← ArticlesProject Risk Identification Workshops and MethodsProject Delivery · RiskLesson 1/10← PrevNext →
GuidePublished 13 Aug 202611 min readBy Kevin Joginrisk identificationrisk workshopbrainstormingassumptions

Project Delivery · Project Risk Management

Project Risk Identification Workshops and Methods

A facilitator's handbook for systematic risk identification using objectives, assumptions, interfaces, structured prompts and cross-functional challenge.

11 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A facilitator's handbook for systematic risk identification using objectives, assumptions, interfaces, structured prompts and cross-functional challenge. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Prepare scope and evidence
  • Select diverse participants
  • Generate risks through multiple lenses
  • Structure and challenge records
  • Assign follow-up and ownership
  1. Prepare scope and evidence
  2. Select diverse participants
  3. Generate risks through multiple lenses
  4. Structure and challenge records
  5. Assign follow-up and ownership

Why This Matters: The Most Consequential Phase

Every experienced project manager knows the axiom: you cannot manage a risk you have not identified. What fewer appreciate is just how consequential the identification phase truly is. Uncertainty-management sources put it bluntly — if sources and responses are not properly understood, any subsequent risk management can be a complete waste of resources.

In heavy engineering and defence contracting, this is not theoretical. A Tier-1 defence programme that fails to identify regulatory approval as a coupled technical-legal risk source during identification will discover the oversight during execution — when the cost of recovery is orders of magnitude higher. A manufacturing project that relies solely on a generic checklist will miss the site-specific interactions between weather, crane availability, and concrete curing schedules that drive the real schedule risk.

This article moves beyond the introductory treatment of PMBOK's "Identify Risks" process to examine the full toolkit of identification techniques, drawing on a widely used uncertainty-management framework's SHAMPU framework, the earlier process-based project risk model, the APM PRAM Guide, and practitioner templates from the requirements-focused checklist risk identification checklist.

What Is Risk Identification?

In SHAMPU terms, identification involves two specific tasks:

  1. Search — for sources of uncertainty and associated responses, employing a range of techniques
  2. Classify — to provide a suitable structure for defining sources and responses, aggregating or disaggregating particular issues as appropriate

The key deliverable is a clear, common understanding of the sources of uncertainty facing the project and what can be done about them. Crucially, SHAMPU insists that identification must surface opportunities alongside threats, and must identify at least one assumed response for each identified source — even if that response is simply "do nothing."

Sources, Responses, and Secondary Sources

A fundamental distinction in mature risk identification is the three-layer model:

Layer Definition Example (Naval Shipbuilding)
Primary Source An uncertainty that directly impacts a performance criterion Specialist welding contractors may not be available when needed
Response A proactive or reactive action to address the source Pre-qualify and retain three alternative welding contractors
Secondary Source New uncertainty created by the response itself Alternative contractors may have lower quality standards, creating rework risk

How It Works: The Identification Toolkit

Technique 1: The Structured Ponder Approach

A widely used uncertainty-management framework's recommended starting point is deceptively simple: ponder. Begin with the project's key performance criterion and systematically consider what could affect it, activity by activity. This is not casual reflection — it is a disciplined, individual analyst-level examination of the project activity structure defined in the SHAMPU Define phase.

The ponder approach begins with KLP issues — Key criterion, Level one, Primary issues — before expanding to secondary criteria and other Ws. Practical application: An analyst examining a defence vehicle prototype programme would start with the key criterion (delivery date), walk through each activity in the 20-activity strategic structure, and identify what could directly delay each one. Only after this first sweep would cost uncertainty, quality uncertainty, and stakeholder uncertainty be layered on.

Technique 2: Brainstorming Workshops

Brainstorming is the most widely used identification technique and the most frequently misapplied. Effective brainstorming requires:

Technique 3: The Delphi Technique

The Delphi technique addresses brainstorming's social conformity weakness by collecting expert judgements anonymously and iteratively:

  1. Round 1: Each expert independently identifies risks and provides preliminary assessments
  2. Compilation: A facilitator aggregates and anonymises all responses
  3. Round 2: Experts review the aggregated list and revise their assessments in light of others' input
  4. Convergence: Repeated rounds continue until a stable consensus emerges Strengths: Eliminates groupthink, anchoring bias, and authority bias. Particularly valuable when experts are geographically dispersed or when political sensitivities make open discussion difficult. Limitations: Time-consuming, requires sustained expert engagement, and can lose the creative spark that face-to-face interaction generates.

Technique 4: Expert Interviews

Structured interviews with subject matter experts, past project managers, and task managers uncover "subtle" information that has not been documented. Uncertainty-management sources describe the risk analyst's role as someone "prepared to ask lots of dumb questions" — and note that sometimes the apparently dumb questions have no effective answers, revealing cracks that need serious attention.

Interview Protocol for Defence/Engineering Projects:

Interview Element Purpose
Walk through the WBS activity by activity Surface activity-specific sources
Ask "what keeps you awake at night?" Elicit tacit concerns not captured in formal documentation
Ask "what happened last time?" Draw on historical project memory
Ask "who else should I talk to?" Expand the identification network
Ask "what assumptions are you making?" Surface hidden assumptions that may be invalid

Technique 5: Checklist and Prompt List Analysis

Checklists are popular because they provide a structured, repeatable starting point. However, uncertainty-management sources offer a significant caution:

The distinction between a checklist and a prompt list is important:

Tool Purpose Risk
Checklist Exhaustive list of specific risks from previous projects May constrain thinking to known risks; provides false assurance of completeness
Prompt List Broad category headings that stimulate thinking Less constraining but requires more expertise to use effectively

A typical prompt list for heavy engineering might use these broad headings:

The requirements-focused checklist Checklist Approach: The practitioner template from the project knowledge base demonstrates a comprehensive requirements-focused checklist covering requirements source, requirements stability, solution complexity, technology risk, and team capability. Each section poses specific diagnostic questions — for example, "Have requirements been jointly developed by the customer and the solution team?" This approach works well for IT and systems projects but must be adapted for heavy engineering contexts.

Technique 6: Assumptions Analysis

Every project plan rests on assumptions. Assumptions analysis systematically challenges these assumptions to determine what risks they conceal. PMBOK identifies four categories of assumption vulnerability:

Technique 7: Diagramming Techniques

Visual methods for identifying causal relationships between risks include:

Technique 8: SWOT Analysis

SWOT analysis examines the project from the perspective of internal strengths and weaknesses alongside external opportunities and threats. While primarily a strategic planning tool, it serves as a useful cross-check during risk identification to ensure that both upside and downside uncertainties have been captured.

Technique 9: Documentation Reviews

Structured reviews of all project documentation — plans, assumptions, previous project files, contracts, specifications — can reveal inconsistencies and gaps that are themselves sources of risk. Uncertainty-management sources note that the quality of plans, as well as consistency between plans and requirements, can be direct indicators of risk.

The Five-Step Identification Sequence

Uncertainty-management sources recommend a structured five-step identification sequence within the SHAMPU Identify phase:

Step 1 begins with the simplest question: what could directly affect the key performance criterion (usually time or cost) at the activity level? This generates a first-cut list. Step 2 expands the aperture: what about other performance criteria (quality, safety, reputation)? What about the other Ws — who (contractor failures, regulator changes), what (design deficiencies), wherewithal (resource shortages), when (seasonal constraints)? Step 3 immediately pairs each source with at least one response. The "do nothing" response is acceptable as a placeholder, but proactive and reactive options should be generated wherever possible. Step 4 examines whether proposed responses create new uncertainties — the secondary source problem. Step 5 deploys the full range of techniques described above to elaborate and verify the completeness of the identification.

Classifying Risks: Wet Buckles and Dry Buckles

Uncertainty-management sources use an evocative example from the offshore energy sector pipe-laying to illustrate the critical importance of proper classification during identification:

Both are "buckles." But treating them as a single risk category would be catastrophically misleading. Dry buckles are minor productivity variations; wet buckles are project-threatening events requiring dedicated analysis and specific responses.

Pitfalls: Where Identification Goes Wrong

1. Stopping after brainstorming. A single brainstorming session with the project team is necessary but nowhere near sufficient. Multiple techniques must be layered to achieve adequate coverage. 2. Confusing risks with issues. An "issue" is something that has already occurred and requires resolution. A "risk" is an uncertain future event. Mixing them in the identification process creates register contamination. 3. Identifying threats but ignoring opportunities. uncertainty-management sources emphasise that often an RMP is particularly successful because the process of generating responses to threats leads to the identification of important opportunities with implications well beyond the original uncertainty. 4. Using checklists as the sole identification method. Checklists can provide false assurance of completeness. They are most dangerous when they are treated as exhaustive rather than as prompts. 5. Failing to identify responses alongside sources. In mature practice, identification of at least one assumed response for each source should be a first-pass output. Deferring all response thinking until a separate "response planning" phase loses the creative momentum of identification. 6. Political filtering. The most dangerous risks are often the ones nobody wants to discuss — the programme director's pet assumption, the contractor's known but undiscussed capability gap, the regulatory change everyone hopes will not materialise. Effective identification requires psychological safety.

Key Takeaways

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Prepare scope and evidence is defined, owned, evidenced and linked to the relevant project decision.
Check 02Select diverse participants is defined, owned, evidenced and linked to the relevant project decision.
Check 03Generate risks through multiple lenses is defined, owned, evidenced and linked to the relevant project decision.
Check 04Structure and challenge records is defined, owned, evidenced and linked to the relevant project decision.
Check 05Assign follow-up and ownership is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

NEXT LESSON →Environmental Scanning for Project RiskGuide · RiskScenario Planning for Project RiskGuide · RiskCognitive Bias and Risk Blind SpotsGuide · RiskRisk Breakdown Structures and Effective Risk StatementsGuide · Risk