Document Details
Purpose
This register identifies migration risks, potential impacts, preventive controls, mitigations, ownership, and current status.
View or Download
Document Preview
Risk Register
| ID | Risk | Cause | Impact | Likelihood | Mitigation | Owner | Status | Evidence quality |
|---|---|---|---|---|---|---|---|---|
| R-001 | Incorrect balance applied to wrong Lunchtab user. | Identifier collision, stale crosswalk, profile error, or manual edit mistake. | Financial inaccuracy and support burden. | Medium | Name validation, duplicate quarantine, match audit, manual reconciliation audit, reviewer approval. | Operations and profile owner | Open | Observed |
| R-002 | Import file created despite unresolved InitialBalances issues. | Missing or duplicate family codes, invalid amounts, or unmatched destination families. | Bad import or incomplete transfer. | Low | Application omits processed import on blocked run and writes exception evidence. | Operations | Mitigated technically; operational follow-up open | Observed |
| R-003 | Sensitive student or family data stored insecurely. | Generated reports contain names, identifiers, emails, family codes, and balances. | Privacy breach or policy violation. | Medium | Define approved storage, retention, and sharing rules; keep logs/manifests minimized. | Data/privacy owner | Open | Inferred |
| R-004 | Matching profile changes introduce unexpected behavior. | Profile rules, transforms, crosswalks, or fallback settings are changed without review. | Lower match quality or wrong matches. | Medium | Profile ownership, test packs, preview review, exported profile change log. | Profile owner | Open | Observed |
| R-005 | Staff skip manual reconciliation audit before InitialBalances. | Time pressure or unclear SOP. | Invalid manual amounts or risky edits reach downstream workflow. | Medium | Runbook and required audit-control checkpoint. | Operations lead | Open | Inferred |
| R-006 | Candidate report is treated as final decision. | Advisory report ranks possibilities but cannot know staff approval context. | Wrong manual resolution. | Medium | Training, checklist language, reviewer approval for ambiguous candidates. | Operations | Open | Observed |
| R-007 | Source export schema changes break workflow. | Odin or Lunchtab changes column names, order, file encoding, or export shape. | Validation failures or delayed production run. | Medium | Validation errors, sandbox updates, release maintenance. | Technical maintainer | Open | Observed |
| R-008 | Result folder partially published. | Failure during output generation. | Staff may use incomplete evidence. | Low | Staging folder and atomic rename behavior. | Technical maintainer | Mitigated | Observed |
| R-009 | Audit-control totals fail unexpectedly. | Decimal parsing, malformed data, logic defect, or unexpected source values. | Run failure and loss of confidence. | Low | Tests, control-total failure raises error, blocked evidence retained where applicable. | Technical maintainer | Mitigated technically | Observed |
| R-010 | Installer or release issue disrupts operations. | Packaging dependency, Windows runtime, upgrade issue. | Staff cannot run app during migration window. | Medium | Release script, smoke test, installer checklist, checksum, clean Windows testing. | Technical maintainer | Open | Observed |
| R-011 | No longitudinal metrics for realized benefit. | Per-run summaries are not aggregated. | Stakeholders cannot quantify savings or quality trends. | High | Production metrics log and periodic review. | Business owner | Open | Inferred |
| R-012 | Manual source/destination file handling remains error-prone. | File-based workflow relies on selecting correct exports and imports. | Wrong file processed or imported. | Medium | File hashes, source names, timestamped folders, SOP naming checks. | Operations | Open | Observed |