Skip to main content

The Importance of a RAID Log from a Programme Sponsor Perspective

A RAID log – risks, assumptions, issues and dependencies – is one of the few programme artefacts a sponsor should genuinely care about. Done properly it is the clearest single view of what could go wrong and who is dealing with it. Done badly it is a spreadsheet nobody opens.

Why it matters from the sponsor’s seat

Risks. Identified early enough to mitigate rather than absorb, with everything visible in one place and mitigation progress trackable.

Assumptions. Documented and revisited, so they can be tested as the programme moves rather than discovered to be wrong at go-live. Understanding which assumptions carry weight is what makes contingency planning possible.

Issues. Logged as they arise, assigned to a named person, and resolved rather than discussed.

Dependencies. Identified inside and outside the programme, so a delay elsewhere is assessed for impact rather than arriving as a surprise.

What each entry needs

Risks: description, potential impact, likelihood, mitigation plan, owner.

Assumptions: description, consequence if it proves false, the date it will be validated, owner.

Issues: description, effect if unresolved, priority, resolution plan, owner.

Dependencies: description, what happens to the programme if it is not met, due date, owner.

Every category ends with an owner. That is not administrative tidiness – an entry without a named owner is a note, not a control.

What a sponsor should look for

  • Completeness and clarity. Entries complete, described without ambiguity.
  • Regular updates. A log reflecting last quarter’s position is worse than none, because it looks like control.
  • Ownership. Every entry owned, and owners actually held to it.
  • Realistic plans. Mitigation and resolution plans that are actionable, and revised as things change.
  • Prioritisation. Ranked by impact and likelihood, so attention goes where it matters rather than to whatever was logged most recently.

What good practice looks like

  • Regular review meetings with key stakeholders present, not a log updated privately before a board.
  • Integration with other tools – dashboards giving real-time visibility rather than a document someone remembers to circulate.
  • Scenario planning for high-impact risks, with contingency worked out before it is needed.
  • Proactive identification – and rewarding people for surfacing risks early rather than treating it as bad news.
  • Transparency – accessible to everyone relevant, with changes communicated promptly.

That fourth point is the cultural one, and the one most often missed. If raising a risk is treated as pessimism, people stop raising them – and the log becomes a record of what everyone already knew.

Maintained properly, a RAID log gives a sponsor genuine control rather than the appearance of it.

See also Programme Health Check and Taking Over a Programme, or talk to us.

Further reading: Association for Project Management: what is risk management

Change Specialists Ltd
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.