# Risk analysis — Method guidance

**Method:** `risk-analysis@1`
**Purpose:** Identify and assess risks to a defined outcome.
**Required inputs:** scope; objectives; available evidence
**Expected outputs:** risk register; likelihood; impact; mitigations

Apply every section below to the register before reporting the work done — a register with
unowned mitigations or unsupported ratings gives false confidence.

## Risk coverage

Identify risks across every relevant category for the full stated scope, not only the most
obvious one, and confirm the register addresses each named objective. A register with the same
evidence supporting every entry is a sign that a distinct category of risk went unexamined.

## Evidence basis

Record, for each entry in the register, the specific evidence behind its likelihood and impact
rating, rather than an unsupported number, so a reviewer can see why a risk was rated the way it
was. A rating with no cited evidence is a guess, not an assessment.

## Mitigation ownership

State, for every mitigation you propose, a specific owner and a concrete action, not a general
intention like "monitor the situation." A mitigation with no owner and no action is not a
mitigation.
