Finding project risks before they find you: workshops, structured prompts, assumptions, scanning and blind spots

You cannot manage a risk nobody identified. How to run risk workshops that find more than the obvious, use structured prompts, test assumptions and interfaces, and correct for blind spots.

A manufacturer is installing a powder coating line in a newly leased building next door. The project team holds a risk workshop. In an hour, they list 25 risks: equipment delivery delays, installation problems, commissioning faults, a shortage of trained operators. All sensible, all technical, all things the team already knew. Three months later, the project stalls on something nobody listed: the pretreatment stage discharges wastewater, and the local water authority’s trade waste approval takes months. Then the landlord objects to the exhaust stack through the roof.

Risk management cannot deal with risks nobody has identified. Yet identification is often the weakest part of the process. Workshops collect what the people in the room already worry about, generic checklists miss what is specific to the project, and the risks that cause the most damage tend to sit in the gaps: between disciplines, between organisations, outside the project’s boundary or in assumptions so familiar that nobody questions them.

This article explains how to identify project risks systematically: preparing properly, running workshops that go beyond the obvious, using structured prompts and breakdown structures, testing assumptions and interfaces, scanning the environment outside the project, looking for opportunities as well as threats and correcting for the biases that hide risks in plain sight. It is general information for project managers, engineers and owners.

Identification is search, then structure

Identification involves two tasks:

  • Search: finding the sources of uncertainty that could affect the project’s objectives, and the possible responses.
  • Classify: organising what is found so that patterns, shared causes and gaps become visible.

The aim is a shared understanding of what could affect the project and what could be done about it. That includes opportunities, uncertain events that would help the project, as well as threats.

It helps to think in three layers: sources of uncertainty, the responses available to them, and secondary sources, the new risks that a response itself creates. Moving a delivery earlier to protect a date, for example, may create a storage and damage risk.

Prepare before the workshop

A workshop is only as good as its preparation:

  • Define the scope and objectives the risks relate to: the finish date, the budget, quality and performance targets, safety and benefits.
  • Gather evidence: the work breakdown structure, schedule, cost estimate, contracts, lessons from similar projects, incident and defect records.
  • List the assumptions the plan depends on.
  • Map the interfaces: with suppliers, landlords, utilities, regulators, other projects and the operating business.
  • Choose diverse participants: not only the project team but also operators, maintenance, safety, finance, procurement, key suppliers and at least one person from outside the project who will ask naive questions.

A simple workshop agenda

A two to three hour workshop for a medium-sized project might run like this:

  1. Purpose and objectives (10 minutes): what the project must achieve and what the workshop will produce.
  2. Silent individual generation (15 minutes): each person writes risks and opportunities on cards or in a shared document, one per card, without discussion.
  3. Share and cluster (30 minutes): read out the cards, group them by category and merge duplicates.
  4. Structured prompts (30 minutes): work through the assumptions list, the interface map and the prompt categories that have few or no cards.
  5. Pre-mortem (20 minutes): imagine the project has failed and list the reasons.
  6. Initial assessment and ownership (30 minutes): a quick view of likelihood and impact for each, and a named person to develop each significant risk further.
  7. Close (10 minutes): confirm actions and when the register will next be reviewed.

The facilitator’s main jobs are to keep generation separate from evaluation, to make sure quieter people are heard and to push into the categories nobody has touched.

Use several lenses, not one

Different techniques find different risks. Using several reduces the chance of a blind spot.

Objective-led review. Take each key objective in turn and ask what could affect it, activity by activity through the plan. Start with the most important objective, often the finish date or budget, and work outwards.

Brainstorming, well run. Brainstorming is the most used and most misused technique. It works with a skilled facilitator, a clear question, a rule that ideas are not evaluated while they are being generated and a structure that stops the loudest voices dominating. Asking people to write risks individually before sharing them, then discussing, produces more and more varied ideas than open discussion alone.

Work breakdown walkthrough. Step through each deliverable and work package and ask what could go wrong, or better than expected, in producing it.

Prompt lists and checklists. A prompt list of categories, such as technical, commercial, regulatory, people, supply, site, environment, stakeholders and interfaces, helps people think more broadly. Checklists from previous projects capture lessons the organisation has already paid for. Their limitation is that they cover only what has happened before; they should start a conversation, not end it.

Assumptions and constraints analysis. Take each assumption and ask: how confident are we, and what happens if it is wrong? Every assumption that matters and is uncertain is a risk.

Interface analysis. Look at every point where the project depends on someone or something it does not control: approvals, utility connections, supplier deliveries, other projects, customer inputs. Interfaces are where many of the most damaging risks sit.

Pre-mortem. Ask the group to imagine that the project has failed badly a year from now, and to write down why. Imagining a failure that has already happened makes it easier for people to voice concerns they would otherwise keep to themselves.

Expert interviews and lessons learned. Talk individually to people who have done similar work. Some will share concerns privately that they would not raise in a group.

Organise with a risk breakdown structure

A long list of risks becomes useful when it is organised. A risk breakdown structure is a hierarchy of risk categories, similar to a work breakdown structure for work. Common ways of categorising include:

  • By objective or constraint: time, cost, quality, scope, safety, benefits.
  • By source: technical, commercial, organisational, external, people.
  • By business area: market, customer, regulatory, financial.
  • By technical domain: design, manufacture, installation, testing, operation and maintenance.
  • By interface and integration: dependencies on other projects, suppliers and systems.

Categorising often reveals that many risks share a root cause, such as a shortage of a particular skill, which can then be treated once rather than many times. It also shows empty categories, which may be genuinely low risk or may be where nobody looked.

Write risks that point to action

Each risk should be recorded clearly enough to analyse and act on. A useful form links a cause, an uncertain event and its effect on objectives: because of a cause, an event may occur, which would lead to an effect. One risk per record, with an owner. The making a risk register change decisions article covers writing risks that lead to action and keeping the register useful.

Scan outside the project

Many of the risks that hurt projects originate outside them. Scan three layers:

  • The general environment: technological change, economic conditions such as prices, interest rates and exchange rates, political and legal changes, social and workforce trends, and natural events such as weather and climate. The project usually cannot influence these; it can only prepare and adapt.
  • The task environment: suppliers, customers, competitors, regulators, landlords, utilities and the local community. Relationships here run both ways, so the project can influence as well as be influenced.
  • The internal environment: capability, capacity, competing projects, management attention, finances and culture within the business itself.

Look forward, not back: what is changing that could affect this project during its life? Convert significant signals into monitored risks with clear triggers.

Look for opportunities too

Identification sessions naturally focus on threats. Ask explicitly what could go better than planned and how the project could take advantage: a supplier with spare capacity, a technology that could simplify the design, a grant or rebate, a chance to combine work with another project. The risk is also the opportunity you miss article explains why ignoring upside is itself a risk.

Correct for blind spots

The risks most likely to surprise a project are often not hidden by lack of information but by how people and organisations process it. Common blind spots:

  • Overconfidence: estimates and ranges that are too narrow, and too little allowance for things going wrong.
  • Anchoring: the first figure or idea mentioned shapes all the others.
  • Availability: recent or vivid events are overweighted, and unfamiliar ones underweighted.
  • Groupthink and conformity: people go along with the apparent consensus, especially when senior people have spoken.
  • Silos: each function sees its own risks. Engineers see technical risks, commercial staff see contractual ones and few see the risks between them.
  • Motivated reasoning: risks that would threaten a favoured project or a promised date are quietly discounted.
  • Normalisation: problems that have happened before without disaster stop being seen as risks.

Practical corrections include gathering individual input before group discussion, inviting a sceptic or outsider, asking senior people to speak last, deliberately considering extreme and systemic scenarios, recording dissenting views and reviewing what past projects actually experienced rather than what they planned.

Make identification continuous

Risk identification is not a single workshop at the start. Repeat it at stage boundaries, when the scope or plan changes significantly, when new suppliers or stakeholders join, and when warning signs appear. Short, focused reviews during delivery often find the risks that only become visible once work is under way.

A worked example

This is an illustrative example. An 80-person metal products manufacturer is installing a powder coating line, including a chemical pretreatment stage, curing oven and booth, in a newly leased building beside its existing factory. The project has a budget of about $1.6 million and a target start of production in nine months.

First pass. The initial project team brainstorm produces 25 risks, almost all technical: equipment delivery, installation, oven commissioning, operator training.

Broader preparation. The project manager lists the assumptions in the plan and maps the interfaces. The workshop is widened to include the safety coordinator, the finance manager, a maintenance technician, a coating line operator from a sister site, the equipment supplier’s engineer and the building’s property manager.

Several lenses. An objective-led review against the start-of-production date, a walkthrough of the work breakdown structure, an interface review and a pre-mortem together add 18 risks. Among them:

  • The pretreatment stage needs a trade waste agreement with the local water authority before discharging to sewer, which can take several months.
  • The landlord’s consent is needed for roof penetrations for the exhaust stack.
  • The gas supply upgrade depends on the network operator’s connection timeline.
  • Building and fire safety requirements for the oven may need specialist input.
  • Coating chemicals bring new storage and handling obligations.

Scanning and opportunities. An environmental scan flags rising gas prices, which leads the team to ask the supplier about heat recovery options, and long lead times on imported burner components. Opportunities include a state energy efficiency program that may part-fund heat recovery, and using the new line to bring a currently subcontracted coating job in-house.

Blind spots. Individual written input before discussion surfaces a concern from the operator that the planned booth layout makes colour changes slow, a risk nobody senior had considered.

Result. Trade waste, landlord consent and gas connection applications start in the first month instead of the fourth. The booth layout is revised before ordering. When the gas connection is confirmed six weeks later than hoped, the schedule absorbs it because the risk was already visible with a mitigation plan.

Applying this in an Australian business

  • Prepare with evidence: objectives, plans, assumptions and interfaces.
  • Invite diverse participants, including operators, suppliers and an outsider.
  • Use several techniques: objective review, work breakdown walkthrough, prompt lists, assumptions, interfaces and pre-mortems.
  • Gather individual input before group discussion.
  • Organise risks with a breakdown structure, and look for shared causes and empty categories.
  • Scan outside the project, including approvals from authorities and utilities.
  • Identify opportunities as well as threats.
  • Repeat identification at stage boundaries and when things change.

Where risk identification goes wrong

  • One brainstorm with only the project team.
  • Relying on a generic checklist.
  • Ignoring assumptions and interfaces.
  • Looking only inside the project.
  • Letting senior voices set the agenda.
  • Listing only threats.
  • Treating identification as a one-off.

Questions to ask before your next risk workshop

  • Which objectives are the risks being identified against?
  • What does the plan assume, and how confident are we in each assumption?
  • Where does the project depend on people or organisations it does not control?
  • Who is not in the room who should be?
  • What would we say went wrong if this project failed?
  • Which categories of our risk breakdown structure are empty, and why?
  • What opportunities could we take?

Bringing it together

You cannot manage a risk nobody has identified, and the risks that hurt most usually sit outside the obvious: in assumptions, interfaces, the environment around the project and the blind spots of the people planning it. Prepare with evidence, invite a diverse group and use several lenses, from objective-led review and work breakdown walkthroughs to assumptions analysis, interface mapping and pre-mortems. Organise what you find with a risk breakdown structure, scan outside the project, look for opportunities as well as threats and correct deliberately for bias. Then repeat the exercise as the project moves, because new risks appear as the work does.


Source: KEVOS editorial notes, drawing on earlier KEVOS project risk management handbooks on risk identification workshops and methods, risk breakdown structures and risk statements, environmental scanning and cognitive bias in risk decisions. The worked example is illustrative. This article is general information.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.