Drive has 700+ articles for digital transformation leaders written by StarCIO Digital Trailblazer, Isaac Sacolick. Learn more.

While agile and Scrum have many ceremonies, artifacts, and tools, a risk registry is not a standard one. Why is that?

Agile Risk Registry

Keeping teams in focus addresses many of the risks in releasing innovations that plagued IT teams in the pre-agile world and using waterfall project management. Scrum is really good at helping teams focus on a small window of priorities (the backlog) delivered in a short timeframe (a sprint). Agile is now a de facto standard and used in software development, low-code / SaaS, AI, data science, marketing, IT ops, and many other initiatives where changing requirements, technological implementation challenges, and fast customer feedback are the norm.

Scrum focuses on the happy path

Scrum mitigates short-term risks through its team structure, ceremonies, practices, and tools. Here’s a summary of how Scrum helps teams stay in focus sprint to sprint.

 Teams following Scrum and collaborating efficiently find ways to meet their sprint commitments and improve team velocity.

Meeting team sprint commitments isn’t good enough

Meeting sprint commitments, gaining stakeholder satisfaction at sprint reviews, and improving velocity are table stakes. What Scrum doesn’t fully address is whether

  • Releases are on scope and deployed reliably +
  • Customers and end-users received training, are adopting the new capabilities, are satisfied with the improved experiences, and ideally ecstatic with the impacts +
  • Days after the deployment, is the product performing reliably, securely, and scaling as required +
  •  Are the targeted business outcomes achieved +
  • Is the feedback and data collected being used to drive the next set of priorities +
  • Has new technical debt been identified, backlogged, and prioritized +
  • Are other technical, security, operational, and data concerns being addressed +

All of these questions amount to risks, unknowns, and concerns. The challenge is whether agile teams are discussing and formalizing plans around them. Is there a venue for architects, security, data governance, and other experts to raise risks and concerns? Are risks ranked, remediations debated, and solutions prioritized?

Scrum doesn’t have a formal ceremony for discussing release, operational, or technology risks. The most commonly used agile tools, including Jira and Azure DevOps, don’t have out-of-the-box risk registries.

What I have found across most StarCIO clients is that they don’t have a process to manage agile delivery risks, or select teams are cataloging risks in spreadsheets.

What is an agile risk registry?

An agile risk registry is an artifact from a conversation around a team’s risks, issues, and concerns. The scope of risks includes meeting business objectives, adherence to technology standards, implementation uncertainties, and concerns about quality, safety, security, or other operational impacts.

Agile teams following StarCIO’s release management guidelines typically hold three release-level meetings for major releases. Discussing risks should be on the agenda at each of these meetings, and updating the risk registry is a key deliverable.

A risk registry typically captures

  • The date when the risk was captured
  • A title, description, and one or more categories around the risk
  • An owner is assigned clearly defined responsibilities
  • A ranking score, which can be captured as a probability of occurrence (1-10, 10 being the highest) and a business impact score (1-10, 10 being the highest). The ranking is calculated by multiplying probability by business impact, yielding a score that can be used to prioritize remediation.
  • A high-level remediation plan, or a link to a document or wiki page with a more detailed plan.
  • A status field, which can be a simple transition from Identified à Remediation in progress à Risk addressed.

Agile risk registry implementation options

Now, there are many options for creating a risk registry. I’m opposed to using spreadsheets because they don’t provide lineage and identify when risks change. They may be easy for agile teams to use, but pose greater challenges for product managers, delivery leaders, and Digital Trailblazers to monitor across all or groups of teams. If you are going to use a spreadsheet, then see this risk registry template, which you can download.

But there are better options.

StarCIO’s simple approach to developing an agile risk registry

Existing solutions might work for your organization, but I offer an alternative that’s easy to implement. My approach

  • Focuses on the remediation and not just the risk.
  • Makes it easy for teams to record risks and assign context.
  • Simplifies tracking of how well agile teams working in product families, platforms, or across the organization record and remediate risks.
  • Requires add-on components and capabilities that admins will likely already have in place and probably need for other workflow needs.

My approach requires a basic understanding of StarCIO’s Agile Planning Guides. In the guides, we separate two kinds of work item types:

  • Epics and Features are containers for delivering capabilities, but the work isn’t performed under these two work types.
  • User Stories are where the work gets done. In StarCIO Agile, we introduce several other custom work types.

StarCIO’s implementation of a risk registry

Below is StarCIO’s recommended implementation of an agile risk registry.

  • Risks are a custom work item type. They are similar to Epics and Features in that they capture a goal (addressing a risk) and not the work to address it.
  • Define custom fields for capturing risk, including:
    • Probability of occurrence (numeric)
    • Business impact (numeric)
    • Remediation plan (URL)
    • Ranking Score (numeric)
  • The Ranking Score should be a calculated field, which has several implementation options:
    • Azure DevOps also doesn’t support calculated fields, but Power Automate can be used to accomplish this task.
    • Zapier can also perform this automation on Jira or Azure DevOps.
  • Admins can elect to use an out-of-the-box workflow to manage status like To Do à In Progress à Done, or customize the status levels I suggested, Identified à Remediation in progress à Risk addressed.
  • Risks are formally added and discussed during release meetings, but as a work item type, they can be added by anyone at any time.  
  • As Risk is now a work type, it can be used to link user stories and other work items used to perform remediation work.  
  • Risk is also easy to report on;
    • It’s on the backlog, so agile teams can’t ignore it.
    • A full risk registry across teams can be built using Jira’s JQL or Azure DevOps Queries.
    • More dynamic dashboards can be created by connecting Tableau or Power BI.

Use extendable components for configurations

You can argue that the work to create the Ranking Score no longer makes this a “simple approach.” But the tools I’ve recommended are all commonly used for other tasks in Jira / Azure DevOps. It’s reasonable to assume that admins on these tools have automation or dynamic field solutions they already use.

Feel free to reach out if you want to learn more about StarCIO’s release management guidelines.

Published on:

Leave a Reply


StarCIO

My company, StarCIO, provides leadership, learning, and advisory programs for companies looking to accelerate delivering business value from digital transformation. Contact me if you’d like to learn more about partnering opportunities.


Isaac Sacolick

Join us for a future session of Coffee with Digital Trailblazers, where we discuss topics for aspiring transformation leaders. If you enjoy my thought leadership, please sign up for the Driving Digital Newsletter and read all about my transformation stories in Digital Trailblazer.


Coffee with Digital Trailblazers hosted by Isaac Sacolick

Digital Trailblazers! Join us Fridays at 11am ET for a live audio discussion on digital transformation topics:  innovation, product management, agile, DevOps, data governance, and more!


Join the Community of StarCIO Digital Trailblazers

About Drive

Drive Agility, Innovation, Transformation

Drive is the blog for digital transformation leaders brought to you by StarCIO and Isaac Sacolick.

Agility, Innovation, and Transformation are the three primary digital transformation core competencies that every StarCIO Digital Trailblazer must champion in their organizations. Learn more About Drive.


About the StarCIO Digital Trailblazer Community

StarCIO Digital Trailblazer Community

Revolutionizing traditional learning, networking, and advising experiences.

Visit the community


About StarCIO

StarCIO

About Isaac Sacolick

Isaac Sacolick

Author, 1,000+ articles, keynote speaker, Chief StarCIO Digital Trailblazer. Full bio


Driving Digital Newsletter

Driving Digital Newsletter

StarCIO Guides

StarCIO Agile Planning Guides

Digital Trailblazer

Digital Trailblazer by Isaac Sacolick

Driving Digital

Driving Digital by Isaac Sacolick

Driving Digital Standup

Driving Digital Standup

Coffee with Digital Trailblazers

StarCIO Coffee With Digital Trailblazers

Recognition

InfoWorld 2025 Judge
InfoWorld Technology of the Year 2024 Judge
Thinkers360 Top 10 in IT Leadership
Thinkers360 Top Agile Thought Leader
Thinkers360 Top DevOps Leader
Thinkers360 Top in Digital Transfomation
Thinkers360 Top in Analytics
Thinkers360 Top in Product Management

Discover more from StarCIO Digital Trailblazer Community

Subscribe now to keep reading and get access to the full archive.

Continue reading