SE Workspace

Risk register

What can go wrong, how likely, and how bad. Severity = probability × impact. Required artifact in ISO 15288 / IEC 62304 / ISO 14971.

10 risks total. 1 critical + 5 high active.
Probability × Impact heatmap
P5
P411
P3222
P22
P1
I1I2I3I4I5
← Impact
criticalhighmediumlow

Risk register (sorted by severity)

IDTitlePISeverityStatusOwner
R-001Fake / bot profiles erode user trust4416 · criticalanalyzedTrust & Safety Lead
R-002Match algorithm demographic bias3515 · highidentifiedML Engineer
R-005Under-18 user bypasses age verification3515 · highidentifiedTrust & Safety Lead
R-006ML training data contains PII3412 · highanalyzedML Engineer
R-009Key-person dependency on single ML engineer3412 · highidentifiedFounder / CEO
R-003Data breach exposing private messages2510 · highanalyzedBackend Engineer
R-004Apple App Store rejection on IAP rule2510 · highmitigatediOS Developer
R-007Twilio SMS costs explode during viral growth339 · mediumacceptedBackend Engineer
R-010EU DSA non-compliance — algorithmic transparency339 · mediumidentifiedLead GDPR Supervisory Authority (Irish DPC)
R-008Competitor launches values-matching feature428 · mediumidentifiedProduct Manager