> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/delivery-governance/risk-and-issue-management.md).

# Risk and Issue Management

### Purpose

Risk and issue management ensures that threats to delivery are visible, owned, and actively managed.

### Risk

A risk is something that may happen and may affect delivery.

Risk records should include:

* description
* cause
* impact
* probability
* severity
* owner
* mitigation
* contingency
* status
* review date

### Issue

An issue is something that has happened and is affecting delivery.

Issue records should include:

* description
* impact
* owner
* priority
* action plan
* due date
* escalation route
* status

### Escalation

Escalate when:

* a risk exceeds tolerance
* an issue blocks delivery
* a customer dependency is not met
* a commercial decision is needed
* security approval is delayed
* supplier failure threatens delivery
* acceptance is disputed

### Operating Rule

Risks and issues must be reviewed regularly and not left as static records.
