← M&A Integration Suite Register · Artifact 28 · how to read this suite

Risk Register

Download Word

The program risk register as at February 5, 2024 — four months after Day 1, two weeks after the post-discovery re-baseline, and seven months before the planned TSA exit. Eighteen risks are open or tracked, four have closed, and three have already been realized and moved to issue management. This is a working document rather than a summary: it records what the program believed at this date, including what it had sized correctly and what it had not yet been able to measure.

This register is a period document. It reflects the program's understanding on its issue date and is not updated retrospectively. Where a later event changes the picture, that appears in the next issue of the register — not by editing this one. A risk register rewritten with hindsight is a summary of what happened, which is a different and much less useful thing.

Table of Contents

Part I — Method
  1. Risk, Issue, Assumption
  2. Scoring
Part II — The Register
  1. Open Risks
  2. The Four That Drive the Program
  3. Closed and Realized
Part III — Governance
  1. Ownership and Escalation
Part I — Method

1. Risk, Issue, Assumption

CategoryDefinitionHandled by
RiskMight happen. Has a probability.This register. Mitigated, transferred, avoided or accepted.
IssueHas happened. Probability is 1.Issue management. ⚠ A realized risk stops being a risk — leaving it in the register overstates future exposure.
AssumptionBelieved true, not verified. If false, becomes a risk.Tracked with a test date. See 1.1.
DependencySomething outside the program's control that it needsTracked separately; escalated when the external party slips

1.1 Assumptions that became risks

The Due Diligence Findings carried a register of matters that could not be assessed before closing. Each was an assumption with a test date. As those tests complete, the assumption either closes or converts into a risk with a score.

Assumption at closingTestOutcome as at this date
Target vendor contracts assignable or novatablePre-close sweepClosed Consents obtained; see R-04
ACME platform absorbs target volume without re-architecturePost-close load analysisClosed Headroom confirmed
No regulatory condition restricting data locationForm A termsConverted A condition does apply — became R-07
Target member data quality broadly as representedPost-close profiling⚠⚠ Still open. Profiling in progress. Carried as R-01.
The last row is the only assumption from closing that remains untested four months in, and it is the largest. Profiling requires the full member file loaded, standardized and matched — work that could not begin until after closing and that has taken longer than the sequence assumed. Until it completes, R-01 is scored on the deal-model assumption rather than on measurement, which means the register is carrying its most consequential risk at an exposure nobody has yet been able to verify.

2. Scoring

Exposure is probability against impact, with one deliberate departure from the usual method.

ExposureMeaning
CriticalThreatens a Charter rank 1 or 2 constraint — the TSA maximum or Day 1 operational integrity. ⚠ Assigned on impact regardless of probability.
HighThreatens the synergy commitment or a major milestone
MediumMaterial cost or schedule effect, absorbable within contingency
LowMonitored; no active mitigation spend
The departure: a low-probability risk that would breach a hard constraint is scored Critical anyway. Multiplying probability by impact collapses "unlikely but fatal" and "likely but survivable" into the same number, and they demand completely different responses. A five percent chance of breaching the TSA contractual maximum is not a medium risk that can wait for the monthly review — it is a risk the Steering Committee should see every time it meets, because the consequence is not recoverable by spending more money later.
Part II — The Register

3. Open Risks

RefRiskExposureOwnerStatusMitigation
R-01Member identity resolution materially harder than modeledCriticalDr. A. RavindranOpen⚠ Profiling in progress. Steward capacity scalable through the staffing agreement. See §4.1.
R-02Attrition of retention-covered target staff before TSA exitCriticalD. MarchbanksOpenRetention agreements on 14 roles; knowledge transfer as a tracked deliverable with named receivers
R-03Cloud skills gap slows migration or incident responseHighB. TrammellOpenCo-managed model with Rutherford Cloud Operations; capability measured at each step-down boundary
R-04Vendor exercises a change-of-control termination rightHighH. CastellowOpenThree rights identified; consents and run-out terms secured. Residual exposure is renewal pricing, not service loss.
R-05Core administration cutover slips past the TSA plan dateCriticalW. FerridayOpenDependent on R-01. Six months of negotiated margin remain unspent.
R-06Provider contracts do not permit rationalization in the modeled windowHighJ. KirkendallOpenNetwork synergy re-profiled to renewal calendar; timing risk rather than value loss
R-07State conditions restrict where member data may be processedHighR. CadwalladerAccepted⚠ Not mitigable — it is a regulatory condition. Accepted, with the constraint reflected in resourcing and platform policy.
R-08Data warehouse go-live without demonstrated recoveryHighH. SandiferOpenTier 2, RTO 72h / RPO 24h; seven gate conditions incl. a tested restore before go-live. See §4.4.
R-09Egress capacity insufficient for the historical estateMediumD. FontenotOpenFive physical transfer appliances in rotation; archive transfer ahead of schedule
R-10Interface defects surface during parallel runMediumR. DelacroixOpenDaily control-total reconciliation; X12 assurance contracted to a specialist
R-11Business Associate Agreement scope inadequate for a new region or serviceHighL. BraithwaiteOpenScope confirmation rather than existence check; sixteen agreements tracked individually
R-12MSP step-down slips; ACME does not reach self-sufficiencyMediumB. TrammellOpenStep-down is a contractual exhibit with acceptance at each boundary, not a statement of intent
R-13Member service degradation at CRM absorptionMediumT. RuffaloOpenCoexistence held through Day 100 precisely to avoid this; absorption sequenced after stabilization
R-14Claims timeliness degrades under combined volume, drawing regulatory attentionHighR. CadwalladerOpenTimeliness metrics monitored through cutover; prior market conduct finding makes this a regulatory matter, not only a service one
R-15Source systems not decommissioned, data center exit slipsMediumH. SandiferOpenDated shutdown required at each wave exit; tracked to the lease date
R-16Synergy reported but not evidenced in the ledgerMediumJ. PetrosyanOpenIndependent measurement against a frozen baseline; source owners deliver but do not measure
R-17Integration layer accumulates business logic and cannot be retiredLowR. DelacroixOpenEnforced at design review; registered consumer list; retirement evidenced by zero traffic
R-18Open appeals cases cannot migrate with regulatory record intactMediumF. UnderhillOpenCases complete in the system that opened them; appeals interface retires last

4. The Four That Drive the Program

4.1 R-01 — identity resolution

Critical. Open. Unquantified.

The deal model assumed a clerical review band of roughly eight percent of the target population, producing a queue of about 33,600 records. At four stewards clearing 100 records a day, that is 84 working days — comfortably inside the migration window. Every input to that calculation except the population size is an assumption, and the assumption that matters most was made without sight of the data because the Clean Team Protocol forbade it.

If the band isQueueDays at current staffingEffect
8% — the assumption33,60084Fits with margin
12%50,400126Fits, no margin
16%67,200168⚠ Exceeds the window at current staffing
The queue scales linearly with the review band, and three of the obvious responses are unavailable. Offshore stewards are barred — state conditions prohibit processing member-level data outside the United States, which is R-07 and is accepted rather than mitigated. Throughput cannot be raised by pressure, because a steward working faster is a steward spending less time on the hard cases, and the hard cases are where false positives originate. Additional stewards can be recruited through the staffing agreement, but onboarding and training run several weeks. The only lever that responds quickly is time, and time is the rank 1 constraint.

Profiling is scheduled to complete this quarter. Until it does, this risk is carried at an exposure the program has not been able to verify, and R-05 is dependent on it.

4.2 R-02 — retention

Critical. Open. Fourteen target-side roles are covered by retention agreements, selected because they hold system knowledge the TSA exit depends on. The exposure is not headcount; it is that a departure removes knowledge the receiving organization has not yet absorbed. Knowledge transfer is specified as a deliverable with named receivers and reverse-shadowing acceptance, precisely so that a departure after transfer is a staffing problem rather than a program one.

4.3 R-05 — TSA date

Critical. Open, and dependent on R-01. Core administration cutover is the last wave and the longest chain. Six months of negotiated margin sit between the planned exit and the contractual maximum. That margin exists for exactly this situation and has not been drawn on. ⚠ It is also finite, and spending it is a Steering Committee decision rather than a program one.

4.4 R-08 — warehouse recovery

High. Open. The enterprise data warehouse is the program's only new build, so it inherits no backup regime, no tested runbook and no restore history. It is Tier 2 — RTO 72 hours, RPO 24 hours — with seven gate conditions that must be evidenced before go-live, including a full restore tested end to end. ⚠ For a warehouse, durability matters more than availability: a 72-hour outage is survivable, but losing a quality measurement year is not recoverable at any recovery time objective.

5. Closed and Realized

5.1 Closed

RefRiskWhy it closed
R-C1Regulatory approval delayed or conditioned unfavorablyForm A approved. One condition applies and converted to R-07.
R-C2Day 1 payroll or benefits failurePassed. HRIS and payroll migrated at month three with a parallel cycle run first.
R-C3Platform capacity insufficient for combined volumeLoad analysis confirmed headroom post-close
R-C4Landing zone not ready before first migration waveAccepted against ten evidenced conditions; Wave 1 proceeded
A register where nothing ever closes is not being managed, it is being accumulated. Risks that have passed their window, or whose triggering condition can no longer occur, are closed with a reason — otherwise the register grows monotonically and its top ten stops meaning anything. Four closures in four months against eighteen open is a reasonable ratio; zero closures would be the signal that nobody is reviewing it.

5.2 Realized — moved to issue management

RefWasNow
I-01Provider directory discrepancies between the two networksIssue. Remediation underway ahead of network rationalization.
I-02Trading partner re-registration slower than plannedIssue. Externally paced; clearinghouse exit re-sequenced accordingly.
I-03Discovery revealed integration scope beyond the deal-model estimateIssue, resolved through the January re-baseline
Part III — Governance

6. Ownership and Escalation

ProvisionDetail
Risk ownerAlways the person who can act on it, never the Program Manager. The IMO administers the register; it does not own the risks.
Review cadenceWorkstream weekly; full register monthly with the Steering Committee
Critical exposureReviewed at every Steering meeting regardless of movement
Escalation triggerAny risk threatening a rank 1 or 2 constraint escalates immediately, not at the next cadence
AcceptanceAccepting a risk requires a named accepter at the appropriate level. ⚠ Nobody accepts a risk anonymously.
ClosureRequires a stated reason. "No longer discussed" is not closure.
The first row is the one that decides whether a register works. It is tempting for the Program Manager to own every risk, because the PM is the one maintaining the document and chasing the updates. It is also useless: a risk owned by someone with no authority to change the outcome produces status reporting rather than mitigation. The owner must be the person who can spend the money, change the sequence, or make the call — which for this program means fourteen different executives own the eighteen open risks, and the IMO owns none of them.
On R-07 being marked "Accepted" rather than mitigated — that is a real disposition, not a failure to try. A state regulatory condition on data processing location is not something a program can mitigate; it can only be complied with. Recording it as accepted, with a named accepter and the constraint reflected in resourcing and platform policy, is more honest than inventing a mitigation that amounts to "we will follow the law." Registers that contain no accepted risks are usually registers where acceptance is happening without a name against it.

Related artifacts: 1 — Integration Charter · 7 — Due Diligence Findings · 13 — Synergy Realization Plan · 21 — Vendor & Contract Disposition Matrix · 23 — Data Migration & EMPI Strategy · 34 — Cloud Landing Zone Design · 35 — Cloud Migration Wave Plan · 31 — Data Profiling Report · 44 — Change Control Log