← All articles

14 July 2026 · By Douwe Pietersma

Why risk analyses usually come too late (and how to prevent it)

Risks are only identified once the plan is already fixed — when course-correcting is expensive. Here is how to break that pattern.

Risk management Project planning

Ask any project manager when the risk analysis for their last project was carried out, and the answer is almost always the same: after the plan was already finished. The scope was fixed, the schedule had been worked out, the budget had been requested, and then, as a final touch, came the mandatory risk section. Often the evening before the steering committee meeting.

That is not laziness. It is a structural pattern with identifiable causes. And once you know the causes, you can do something about them.

The risk section as a formality

In many organisations, the risk analysis is a mandatory part of the project proposal. That sounds like good news: after all, risk management is embedded in the process. In practice, it backfires: the analysis becomes a box-ticking exercise you complete to get through the gate.

The result is predictable. The risk table contains generic entries ("insufficient capacity", "scope expansion", "dependency on suppliers") with a probability, an impact and a mitigation measure that nobody ever reads again. The analysis is not there to improve the plan, but to get the plan approved.

And that is precisely the problem: a risk analysis that can no longer change the plan is not an analysis but a ritual.

Why we do it too late: two cognitive traps

Anchoring: the plan has become the reference point

As soon as a plan is on paper, the psychology changes. The plan is no longer one of several possible routes, it is the route. All new information is judged against that anchor. A risk that fundamentally challenges the plan ("perhaps this approach simply isn't feasible in twelve months") no longer feels like valuable input, but like an attack on weeks of work.

This is the well-known anchoring effect, and it explains why late risk analyses rarely lead to adjustments. The question has silently shifted from "is this a good plan?" to "which risks should we record for this plan?". Those are two fundamentally different questions.

Optimism bias: we are the exception

The second trap is more stubborn. Project teams know perfectly well that comparable projects overrun: the figures on public-sector IT projects are no secret. Yet they genuinely believe things will be different for them. After all, we have an experienced team, a committed sponsor, a proven approach.

This is not stupidity; it is how people work. Planning happens from the inside ("what do we need to do and how long does each step take?") rather than from the outside ("how did comparable projects fare?"). The inside view systematically underestimates, because you can only plan for what you can think of, and problems, by definition, tend to come from the corner you had not thought of.

The combination is toxic: anchoring ensures the plan is no longer up for discussion, and optimism bias ensures nobody loses sleep over that.

The moments when a risk analysis does add value

The good news: the alternative is not "more risk management" but better-timed risk management. There are a few moments when an analysis can actually change something.

1. Before the approach is fixed

The biggest risks rarely lie in execution; they lie in the chosen approach. One large tender or three small ones? Everything in-house or with an external partner? Big bang or phased? A risk session at this point, when there is nothing yet to anchor to, produces fundamentally different conversations than a session about a plan that is already locked down.

2. At the first complete draft of the plan

This is the classic moment, but with one crucial condition: the plan must still genuinely be able to change. So schedule the risk analysis well before the proposal deadline, not after it. A concrete tool: explicitly reserve time in the schedule for "processing the outcomes of the risk analysis". If that line item is missing, the analysis is apparently not intended to produce anything.

3. At every major phase transition

A risk profile is not a photograph but a film. The project you start is never the project you have halfway through. A brief recalibration at every phase transition (what has changed, which risks have lapsed, which have been added) keeps the analysis alive. Twenty minutes is often enough.

4. When something material changes in the environment

A new executive, a reorganisation that shifts the landscape, a supplier being acquired, upcoming legislation. Think of a municipal IT project where new privacy legislation comes into force halfway through: anyone who only looks at the risks at the next scheduled report is months too late.

Practical checklist: risk analysis on time

If you want to break the pattern, use this checklist:

The essence

A risk analysis is not a document but a decision moment. Its value lies not in the table, but in what you do differently because of it, and that is only possible if there is still something different to be done. Those who schedule the analysis while the plan can still move get more out of it than those who invest ten times the effort once everything is already fixed.

Want a fresh, unbiased second opinion on your project plan before it goes to the steering committee? RisicoRadar scans your plan for risks across five categories within minutes, precisely at the moment when you can still act on them.

Want your project plan scanned?

Upload your project plan and receive an AI risk analysis across 5 categories with concrete recommendations within a minute.

Try RisicoRadar