Ko ia kāhore nei i rapu, tē kitea
He who does not seek will not find
Risk mitigation is how you identify what could go wrong and put steps in place to reduce the impact.
At Level 3, your risks should come from your proposal and research (scope, requirements, tools, users, and wider implications). You are not trying to eliminate all risk - you are showing that you can plan realistically and respond if issues arise.
Use these as ideas. Only include risks that apply to your project.
Time / workload risk
Scope creep risk
Technical / functionality risk
Quality risk (design consistency, readability, performance)
Access risk (equipment/software, files, accounts)
Factors outside your control (illness, absences, school events)
Cost/financial risk (assets, hosting, subscriptions)
Legal/IP risk (copyright, licensing, attribution)
Privacy/ethics risk (data, consent, representation, harm)
Write your risks and mitigations. Choose at least 3–5 relevant risks for your project.
Use the Risk → Impact → Likelihood → Mitigation → Early warning signs → Backup plan structure above.
For each risk, write:
Risk: What could go wrong?
Impact: What would happen if it did? (time, quality, user experience, safety, compliance)
Likelihood: Low / Medium / High
Mitigation: What will you do to prevent/reduce it? (specific actions)
Early warning signs: How will you know this risk is starting to happen?
What I’ll do if it happens: Your backup plan / adjustment
Risk: I add too many features and don’t finish the core outcome.
Impact: Incomplete outcome and lower quality testing/polish.
Likelihood: Medium
Mitigation: Lock MVP; keep a “nice-to-have” list; weekly scope check against requirements.
Early warning signs: I’m spending time on extras before the core loop works.
If it happens: Cut features back to MVP and focus on finishing + testing.
Risk: Using unlicensed music/images/fonts and not being able to publish.
Impact: Outcome can’t be shared; breaches legal/IP requirements.
Likelihood: Medium
Mitigation: Use original or licensed assets; keep a credits list as I go; check licences before downloading.
Early warning signs: I can’t clearly explain where an asset came from.
If it happens: Replace assets with royalty-free/original versions and update credits.
Before you move on, check risks for:
✔️ I have identified 3–5 risks that genuinely apply to my project
✔️ Each risk explains the impact (what it affects and why it matters)
✔️ Each risk includes a real mitigation (specific actions, not vague promises)
✔️ I included likelihood (Low/Medium/High)
✔️ I included early warning signs and a backup plan
✔️ My risks connect to my scope, requirements/specs, and wider implications
✔️ At least one risk relates to quality (testing, usability, accessibility, performance)
✔️ If relevant, I included an IP/privacy/ethics risk