Document Details
Purpose
This register identifies operational, data, security, adoption, and delivery risks together with their impacts, controls, mitigations, and ownership.
View or Download
Document Preview
Risk Register
| ID | Risk | Cause | Impact | Likelihood | Mitigation | Owner | Status | Evidence Quality |
|---|---|---|---|---|---|---|---|---|
| RISK-001 | Operational counts may be mistaken for finalized accounting inventory. | Inventory counts are live and no finalization process exists. | Incorrect financial reporting or audit confusion. | Medium | Label operational counts clearly; design receiving/accounting states separately. | Inventory / Finance stakeholder | Open | Observed/Inferred |
| RISK-002 | Invoice placement may be mistaken for receiving or invoice approval. | Current placement seeds count rows but is not accounting. | Bad cost history or premature financial reliance. | Medium | Add explicit state names and UI copy; defer accounting posts. | Inventory / Finance stakeholder | Open | Observed |
| RISK-003 | Vendor/category preferences may route items to wrong vendors. | Category-level vendor rules cannot handle item-level vendor splits. | Poor purchase planning or missed vendor source. | High | Add item/catalog-line vendor resolution. | Purchasing stakeholder | Open | Observed |
| RISK-004 | Temporary each conversion assumptions may corrupt item truth if persisted later. | Inventory needs temporary operational bridges for count coverage. | Bad recipe scaling, inventory coverage, or purchasing math. | Medium | Keep temporary conversions preview-only; store vendor/pack assumptions in inventory context. | Product / Inventory | Mitigated by current rule | Observed |
| RISK-005 | Analytics may consume unstable contracts. | Inventory/purchasing/cost contracts are not stable. | Misleading reports and rework. | Medium | Keep Analytics deferred; version downstream contracts. | Analytics stakeholder | Open | Observed |
| RISK-006 | Mock auth may be used beyond MVP. | Current role system is session-backed development auth. | Security and accountability gaps. | Medium | Define production identity/access requirements before deployment. | Admin / Technical owner | Open | Observed/Inferred |
| RISK-007 | Single large route module may become difficult to govern. | src/app.py owns many route groups as product scope grows. |
Higher change coupling and review difficulty. | Medium | Continue service/query separation; consider route modularization only when it reduces real complexity. | Technical owner | Monitor | Inferred |
| RISK-008 | Catalog review workload could become too broad. | Production data may include thousands of items. | Operator fatigue and abandoned review process. | Medium | Keep default review demand-driven; reserve scope=all for audit/debug. |
Inventory owner | Mitigated by current design | Observed |
| RISK-009 | No-count-row demand gaps may hide shortages. | Planning currently needs expansion beyond counted items. | Missed purchases or production shortages. | High | Implement roadmap item for uncounted upcoming base-food needs. | Inventory / Production | Open | Observed |
| RISK-010 | Requirements inferred from prototype behavior may not match stakeholder intent. | Draft requirements have not completed stakeholder validation. | Wrong product priorities or over-formalized MVP behavior. | Medium | Validate requirements and future-state priorities with stakeholders. | Product owner | Open | Inferred |
| RISK-011 | The prototype may be mistaken for the current operating state. | Current-state evidence is limited, while prototype behavior is documented in detail. | Gap analysis may compare the prototype to itself and obscure why the project exists. | Medium | Define current state through operating limitations and treat the prototype as future-state evidence. | Product owner / BA | Mitigated | User-provided |
| RISK-012 | Future-state validation may lack real corporate examples. | The current analysis has examples of missing capabilities but not specific source recipes, menus, or production records. | Prototype may solve generic problems without proving it handles high-value corporate cases. | Medium | Validate with representative corporate recipes, sub-recipes, hotel-pan scenarios, menu cycles, and production actuals. | Product owner / Operations | Open | User-provided/Inferred |
BA Alignment
- Activity areas: Evaluate solution; analyze strategy; manage requirements lifecycle.
- Techniques used: Risk analysis, document analysis, stakeholder analysis.