1) Why AI principles matter in risk and issue management
Applying AI in projects creates both value and exposure. Principles such as transparency, accountability, reliability and fairness help guide safe and responsible adoption of AI, ensuring teams can explain how an AI-assisted assessment was produced, verify accuracy, and avoid bias (NIST, 2023). Privacy and security principles further ensure sensitive information is protected, aligning with the requirements of UK GDPR and broader data protection good practice (Information Commissioner’s Office, 2021). These principles reflect established risk management guidance, which emphasises using reliable information sources, governance controls and proportionality when assessing and responding to risks (ISO, 2018; Association for Project Management, 2019). In practice, this means recording prompts, assumptions, sources and limitations, and submitting AI-informed risk outputs through formal assurance routes before decisions are taken (APM, 2019).
2) From uncertainty to action: Risks vs issues
Uncertainty manifests as risks—events that might happen—and issues—events that have already occurred (APM, 2019). AI can scan documents, lessons learned and environmental signals to highlight candidate risks, while automated monitoring can flag emerging issues earlier than traditional mechanisms (NIST, 2023). AI suggestions should always be treated as leads: validate them with subject matter experts, quantify likelihood and impact, and assign owners to monitor progress within a structured review cycle (ISO, 2018). For issues, the project team should capture the root cause, immediate containment actions and long-term corrective actions, updating related risks to prevent recurrence (APM, 2019). A clear audit trail must be kept for every AI-derived entry to ensure transparency and defensible decision-making (NIST, 2023).
3) Positive risk management: threats and opportunities with TARA and SEER
Positive risk management means managing both threats and opportunities. The TARA approach supports balanced consideration by tracking threats and rapid opportunities alongside mitigations, fallback strategies and exploitation actions (APM, 2019). Pairing TARA with SEER, which examines Stakeholder, Ethical, Environmental and Regulatory factors, ensures that AI-generated suggestions are compliant, ethical and acceptable to stakeholders (NIST, 2023; UK Government, 2020). For example, AI might identify an opportunity to automate testing to reduce cycle time; the SEER analysis would help assess fairness, regulatory conditions, environmental effects and stakeholder impact before approval (Information Commissioner’s Office, 2021). Both threats and opportunities must be logged in the risk register and RAID log with KPIs, ownership and monitoring built in (ISO, 2018).
4) Using AI across the risk lifecycle
Identification: AI can analyse contracts, requirements, non-functional constraints, supply chain information and lessons learned to classify threats and opportunities, mapping them to scope, time, cost, quality, benefits and safety (APM, 2019).
Assessment: Project teams can request AI-generated rationales for likelihood, impact and assumptions, while also requiring confidence levels and evidence references to support validation (ISO, 2018).
Treatment: AI can propose alternative response strategies, avoid, reduce, transfer, accept for threats, and exploit, enhance, share, accept for opportunities, sometimes with indicative costings or scenario variations (UK Government, 2020).
Monitoring and control: AI can help develop early warning indicators, leading metrics and trigger points that integrate with project governance cycles (NIST, 2023).
Communication: AI can draft clear summaries for steering packs and stakeholder updates, but outputs must be validated and aligned with project governance (APM, 2019).
All stages require human review and approval before changes enter baselined documents (ISO, 2018).
5) Data protection, security and ethics
AI must be used responsibly, especially when handling data. Personal or confidential information should not be entered into AI tools without a lawful basis and appropriate safeguards (Information Commissioner’s Office, 2021). Privacy-preserving techniques such as redaction and synthetic examples should be used. Teams must evaluate model limitations and potential biases, ensuring that value judgements are not delegated to AI (NIST, 2023). High-risk contexts, such as safety critical or fairness sensitive decisions, should require multi-person review. Version control for prompts and outputs is essential to support audit, compliance and traceability (APM, 2019).
6) Linking to project artefacts: Risk Register and RAID
AI-generated insights should feed into a unified source of truth. A risk register should include unique IDs, causes, events, consequences, controls, owners, review dates and RAG ratings (APM, 2019). Issues should be captured in a RAID log with actions, ownership, due dates and statuses. Where AI has suggested a risk or issue, the project should record the prompt, date, AI model used, confidence indicators and human validation outcome (NIST, 2023). Tracking KPIs and residual exposure enhances assurance and strengthens oversight (ISO, 2018).
7) What to avoid
Do not insert unvalidated AI outputs into governance documents (NIST, 2023). Do not treat AI confidence scores as factual reliability indicators. Risk appetite statements and sign off decisions must remain with senior leadership (APM, 2019). Avoid vague entries that lack triggers, owners or measurable responses, as these weaken governance and increase exposure (ISO, 2018).
Action Point
Copy one of the prompts below and generate an AI‑assisted risk list for your current project. Validate with two stakeholders, classify items as threats or opportunities using TARA, assess SEER implications, and record accepted items with owners in your risk register and RAID. Store the AI prompt, output, decisions and evidence, then take your updates through formal governance at the next review.