The program risk register as at February 5, 2024 — four months after Day 1, two weeks after the post-discovery re-baseline, and seven months before the planned TSA exit. Eighteen risks are open or tracked, four have closed, and three have already been realized and moved to issue management. This is a working document rather than a summary: it records what the program believed at this date, including what it had sized correctly and what it had not yet been able to measure.
Table of Contents
1. Risk, Issue, Assumption
| Category | Definition | Handled by |
|---|---|---|
| Risk | Might happen. Has a probability. | This register. Mitigated, transferred, avoided or accepted. |
| Issue | Has happened. Probability is 1. | Issue management. ⚠ A realized risk stops being a risk — leaving it in the register overstates future exposure. |
| Assumption | Believed true, not verified. If false, becomes a risk. | Tracked with a test date. See 1.1. |
| Dependency | Something outside the program's control that it needs | Tracked separately; escalated when the external party slips |
1.1 Assumptions that became risks
The Due Diligence Findings carried a register of matters that could not be assessed before closing. Each was an assumption with a test date. As those tests complete, the assumption either closes or converts into a risk with a score.
| Assumption at closing | Test | Outcome as at this date |
|---|---|---|
| Target vendor contracts assignable or novatable | Pre-close sweep | Closed Consents obtained; see R-04 |
| ACME platform absorbs target volume without re-architecture | Post-close load analysis | Closed Headroom confirmed |
| No regulatory condition restricting data location | Form A terms | ⚠ Converted A condition does apply — became R-07 |
| Target member data quality broadly as represented | Post-close profiling | ⚠⚠ Still open. Profiling in progress. Carried as R-01. |
2. Scoring
Exposure is probability against impact, with one deliberate departure from the usual method.
| Exposure | Meaning |
|---|---|
| Critical | Threatens a Charter rank 1 or 2 constraint — the TSA maximum or Day 1 operational integrity. ⚠ Assigned on impact regardless of probability. |
| High | Threatens the synergy commitment or a major milestone |
| Medium | Material cost or schedule effect, absorbable within contingency |
| Low | Monitored; no active mitigation spend |
3. Open Risks
| Ref | Risk | Exposure | Owner | Status | Mitigation |
|---|---|---|---|---|---|
| R-01 | Member identity resolution materially harder than modeled | Critical | Dr. A. Ravindran | Open | ⚠ Profiling in progress. Steward capacity scalable through the staffing agreement. See §4.1. |
| R-02 | Attrition of retention-covered target staff before TSA exit | Critical | D. Marchbanks | Open | Retention agreements on 14 roles; knowledge transfer as a tracked deliverable with named receivers |
| R-03 | Cloud skills gap slows migration or incident response | High | B. Trammell | Open | Co-managed model with Rutherford Cloud Operations; capability measured at each step-down boundary |
| R-04 | Vendor exercises a change-of-control termination right | High | H. Castellow | Open | Three rights identified; consents and run-out terms secured. Residual exposure is renewal pricing, not service loss. |
| R-05 | Core administration cutover slips past the TSA plan date | Critical | W. Ferriday | Open | Dependent on R-01. Six months of negotiated margin remain unspent. |
| R-06 | Provider contracts do not permit rationalization in the modeled window | High | J. Kirkendall | Open | Network synergy re-profiled to renewal calendar; timing risk rather than value loss |
| R-07 | State conditions restrict where member data may be processed | High | R. Cadwallader | Accepted | ⚠ Not mitigable — it is a regulatory condition. Accepted, with the constraint reflected in resourcing and platform policy. |
| R-08 | Data warehouse go-live without demonstrated recovery | High | H. Sandifer | Open | Tier 2, RTO 72h / RPO 24h; seven gate conditions incl. a tested restore before go-live. See §4.4. |
| R-09 | Egress capacity insufficient for the historical estate | Medium | D. Fontenot | Open | Five physical transfer appliances in rotation; archive transfer ahead of schedule |
| R-10 | Interface defects surface during parallel run | Medium | R. Delacroix | Open | Daily control-total reconciliation; X12 assurance contracted to a specialist |
| R-11 | Business Associate Agreement scope inadequate for a new region or service | High | L. Braithwaite | Open | Scope confirmation rather than existence check; sixteen agreements tracked individually |
| R-12 | MSP step-down slips; ACME does not reach self-sufficiency | Medium | B. Trammell | Open | Step-down is a contractual exhibit with acceptance at each boundary, not a statement of intent |
| R-13 | Member service degradation at CRM absorption | Medium | T. Ruffalo | Open | Coexistence held through Day 100 precisely to avoid this; absorption sequenced after stabilization |
| R-14 | Claims timeliness degrades under combined volume, drawing regulatory attention | High | R. Cadwallader | Open | Timeliness metrics monitored through cutover; prior market conduct finding makes this a regulatory matter, not only a service one |
| R-15 | Source systems not decommissioned, data center exit slips | Medium | H. Sandifer | Open | Dated shutdown required at each wave exit; tracked to the lease date |
| R-16 | Synergy reported but not evidenced in the ledger | Medium | J. Petrosyan | Open | Independent measurement against a frozen baseline; source owners deliver but do not measure |
| R-17 | Integration layer accumulates business logic and cannot be retired | Low | R. Delacroix | Open | Enforced at design review; registered consumer list; retirement evidenced by zero traffic |
| R-18 | Open appeals cases cannot migrate with regulatory record intact | Medium | F. Underhill | Open | Cases complete in the system that opened them; appeals interface retires last |
4. The Four That Drive the Program
4.1 R-01 — identity resolution
Critical. Open. Unquantified.
The deal model assumed a clerical review band of roughly eight percent of the target population, producing a queue of about 33,600 records. At four stewards clearing 100 records a day, that is 84 working days — comfortably inside the migration window. Every input to that calculation except the population size is an assumption, and the assumption that matters most was made without sight of the data because the Clean Team Protocol forbade it.
| If the band is | Queue | Days at current staffing | Effect |
|---|---|---|---|
| 8% — the assumption | 33,600 | 84 | Fits with margin |
| 12% | 50,400 | 126 | Fits, no margin |
| 16% | 67,200 | 168 | ⚠ Exceeds the window at current staffing |
Profiling is scheduled to complete this quarter. Until it does, this risk is carried at an exposure the program has not been able to verify, and R-05 is dependent on it.
4.2 R-02 — retention
Critical. Open. Fourteen target-side roles are covered by retention agreements, selected because they hold system knowledge the TSA exit depends on. The exposure is not headcount; it is that a departure removes knowledge the receiving organization has not yet absorbed. Knowledge transfer is specified as a deliverable with named receivers and reverse-shadowing acceptance, precisely so that a departure after transfer is a staffing problem rather than a program one.
4.3 R-05 — TSA date
Critical. Open, and dependent on R-01. Core administration cutover is the last wave and the longest chain. Six months of negotiated margin sit between the planned exit and the contractual maximum. That margin exists for exactly this situation and has not been drawn on. ⚠ It is also finite, and spending it is a Steering Committee decision rather than a program one.
4.4 R-08 — warehouse recovery
High. Open. The enterprise data warehouse is the program's only new build, so it inherits no backup regime, no tested runbook and no restore history. It is Tier 2 — RTO 72 hours, RPO 24 hours — with seven gate conditions that must be evidenced before go-live, including a full restore tested end to end. ⚠ For a warehouse, durability matters more than availability: a 72-hour outage is survivable, but losing a quality measurement year is not recoverable at any recovery time objective.
5. Closed and Realized
5.1 Closed
| Ref | Risk | Why it closed |
|---|---|---|
| R-C1 | Regulatory approval delayed or conditioned unfavorably | Form A approved. One condition applies and converted to R-07. |
| R-C2 | Day 1 payroll or benefits failure | Passed. HRIS and payroll migrated at month three with a parallel cycle run first. |
| R-C3 | Platform capacity insufficient for combined volume | Load analysis confirmed headroom post-close |
| R-C4 | Landing zone not ready before first migration wave | Accepted against ten evidenced conditions; Wave 1 proceeded |
5.2 Realized — moved to issue management
| Ref | Was | Now |
|---|---|---|
| I-01 | Provider directory discrepancies between the two networks | Issue. Remediation underway ahead of network rationalization. |
| I-02 | Trading partner re-registration slower than planned | Issue. Externally paced; clearinghouse exit re-sequenced accordingly. |
| I-03 | Discovery revealed integration scope beyond the deal-model estimate | Issue, resolved through the January re-baseline |
6. Ownership and Escalation
| Provision | Detail |
|---|---|
| Risk owner | ⚠ Always the person who can act on it, never the Program Manager. The IMO administers the register; it does not own the risks. |
| Review cadence | Workstream weekly; full register monthly with the Steering Committee |
| Critical exposure | Reviewed at every Steering meeting regardless of movement |
| Escalation trigger | Any risk threatening a rank 1 or 2 constraint escalates immediately, not at the next cadence |
| Acceptance | Accepting a risk requires a named accepter at the appropriate level. ⚠ Nobody accepts a risk anonymously. |
| Closure | Requires a stated reason. "No longer discussed" is not closure. |
Related artifacts: 1 — Integration Charter · 7 — Due Diligence Findings · 13 — Synergy Realization Plan · 21 — Vendor & Contract Disposition Matrix · 23 — Data Migration & EMPI Strategy · 34 — Cloud Landing Zone Design · 35 — Cloud Migration Wave Plan · 31 — Data Profiling Report · 44 — Change Control Log