery-Driven Planning. Harvard Business Review. 73(4). pp. 44–54.
- R. S. Kaplan & D. P. Norton (1996). The Balanced Scorecard: Translating Strategy into Action. Harvard Business School Press.
Share how you use Risk and Assumption Mapping
This is where practitioners will be able to share field notes, variations, and additional templates for this method — what worked, what to watch for, and adaptations for different contexts.
Until the community space opens, we welcome contributions by email and will fold the best into the method page.