Builds a live risk register pairing every material risk with a named mitigant, an owner and a residual assessment, when you need to show which risks are priced into the bid and which are simply accepted.
Scanned 9/19/2026
Install to Claude Code
npx -y skills add andreworia/claude-finance-skills --skill risk-and-mitigant-register --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Risk And Mitigant Register?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/andreworia-risk-and-mitigant-register)More formats (shields.io, HTML) on the badges page.
---
name: Risk and Mitigant Register
description: Builds a live risk register pairing every material risk with a named mitigant, an owner and a residual assessment, when you need to show which risks are priced into the bid and which are simply accepted.
---
# Risk and Mitigant Register
## When to use
Use this skill from the point diligence findings start landing through to the first board meeting after close. The IC memo carries a risk matrix; this is the instrument behind it, kept live and handed over at completion. Reach for it when the risk section reads as a list of things that might go wrong rather than decisions taken.
## What it does
Produces a register in which each risk is sized in the currency of the deal, matched to one mitigant with one named owner and a date, assessed for what remains after it, and classified as priced, transferred, mitigated or accepted -- ending with the accepted risks on one page.
## Method
1. **Harvest, never invent.** Every entry traces to a finding in a workstream, cited by source. Generic risks -- competition, cyclicality, key person -- are cut unless a finding gives them a number.
2. **Size before you rank.** Express each risk as EBITDA at risk, enterprise value at risk, or months of delay. "Customer concentration" is not a risk; "the top customer, 18% of revenue, renews eleven months after close" is.
3. **Name one mitigant and one owner.** The mitigant is an action with a date, not a posture; the owner is a person, not a committee. Mitigants come in four families: priced into the bid, transferred by instrument, secured contractually, or executed in the 100-day plan.
4. **Assess the residual, not the gross.** Restate probability and severity after the mitigant applies. Residual is the only column the committee should act on, and one that does not move it is not a mitigant but a comfort.
5. **Separate priced from accepted.** Say which each risk is: priced -- reflected in the offer, with the amount; transferred -- to the seller or an insurer, with instrument and cap; mitigated -- reduced by action, with the owner; or accepted -- taken on knowingly at this price. A register in which nothing is accepted has not been read honestly.
6. **Test for correlation.** Risks sharing a driver -- one customer, one site, one regulator, one refinancing window -- are not independent. Group them and size the group, because the group is the loss that arrives.
7. **Set a tripwire for the top five.** For each, the observable that says it is materialising, the date of the first look and who looks. A risk without one is discovered late by definition.
8. **Carry it across completion.** At close the register becomes the ownership risk log: owners transfer to the chair and management, and the accepted page is read at the first board meeting so nobody rediscovers it later.
## Inputs
- Diligence findings by workstream, with the issues log
- QoE report, with rejected add-backs and normalisations
- Draft SPA terms: warranties, indemnities, escrow, W&I cover and caps
- The returns model, to price a risk in multiple terms
- The 100-day plan, for operationally mitigated items
## Output format
- Entries in prose: risk, source, size, mitigant, owner, date, residual, treatment
- A correlation section grouping risks that share a driver, sized together
- A priced summary reconciling risk adjustments to the bid
- One accepted-risk page, without mitigants, recording what was knowingly taken
- Tripwires for the top five, each with an observable, a date and a watcher
- Present the register and all schedules in prose, never as markdown tables
## Example
Kellerman Fluid Systems (fictional, illustrative): revenue 150, QoE EBITDA 30, bid at 9.0x for enterprise value of 270. The technical review found 6 of deferred maintenance capex in years one and two; treatment is priced -- the bid drops by the full 6 to 264, or 8.8x, and the spend sits in the model, not the risk narrative. The top customer is 27 of revenue at 18%, carrying 10.8 of contribution at a 40% contribution margin against EBITDA of 30; treatment is contractual, a three-year renewal signed before completion, residual medium because the renewal secures the contract but not the volume inside it, owner the deal partner until close, the chair after. The single site is accepted: no mitigant exists at this price, and the continuity review is a control not a cure. Saying so on the accepted page serves the committee better than calling a control a mitigant.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!