Why This Matters: The Most Consequential Phase
Every experienced project manager knows the axiom: you cannot manage a risk you have not identified. What fewer appreciate is just how consequential the identification phase truly is. Uncertainty-management sources put it bluntly — if sources and responses are not properly understood, any subsequent risk management can be a complete waste of resources.
In heavy engineering and defence contracting, this is not theoretical. A Tier-1 defence programme that fails to identify regulatory approval as a coupled technical-legal risk source during identification will discover the oversight during execution — when the cost of recovery is orders of magnitude higher. A manufacturing project that relies solely on a generic checklist will miss the site-specific interactions between weather, crane availability, and concrete curing schedules that drive the real schedule risk.
This article moves beyond the introductory treatment of PMBOK's "Identify Risks" process to examine the full toolkit of identification techniques, drawing on a widely used uncertainty-management framework's SHAMPU framework, the earlier process-based project risk model, the APM PRAM Guide, and practitioner templates from the requirements-focused checklist risk identification checklist.
What Is Risk Identification?
In SHAMPU terms, identification involves two specific tasks:
- Search — for sources of uncertainty and associated responses, employing a range of techniques
- Classify — to provide a suitable structure for defining sources and responses, aggregating or disaggregating particular issues as appropriate
The key deliverable is a clear, common understanding of the sources of uncertainty facing the project and what can be done about them. Crucially, SHAMPU insists that identification must surface opportunities alongside threats, and must identify at least one assumed response for each identified source — even if that response is simply "do nothing."
Sources, Responses, and Secondary Sources
A fundamental distinction in mature risk identification is the three-layer model:
| Layer | Definition | Example (Naval Shipbuilding) |
|---|---|---|
| Primary Source | An uncertainty that directly impacts a performance criterion | Specialist welding contractors may not be available when needed |
| Response | A proactive or reactive action to address the source | Pre-qualify and retain three alternative welding contractors |
| Secondary Source | New uncertainty created by the response itself | Alternative contractors may have lower quality standards, creating rework risk |
How It Works: The Identification Toolkit
Technique 1: The Structured Ponder Approach
A widely used uncertainty-management framework's recommended starting point is deceptively simple: ponder. Begin with the project's key performance criterion and systematically consider what could affect it, activity by activity. This is not casual reflection — it is a disciplined, individual analyst-level examination of the project activity structure defined in the SHAMPU Define phase.
The ponder approach begins with KLP issues — Key criterion, Level one, Primary issues — before expanding to secondary criteria and other Ws. Practical application: An analyst examining a defence vehicle prototype programme would start with the key criterion (delivery date), walk through each activity in the 20-activity strategic structure, and identify what could directly delay each one. Only after this first sweep would cost uncertainty, quality uncertainty, and stakeholder uncertainty be layered on.
Technique 2: Brainstorming Workshops
Brainstorming is the most widely used identification technique and the most frequently misapplied. Effective brainstorming requires:
- A skilled facilitator who manages group dynamics and prevents premature evaluation
- Real-time documentation of all ideas without filtering
- Separation of generation from evaluation — ideas are recorded, not judged
- Structured prompts that walk through project activities, the six Ws, and risk categories systematically
Technique 3: The Delphi Technique
The Delphi technique addresses brainstorming's social conformity weakness by collecting expert judgements anonymously and iteratively:
- Round 1: Each expert independently identifies risks and provides preliminary assessments
- Compilation: A facilitator aggregates and anonymises all responses
- Round 2: Experts review the aggregated list and revise their assessments in light of others' input
- Convergence: Repeated rounds continue until a stable consensus emerges Strengths: Eliminates groupthink, anchoring bias, and authority bias. Particularly valuable when experts are geographically dispersed or when political sensitivities make open discussion difficult. Limitations: Time-consuming, requires sustained expert engagement, and can lose the creative spark that face-to-face interaction generates.
Technique 4: Expert Interviews
Structured interviews with subject matter experts, past project managers, and task managers uncover "subtle" information that has not been documented. Uncertainty-management sources describe the risk analyst's role as someone "prepared to ask lots of dumb questions" — and note that sometimes the apparently dumb questions have no effective answers, revealing cracks that need serious attention.
Interview Protocol for Defence/Engineering Projects:
| Interview Element | Purpose |
|---|---|
| Walk through the WBS activity by activity | Surface activity-specific sources |
| Ask "what keeps you awake at night?" | Elicit tacit concerns not captured in formal documentation |
| Ask "what happened last time?" | Draw on historical project memory |
| Ask "who else should I talk to?" | Expand the identification network |
| Ask "what assumptions are you making?" | Surface hidden assumptions that may be invalid |
Technique 5: Checklist and Prompt List Analysis
Checklists are popular because they provide a structured, repeatable starting point. However, uncertainty-management sources offer a significant caution:
The distinction between a checklist and a prompt list is important:
| Tool | Purpose | Risk |
|---|---|---|
| Checklist | Exhaustive list of specific risks from previous projects | May constrain thinking to known risks; provides false assurance of completeness |
| Prompt List | Broad category headings that stimulate thinking | Less constraining but requires more expertise to use effectively |
A typical prompt list for heavy engineering might use these broad headings:
- Technical complexity and novelty
- Regulatory and approval processes
- Supply chain and procurement
- Weather and environmental conditions
- Resource availability and skills
- Stakeholder and political dynamics
- Contractual and commercial terms
- Interface management between work packages
The requirements-focused checklist Checklist Approach: The practitioner template from the project knowledge base demonstrates a comprehensive requirements-focused checklist covering requirements source, requirements stability, solution complexity, technology risk, and team capability. Each section poses specific diagnostic questions — for example, "Have requirements been jointly developed by the customer and the solution team?" This approach works well for IT and systems projects but must be adapted for heavy engineering contexts.
Technique 6: Assumptions Analysis
Every project plan rests on assumptions. Assumptions analysis systematically challenges these assumptions to determine what risks they conceal. PMBOK identifies four categories of assumption vulnerability:
- Inaccuracy — the assumption may be factually wrong
- Instability — the assumption may change over the project lifecycle
- Inconsistency — different assumptions may contradict each other
- Incompleteness — critical assumptions may not have been made at all Defence Example: A missile system development programme assumes that a specific composite material will be available from a single-source supplier at current pricing. Assumptions analysis would challenge: (1) Is there a second source? (2) What if export controls change? (3) Is the material specification stable or evolving? (4) Are there lead-time assumptions embedded in the schedule that conflict with procurement realities?
Technique 7: Diagramming Techniques
Visual methods for identifying causal relationships between risks include:
- Cause-and-Effect (Ishikawa/Fishbone) Diagrams — identify root causes of a risk event across categories (methods, machines, materials, manpower, measurement, environment)
- Flowcharts and Process Diagrams — trace the sequence of activities to identify failure points
- Influence Diagrams — show causal relationships, feedback loops, and decision points
- Cognitive Mapping — used for complex litigation and delay analysis
Technique 8: SWOT Analysis
SWOT analysis examines the project from the perspective of internal strengths and weaknesses alongside external opportunities and threats. While primarily a strategic planning tool, it serves as a useful cross-check during risk identification to ensure that both upside and downside uncertainties have been captured.
Technique 9: Documentation Reviews
Structured reviews of all project documentation — plans, assumptions, previous project files, contracts, specifications — can reveal inconsistencies and gaps that are themselves sources of risk. Uncertainty-management sources note that the quality of plans, as well as consistency between plans and requirements, can be direct indicators of risk.
The Five-Step Identification Sequence
Uncertainty-management sources recommend a structured five-step identification sequence within the SHAMPU Identify phase:
Step 1 begins with the simplest question: what could directly affect the key performance criterion (usually time or cost) at the activity level? This generates a first-cut list. Step 2 expands the aperture: what about other performance criteria (quality, safety, reputation)? What about the other Ws — who (contractor failures, regulator changes), what (design deficiencies), wherewithal (resource shortages), when (seasonal constraints)? Step 3 immediately pairs each source with at least one response. The "do nothing" response is acceptable as a placeholder, but proactive and reactive options should be generated wherever possible. Step 4 examines whether proposed responses create new uncertainties — the secondary source problem. Step 5 deploys the full range of techniques described above to elaborate and verify the completeness of the identification.
Classifying Risks: Wet Buckles and Dry Buckles
Uncertainty-management sources use an evocative example from the offshore energy sector pipe-laying to illustrate the critical importance of proper classification during identification:
- A dry buckle is a kink in the pipe — the pipeline can be pulled back onto the barge, the damaged section cut off, and laying continues with minimal time lost
- A wet buckle is a fracture that allows seawater to rush in — the pipe becomes too heavy, rips itself from the barge, and sinks to the ocean floor
Both are "buckles." But treating them as a single risk category would be catastrophically misleading. Dry buckles are minor productivity variations; wet buckles are project-threatening events requiring dedicated analysis and specific responses.
Pitfalls: Where Identification Goes Wrong
1. Stopping after brainstorming. A single brainstorming session with the project team is necessary but nowhere near sufficient. Multiple techniques must be layered to achieve adequate coverage. 2. Confusing risks with issues. An "issue" is something that has already occurred and requires resolution. A "risk" is an uncertain future event. Mixing them in the identification process creates register contamination. 3. Identifying threats but ignoring opportunities. uncertainty-management sources emphasise that often an RMP is particularly successful because the process of generating responses to threats leads to the identification of important opportunities with implications well beyond the original uncertainty. 4. Using checklists as the sole identification method. Checklists can provide false assurance of completeness. They are most dangerous when they are treated as exhaustive rather than as prompts. 5. Failing to identify responses alongside sources. In mature practice, identification of at least one assumed response for each source should be a first-pass output. Deferring all response thinking until a separate "response planning" phase loses the creative momentum of identification. 6. Political filtering. The most dangerous risks are often the ones nobody wants to discuss — the programme director's pet assumption, the contractor's known but undiscussed capability gap, the regulatory change everyone hopes will not materialise. Effective identification requires psychological safety.
Key Takeaways
- Risk identification involves two tasks — search (finding sources and responses) and classify (structuring them for analysis) — not merely listing risks in a register.
- Multiple techniques must be layered: ponder, brainstorm, Delphi, interviews, checklists/prompts, assumptions analysis, diagramming, SWOT, and documentation reviews.
- Sources must be paired with responses from the outset, and secondary sources arising from those responses must be explicitly identified.
- The wet buckle / dry buckle distinction illustrates the critical importance of proper classification — treating all sources as equivalent can be catastrophically misleading.
- A widely used uncertainty-management framework's five-step identification sequence (KLP issues → other criteria → responses → secondary sources → elaborate search) provides a structured approach that avoids the common trap of premature closure.
- Checklists are useful prompts but dangerous substitutes for genuine analytical thinking. Over-reliance on checklists is a hallmark of risk management immaturity.
