Executive Summary
A RAID log is a record. It is not a risk management practice.
Most enterprise programs maintain a RAID log because a template says they should, then treat it as a compliance artifact rather than a decision-making tool.
Risks get logged, assigned an owner, and revisited only when they become issues.
This article introduces a practical approach to program risk management built around three habits: pre-mortems before execution, a living risk register reviewed on a fixed cadence, and mitigation plans with committed owners and dates rather than vague intentions.
It is written for Technical Program Managers, engineering leaders, and anyone accountable for programs where the cost of a surfaced-too-late risk is measured in quarters, not days.
By the end, you will have a repeatable way to convert a static log into an operating risk culture.
Coming Soon
Part 2 of the TPM Insights series is in progress.
It will introduce the RRO framework — Reveal, Register, Own — for building a real risk culture, including a pre-mortem workshop guide, a program risk register example, a case study, common mistakes, and a full risk management checklist.
What's Next
The next article in this series, Stakeholder Management for Engineering Leaders, covers how to map stakeholder influence and interest, run effective alignment workshops, and manage conflicting priorities across sponsors.
Enjoyed this article?
I write about technical program management, engineering transformation, platform engineering, and enterprise delivery. If this article resonated with you, connect with me on LinkedIn or explore more articles in the Insights section.