Ask any project manager when the risk analysis for their last project was carried out, and the answer is almost always the same: after the plan was already finished. The scope was fixed, the schedule had been worked out, the budget had been requested, and then, as a final touch, came the mandatory risk section. Often the evening before the steering committee meeting.
That is not laziness. It is a structural pattern with identifiable causes. And once you know the causes, you can do something about them.
The risk section as a formality
In many organisations, the risk analysis is a mandatory part of the project proposal. That sounds like good news: after all, risk management is embedded in the process. In practice, it backfires: the analysis becomes a box-ticking exercise you complete to get through the gate.
The result is predictable. The risk table contains generic entries ("insufficient capacity", "scope expansion", "dependency on suppliers") with a probability, an impact and a mitigation measure that nobody ever reads again. The analysis is not there to improve the plan, but to get the plan approved.
And that is precisely the problem: a risk analysis that can no longer change the plan is not an analysis but a ritual.
Why we do it too late: two cognitive traps
Anchoring: the plan has become the reference point
As soon as a plan is on paper, the psychology changes. The plan is no longer one of several possible routes, it is the route. All new information is judged against that anchor. A risk that fundamentally challenges the plan ("perhaps this approach simply isn't feasible in twelve months") no longer feels like valuable input, but like an attack on weeks of work.
This is the well-known anchoring effect, and it explains why late risk analyses rarely lead to adjustments. The question has silently shifted from "is this a good plan?" to "which risks should we record for this plan?". Those are two fundamentally different questions.
Optimism bias: we are the exception
The second trap is more stubborn. Project teams know perfectly well that comparable projects overrun: the figures on public-sector IT projects are no secret. Yet they genuinely believe things will be different for them. After all, we have an experienced team, a committed sponsor, a proven approach.
This is not stupidity; it is how people work. Planning happens from the inside ("what do we need to do and how long does each step take?") rather than from the outside ("how did comparable projects fare?"). The inside view systematically underestimates, because you can only plan for what you can think of, and problems, by definition, tend to come from the corner you had not thought of.
The combination is toxic: anchoring ensures the plan is no longer up for discussion, and optimism bias ensures nobody loses sleep over that.
The moments when a risk analysis does add value
The good news: the alternative is not "more risk management" but better-timed risk management. There are a few moments when an analysis can actually change something.
1. Before the approach is fixed
The biggest risks rarely lie in execution; they lie in the chosen approach. One large tender or three small ones? Everything in-house or with an external partner? Big bang or phased? A risk session at this point, when there is nothing yet to anchor to, produces fundamentally different conversations than a session about a plan that is already locked down.
2. At the first complete draft of the plan
This is the classic moment, but with one crucial condition: the plan must still genuinely be able to change. So schedule the risk analysis well before the proposal deadline, not after it. A concrete tool: explicitly reserve time in the schedule for "processing the outcomes of the risk analysis". If that line item is missing, the analysis is apparently not intended to produce anything.
3. At every major phase transition
A risk profile is not a photograph but a film. The project you start is never the project you have halfway through. A brief recalibration at every phase transition (what has changed, which risks have lapsed, which have been added) keeps the analysis alive. Twenty minutes is often enough.
4. When something material changes in the environment
A new executive, a reorganisation that shifts the landscape, a supplier being acquired, upcoming legislation. Think of a municipal IT project where new privacy legislation comes into force halfway through: anyone who only looks at the risks at the next scheduled report is months too late.
Practical checklist: risk analysis on time
If you want to break the pattern, use this checklist:
- Schedule the first risk session before the approach is final, not as an appendix to the final draft.
- Reserve processing time in the schedule. An analysis without time to act on the outcomes is a ritual.
- Use the outside view. Ask explicitly: how did the last three comparable projects in this organisation fare? What went wrong there?
- Invite an outsider. Someone with no stake in the plan sees risks the team can no longer see, precisely because of anchoring.
- Ask the killer question: "Suppose this project has failed a year from now. What happened?" This so-called pre-mortem bypasses optimism bias, because failure is the starting point rather than the taboo.
- Recalibrate at every phase transition, briefly but consistently. Make it a standing agenda item for the steering committee.
- Document what you did with the outcomes. Not as accountability, but as a test: if the answer is consistently "nothing", you are doing the analysis too late.
The essence
A risk analysis is not a document but a decision moment. Its value lies not in the table, but in what you do differently because of it, and that is only possible if there is still something different to be done. Those who schedule the analysis while the plan can still move get more out of it than those who invest ten times the effort once everything is already fixed.
Want a fresh, unbiased second opinion on your project plan before it goes to the steering committee? RisicoRadar scans your plan for risks across five categories within minutes, precisely at the moment when you can still act on them.